No promise beyond what the tool actually does. Here is what it is, what it is not, and what we commit to.
French SMEs get audited by their insurers and their large customers on their security posture, but have neither a full-time security officer nor the budget for a recurring audit firm. Either they pay a consultant for a one-off audit that goes stale within six months, or they do nothing and hope. KryptaScope offers a third path: continuous external monitoring and a file ready to present, at a reasonable price, with nothing to install.
Nothing to install on your machines or servers. No access to your systems, no credentials to hand over, no passwords stored. We look at your company from the internet — exactly what an attacker can see — and we query public breach databases. The scope analysed and the frequency of each scan are published in detail on our methodology page.
A penetration test, real-time monitoring of your internal network, an ISO 27001 certification. KryptaScope focuses on the external view and on GDPR groundwork documentation. For the rest, we point you to a specialist — that is more honest than claiming to cover the whole ground, and it saves you buying the same thing twice.
Your data is hosted and processed in the European Union. Our sub-processors are named one by one on the security page, with their role — your procurement team can check them. You can download a report and a draft CNIL notification BEFORE buying, so you judge on evidence rather than on promises. And we show no fake testimonials and no unverifiable statistics: what you read here is what the tool does.
We issue no compliance attestation and do not present ourselves as a third-party certifier. Pronouncing your compliance would expose you, and it is not our role: we monitor and we document. Assessing the risk, deciding whether to notify the regulator, signing a document — all of that is yours. We give you the material, not the verdict.