Continuous external testing. One BreachRisk Score.
BreachRisk Business discovers everything you have facing the internet, emulates real attackers to prove what's exploitable, and rolls it into a single BreachRisk Score — re-run on a recurring cadence, not once a year.
Three tools' jobs, done continuously.
Buyers usually purchase these separately. BreachRisk Business does all three — as always-on SaaS — and turns it into a score.
Real attacker testing
but manual, and only once a year.
Broad coverage
but they flag maybes — they never exploit.
An outside-in score
but no actual testing behind it.
Your whole external surface.
Asset discovery
Finds everything you have facing the internet — domains, subdomains, IPs, and hosts — from public and threat-intel sources.
Perimeter
Deep-scans every host and emulates real attackers to prove exploitable threats, backed by penetration-test evidence.
Social & phishing
Checks email spoofing protections and exposed identities, and runs phishing-simulation testing.
Cloud
Connect AWS, Azure, Azure Government, Google Cloud, Microsoft 365, and Google Workspace — resources and misconfigurations aggregated in one view.
Credential & dark web
Surfaces leaked credentials and dark-web exposure tied to your organization.
BreachRisk Score
Everything rolls up into one quantified score, broken down by pillar and trended over time.
A score, and the evidence behind it.
Every assessment produces one quantified BreachRisk Score — broken down by pillar, comparable over time — plus branded, client-ready reports with the pen-test evidence behind each finding.
- >> Quantified score, broken down by risk pillar and trended.
- >> Real penetration-test evidence, not scanner noise.
- >> Branded PDF reports aligned to SOC 2, PCI-DSS, HIPAA & NIST 800-53.
Every plan, feature by feature.
Three tiers of BreachRisk Business — each one builds on the last.
| Feature | LiteFind, verify & score your threats | Pro+ Pen testing, dark web & cloud | Premium+ Social-engineering testing |
|---|---|---|---|
| Asset discovery | |||
| Public attack surface discovery & monitoringFinds everything facing the internet — domains, subdomains, IPs, and hosts. | ✓ | ✓ | ✓ |
| Continuous assessment | |||
| Recurring automated assessmentRe-tests your surface on a continuous cadence — not once a year. | ✓ | ✓ | ✓ |
| Trends over timeTracks your score and findings across every assessment. | ✓ | ✓ | ✓ |
| Assessment cadenceHow often your surface is re-assessed. | Monthly | Weekly | Weekly & on-demand |
| Deep scanning & threat detection | |||
| Vulnerability detection (CVE)Identifies known vulnerabilities with CVE and severity signal. | ✓ | ✓ | ✓ |
| External threat discovery & verificationFinds the vulnerability, misconfiguration, and credential threats where attackers will try to breach. | ✓ | ✓ | ✓ |
| External penetration testing | |||
| Penetration testing of external threatsSafely attempts to breach each threat discovered — just like an attacker will. | — | ✓ | ✓ |
| Social & phishing | |||
| Email control assessmentDiscovers and monitors the email controls across your domains, so you're safe from spoofing. | ✓ | ✓ | ✓ |
| Social attack surface discovery & monitoringFinds employee emails and identities on the internet and dark web that could be social-engineering targets. | ✓ | ✓ | ✓ |
| Social-engineering testingAI-powered spearphishing testing using advanced social-engineering tactics. | — | — | ✓ |
| Cloud | |||
| Cloud integrationsConnect AWS, Azure, Azure Government, Google Cloud, Microsoft 365, or Google Workspace so every asset is tested and monitored. | ✓ | ✓ | ✓ |
| Cloud penetration testingTests your integrated cloud environments against tactics unique to each. | — | ✓ | ✓ |
| Credential & dark-web exposure | |||
| Breach indication monitoringMonitors dark-web forums for signs your company has been breached or targeted. | — | ✓ | ✓ |
| Compromised credential monitoringMonitors dark-web forums for exposed credentials tied to your company. | — | ✓ | ✓ |
| Domain monitoringMonitors dark-web forums for chatter or mentions of your company or employees. | — | ✓ | ✓ |
| Scoring & reporting | |||
| BreachRisk™ ScoreOne quantified breach-risk score, broken down by risk pillar. | ✓ | ✓ | ✓ |
| Penetration test reportsCustomizable PDF reporting, generated on demand. | — | ✓ | ✓ |
| SOC 2 penetration test reportsReports aligned to SOC 2 standards. | — | ✓ | ✓ |
| PCI-DSS penetration test reportsReports aligned to PCI-DSS standards. | — | ✓ | ✓ |
| HIPAA penetration test reportsReports aligned to HIPAA standards. | — | ✓ | ✓ |
| NIST 800-53 penetration test reportsReports aligned to NIST 800-53 controls. | — | ✓ | ✓ |
Reports reflect testing performed and mapped to each framework's controls — not a certification of control effectiveness.
See your external surface, scored.
Book a demo and we'll tailor it to exactly what you're looking to solve.