Positioning

KryptaScope does not replace an audit. It complements it.

If you need a signed report for a certification or a tender, you want an audit firm. If you want to see what changes between two audits — and have a dossier ready when asked — KryptaScope is built for that.

Our approach
KryptaScope
Daily external monitoring
When
Every day, from the Internet
Scope
External surface (DNS, subdomains, SSL, public credential leaks)
Deliverable
Dashboard refreshed every day + monthly posture PDF under your name
Cost
From €79/month (reseller plan above that)
Automatic safety net between two audits — detects what appears between manual passes.
Cyber audit firm
One-off in-depth audit
When
Once a year or case by case
Scope
Internal + external perimeter, with pentest, code review, CISO interviews
Deliverable
Detailed report delivered at the end of the engagement — turnaround and shelf life depend on the firm and the scope.
Cost
Several thousand euros per engagement, depending on scope
Deep diagnosis and human commitment. Essential to tick the boxes for ISO 27001, NIS2 or the maturity required by a large client.
Nothing
Default approach
When
Scope
Deliverable
Cost
0€
Hidden cost: an attacker detects a leak before you, or a client requests your posture during a tender and you have nothing to present.

How the two approaches fit together

Frequency
KryptaScope
Daily scan · alert as soon as a change is detected
Audit firm
One-off (on demand, given period)
Both approaches reinforce each other — the one-off audit gives the diagnosis, monitoring detects what appears between two audits.
Depth
KryptaScope
External surface only (what an attacker sees from the Internet)
Audit firm
Full depth (internal, code, processes, team)
KryptaScope does not replace a pentest or a code audit. It ensures the outer layer remains under control between deep passes.
Deliverable
KryptaScope
Dashboard + preparatory PDFs (insurer, audit, due diligence)
Audit firm
Audit report signed by an auditor, sometimes with a best-efforts commitment
KryptaScope produces factual documents to be validated by your DPO or audit firm. Not a deliverable signed by a certified auditor.
Required skill on the client side
KryptaScope
None (guided workflow for each finding)
Audit firm
Internal CISO or DPO to drive actions
KryptaScope was designed for SMBs without a security team. Audit firm reports require someone who can read and act on them.

Already working with an audit firm? KryptaScope fits as a monitoring tool between two audits — you leave with a dossier ready to present to your auditor.

No audit planned yet? Start by seeing what the Internet sees of your company. If the posture is healthy, you'll know. If it isn't, you'll know too — and you'll know what to do.

Scan my domainSee plans