Everything people ask before starting.
If your question is not here, write to us. We will add the answer to this page so the next person does not have to ask.
No, and that is the point of it. The assessment runs itself and the report is written to be handed straight to whoever looks after your IT. Each finding says what is wrong, why it matters, and the specific change that closes it. If your IT person can follow a patch note, they can follow this.
Usually the same day. Register, run the agent on an asset, and the technical report is generated automatically when the scan completes. There is no onboarding project and nothing to configure first.
No. This is a structured vulnerability assessment with risk prioritisation: systematic checking and analysis rather than manual exploitation. A penetration test is a separate exercise and can be scoped on request.
The reports are still readable, and the executive report is written for someone who does not work in IT. For the fixing itself you will need someone technical, whether that is a person on your team or the provider who looks after your systems. If you want us to walk through the findings with you, ask and we will arrange it as a consulting session.
No, and we will never tell you otherwise. It produces documentation that speaks directly to the Article 21 risk management requirements, which is a real and useful part of the picture. Compliance also needs organizational controls that no scan can give you.
It does not read your files, your mail or your databases. It inspects the state of the machine: which services are listening, which patches and packages are installed, how encryption and remote access are set up, how the operating system is configured. Only the findings are sent back, never your content.
No. The agent is lightweight and runs alongside normal operations. Nothing is taken offline, and nobody has to stop working while it runs.
Windows and Linux today, on workstations and servers. macOS is in development. Websites and internet facing services are covered by the external scan on the Growth and Enterprise packages.
Whoever administers the machine installs it, the same way as any other piece of software. It needs enough access to read the system state it reports on. It does not open a remote control channel and there is nothing for us to log into on your side.
The agent looks at a machine from the inside, which tells you how it would hold up if something already got in. The external scan looks at your estate the way the internet does, which tells you what is reachable from outside in the first place. They answer different questions, so on Growth and Enterprise you get both.
You can uninstall the agent at any time, and it stops reporting immediately. If you close your account you can ask us to delete the findings we hold, and we will.
They are priority bands, not severity labels. A finding lands in a band based on how likely it is to be used against you in practice, which includes whether the weakness is known to be actively exploited, not just how bad it would be in theory. P0 is what you deal with now. P3 is worth tidying up when you next have the time.
You scan again. The follow up compares against the previous scan and shows exactly what closed and what is new, which is how you prove the work paid off rather than assuming it did.
You choose. Reports are available in the portal and can be delivered by email to the people you nominate, so the technical report reaches the person fixing things and the executive report reaches the person deciding. You can change the list at any time.
That is a good month, and the report still says so with evidence behind it. It also tells you plainly which checks could not run on a host, so a partial scan never reads like a clean one.
One machine or one website. A laptop is an asset, a server is an asset, a site covered by the external scan is an asset. Your package sets how many you can have and how often each can be scanned.
Tell us and we move you up, or scope an Enterprise package around what you actually run. Nothing breaks silently: the portal shows your usage against your limit as you go.
Yes, and most people should. Start with the assets that would hurt most if they were compromised, see what the first report says, then widen the scope once you know what you are dealing with.