46.0511° n, 14.5051° e
ljubljana / eu
agent: lightweight
disruption: none
surface: 14 services reachable from outside
encryption: weak key exchange still accepted
access: admin panel exposed to the internet
IT hygiene for the systems you already run

Find yourvulnerabilities.Before someone else does.

You should not need a security team on the payroll to know where you are exposed. Arturus puts one to work for you: it checks the machines you already run, ranks what it finds by real risk, and hands your IT person a report they can act on the same day.

scroll
windows · linux · macos in development
lightweight agent · no access to your data · zero disruption
01The problem

Most organizations cannot answer one simple question: where are we exposed?

Not because the answer is exotic, but because nobody has looked. The gaps that get exploited are rarely clever: an unpatched package, a service listening that should not be, an old protocol still accepted, a default left in place.

Finding them has traditionally meant hiring a specialist, or a consulting engagement you run once and never repeat. That is the part we changed.

See what a report covers
0steps
from registration to a report you can act on, nothing to configure
0reports
technical and executive, one assessment written for two different readers
0disruption
the agent runs alongside normal operations, nothing is taken offline
02What we see

We look at everything you run.

Workstations, servers, cloud instances and the services they expose. Assessed in place, on Windows and Linux, with macOS in development.

prod-web-01 · container escape · cve-2024-21626
vpn-gateway · openssh rce · cve-2024-6387
db-primary · database port open · no credentials
ws-014 · security updates 61 days behind
scan complete
12assets
31findings
3p0
Ranked by real world risk
03The findings

Your full attack surface. Mapped.

The agent is lightweight and deliberately incurious. It does not read your files, your mail or your business data. It looks at the state of the machine: which services are listening, which patches are missing, how encryption and remote access are configured, what the operating system allows.

Those checks are built on proven, widely used methods for surfacing weaknesses. What we add is the part that usually goes missing: triage. Every finding is scored, ranked from P0 to P3 by how likely it is to be used against you, and paired with the specific thing to change.

workstations and servers cloud assets network services authentication posture
Start your first scan
arturus / findings · acme-corp · aug 2026
OpenSSH regreSSHion RCE
CVE-2024-6387 · vpn-gateway
p094
Database port open, no credentials
CWE-306 · db-primary
p091
Container escape
CVE-2024-21626 · prod-web-01
p088
Missing OS security updates
14 packages · app-server-02
p168
TLS 1.0 still accepted
tls-security · prod-web-01
p241
risk reduction
28% addressed
raw scanner output
ssl-cert: Subject: CN=prod-web-01
ssl-date: TLS randomness does not represent time
| ssl-dh-params:
| LOGJAM: CVE-2015-4000
| Transport Layer Security
| bits: 1024
| references: https://weakdh.org
open port 3306/tcp: mysql
| mysql-info:
| Protocol: 10 · Version: 8.0.32
| Thread ID: 14
| Capabilities flags: 65535
PORT 22/tcp OPEN ssh
| ssh-hostkey: 3072 aa:bb:cc:dd…
PORT 80/tcp OPEN http · Apache/2.4.57
| http-server-header: Apache
| http-title: Did not follow redirect
[ 3,847 more lines ]
hashfort report
p0 · fix today
⬤ database port open, no auth
impact: full db access, no exploit needed
fix: bind to 127.0.0.1, enforce auth
⬤ openssh rce · cve-2024-6387
impact: unauthenticated root
fix: upgrade to openssh 9.8p1
p1 · fix within 7 days
⬤ missing os security updates
impact: 14 known issues left open
p2 · schedule next sprint
⬤ tls 1.0 still accepted
low real-world exploitability in 2026
→ executive summary: 1 page
→ remediation plan: 6 ordered steps
◂▸

drag to compare

04The report

Raw scanner output is not a report.

Any scanner will give you thousands of lines. Untriaged, that output is worse than nothing: the real problems sit buried under noise, and your IT person spends a week deciding what matters. We do that part, and write it down in language each reader can use.

See what a report covers
05The platform

We built our own platform. You see why.

Off the shelf tools are black boxes. You get a verdict without the working, and when someone asks how you know, there is no answer to give. Arturus keeps every finding attached to the scan that produced it, so a claim can always be followed back to the evidence behind it. Your team sees it live throughout, not as a PDF three weeks later.

proven detection methods for services, patches and misconfiguration
one risk score across every protocol, so the picture holds together
reports written for the person reading them, not for the tool
See the platform
arturus-agent · scan · acme-corp · live
arturus scan --asset prod-web-01
collecting host inventory …
✓ 214 packages, 18 services
checking listening services …
✓ service scan complete
⚠ 3 services reachable from outside
matching against vulnerability data …
[job a3f8c2d1] running …
✗ p0: cve-2024-6387 confirmed
✗ p0: database port open, no credentials
⚠ p1: 14 security updates missing
writing report bundle …
✓ report ready → app.arturus.org/reports
06How it works

Five steps. No specialist required.

No project plan, no discovery workshop, no consultant on site. You can be through the first three steps before lunch.

