Pre-launch — building in the open, early access by waitlist
You're scanning once a year. Attackers aren't.
Continuous vulnerability scanning for teams and solo operators without an enterprise security budget. CyberSpec sweeps your domains, IPs, and CIDR ranges, then maps every finding to the exact SOC 2, ISO 27001, and PCI DSS control it breaks — from $20 a month, self-serve, no sales call. We're opening access in stages — join the waitlist to get in early.
- Free plan at launch, no card
- Self-serve, no sales call
- SOC 2 · ISO 27001 · PCI DSS mapping
Two overlapping code windows: a scan policy config, and an animated terminal showing a live scan of target.corp, surfacing a finding: CVE-2022-3602 · 7.5 HIGH, mapped to SOC 2 and ISO 27001 controls.
$20
Per month at launch, for 20 assets. The scanners this replaces open at five figures and a sales call.
$0
Free plan at launch — one asset, no card, no trial clock.
3
Frameworks your findings map to automatically — SOC 2, ISO 27001, PCI DSS. Not an add-on tier.
Scanners don't map compliance. Compliance tools don't scan.
Enterprise scanners solve exposure and price like it — a sales call and a five-figure contract. Compliance platforms solve evidence collection for an audit, a different problem entirely. So the question every team asks in the weeks before a SOC 2 report — which control does this open finding actually break? — is the one question neither tool answers.
CyberSpec answers it on every finding, on every plan, without a call.
CVE-2022-3602
203.0.113.42:443
OpenSSL 3.0.0–3.0.6 X.509 name-constraint buffer overflow — upgrade to 3.0.7 or later.
maps to SOC 2 CC7.1 · ISO 27001 A.8.8
What it does
Vulnerability management
Every finding deduplicated across scans, triaged by severity, with CVSS scoring and remediation guidance built in.
- Global findings table filterable by severity, CVE, asset, and status
- Bulk status actions — mark resolved, false positive, or risk accepted in bulk
- Automatic dedupe across repeated scans (first-seen/last-seen tracking, not duplicate rows)
Network scanning
On-demand and scheduled scans against domains, IPs, and CIDR ranges, with live progress and CVE correlation.
- Quick, full, and custom scan types against domains, IPs, and CIDR ranges
- Scheduled recurring scans (cron-style) so drift gets caught automatically
- Live scan progress, not poll-and-refresh
Compliance mapping
Every open finding mapped to the SOC 2, ISO 27001, and PCI DSS control families it touches — automatically.
- Coverage view across SOC 2, ISO 27001, and PCI DSS control families
- Driven directly by your current open findings — no separate manual mapping step
- Free tier: not included. Pro and Enterprise: full coverage view
How it works
- 1
Add an asset
Domain, IP, or CIDR range.
- 2
Verify ownership
DNS TXT, well-known file, or attestation.
- 3
Scan on your terms
On-demand or scheduled, quick or full.
- 4
Triage what matters
Findings deduplicated, mapped to compliance controls.
Two-factor set up at first sign-in, on every account
TOTP setup is the step right after your first sign-in, on every sign-in method. Skip it if you genuinely don't need it and turn it on later — the skip is audit-logged, and our own admin accounts can't skip at all. Backup codes are issued at enrolment, and every active session is visible and revocable from Settings.
How CyberSpec secures your accountSimple pricing
Free
$0
1 asset, on-demand scans.
ProFor teams
$20/mo
Up to 20 assets, scheduled scans, compliance mapping.
Enterprise
Custom
Uncapped assets, SSO/SAML, dedicated support.
Frequently asked questions
What we've been reading in the wild
We take apart the vulnerabilities we build against — what actually got exploited, and what patching does and doesn't fix.
· 2 min read
Citrix underrated this NetScaler bug
CVE-2026-8452 shipped as a DoS fix in June. Researchers turned it into unauthenticated RCE in August, and attackers are now dropping web shells on it.
· 3 min read
End-of-life software fails Cyber Essentials
There's no scoring and no grace period. One end-of-life package on an in-scope device is an automatic Cyber Essentials fail, the day the vendor says so.
· 3 min read
Authenticated vs unauthenticated scanning
One scan tells you what an outsider can reach. The other tells you what is installed. Swapping the two is how a finding list stops matching reality.