Start with a conversation
01
Register
Create the account and pick a package. You will have access to the portal straight away.
02
First scan
Download the agent, run it on the asset you want assessed, and the scan starts. It is lightweight and runs while people keep working.
03
Get the report
A technical report for whoever fixes things, and an executive report for whoever decides. Both from the same evidence, so they cannot disagree.
04
Remediation guidance
Each finding comes with the specific change that closes it, ordered so the work that removes the most risk comes first.
05
Follow up scan
Scan again once the fixes are in. The comparison shows exactly what moved, which is the part that proves the effort was worth it.
eu regulation, in force now

NIS2 is not optional.

The directive requires organizations in essential and important sectors to manage risk systematically, and that includes handling vulnerabilities and being able to show your working. A Hashfort assessment produces documentation that speaks directly to those requirements.

article 21 risk managementvulnerability handlingincident reporting readinessiso 27001 alignment

Not sure whether NIS2 applies to you?

Ask us
Why hashfort

Different by design.

Independent, opinionated, and honest about what you actually need. Not a consultancy, not a scanner reseller.

(a)
No specialist needed
The whole point. You do not hire anyone, learn a tool, or interpret a scanner. You read a report and hand your IT person a list.
(b)
Affordable and repeatable
A one off audit tells you about one day. This runs every month for less than a fraction of a specialist salary, which is what actually improves hygiene over time.
(c)
Your data stays yours
The agent inspects configuration and software state. It does not read files, mail or databases, and only findings leave the machine.
(d)
Ranked, not dumped
We do not hand you a scanner export and call it a report. Every finding is triaged, scored and mapped to a clear action.
(e)
Zero disruption
It runs alongside normal operations. Nothing is taken offline and nobody has to stop working.
(f)
Both audiences covered
A technical brief for the person fixing it and an executive summary for the person funding it, both built from the same evidence so they cannot disagree.
Simon Kramarič, founder of Hashfort
The story behind hashfort
I did not build Hashfort to create yet another security review. I built it because organizations deserve to understand their actual security posture, not just another compliance score.

Working with organizations over the years, the same thing kept happening. Companies knew security mattered, but their people and money went into running the business. Security stayed in the background, not because it was unimportant, but because it was complex and hard to see into from the outside.

The honest problem is cost. Knowing where you stand has meant hiring an expert most organizations cannot justify. Arturus is built to replace that need: a security specialist you do not have to employ, producing the same clarity, every month, for a price a small company can actually carry.

Founder, Hashfort · Slovenia · EU
curiositypassioncommitmenttrust
Side initiative

We also scan publicly reachable Slovenian websites.

K.I.S.S. is our public cyber exposure index for Slovenian websites. We scan by industry and publish aggregated scores to make the point that exposure is real, measurable, and usually already visible from the outside.

See the public index
k.i.s.s. · kibernetski indeks spletnih strani
Limited liability companies · all industries
Slovenia, 2026 to date
72
Average K.I.S.S. score
out of 100 · higher is better
5,565 sites scanned across 21 areas
most common findings
Outdated encryption
2057%
Exposed remote access
1047%
Outdated software
15%
Questions

What people ask first.

No, and that is the point of it. The assessment runs itself and the report is written to be handed straight to whoever looks after your IT. Each finding says what is wrong, why it matters, and the specific change that closes it. If your IT person can follow a patch note, they can follow this.

Usually the same day. Register, run the agent on an asset, and the technical report is generated automatically when the scan completes. There is no onboarding project and nothing to configure first.

No. This is a structured vulnerability assessment with risk prioritisation: systematic checking and analysis rather than manual exploitation. A penetration test is a separate exercise and can be scoped on request.

It does not read your files, your mail or your databases. It inspects the state of the machine: which services are listening, which patches and packages are installed, how encryption and remote access are set up, how the operating system is configured. Only the findings are sent back, never your content.

No. The agent is lightweight and runs alongside normal operations. Nothing is taken offline, and nobody has to stop working while it runs.

Windows and Linux today, on workstations and servers. macOS is in development. Websites and internet facing services are covered by the external scan on the Growth and Enterprise packages.

You scan again. The follow up compares against the previous scan and shows exactly what closed and what is new, which is how you prove the work paid off rather than assuming it did.

Explore additional frequently asked questions
Pricing

Priced so you can actually keep doing it.

Security that runs once is a snapshot. These are monthly packages because hygiene is a habit, not an event.

Starter

For organizations getting a first honest picture of where they stand.

  • Up to 5 assets
  • 2 scans per asset per month
  • Workstations and servers (Windows, Linux)
  • Technical and executive reports
  • AI written risk summaries and remediation steps
  • Findings ranked P0 to P3 by real world risk
  • Reports delivered to the people you choose
  • Remote support
Get in touch
most requested
Growth

For organizations that need the full picture, inside and outside.

  • Up to 15 assets
  • 2 scans per asset per month
  • Workstations, servers and websites
  • Two external scans per month
  • Technical and executive reports
  • AI written risk summaries and remediation steps
  • Automatic monthly executive report
  • Scan to scan comparison
  • Reports delivered to the people you choose
  • Remote support
Get in touch
Enterprise

For larger estates that need their own scope, cadence and contact.

  • Custom number of assets
  • Custom scan frequency
  • Everything in Growth
  • Custom number of external scans per month
  • Multi user account: your whole team in one workspace
  • Remote and on site support
  • Dedicated account manager
  • Priority support and escalation path
Get in touch

the first step is a conversation, no pressure, no commitment

Ready to know your
exact exposure?

monthly packages · scope confirmed before anything runs · no surprise invoices