Your whole attack surface, mapped
Not a single check. One live sweep that finds every host, port and service, then probes each one for what attackers would exploit.
External DAST
Point Cystene at a URL and it enumerates the surface from the outside: subdomains, open ports, live services and every exposed endpoint an attacker would find first.
Internal, Credentialed
Go past the login. Authenticated scans probe your APIs, roles and data policies for the flaws that only show up once you are inside the app.
Audit-Ready Reports
Every finding lands ranked by severity with the CWE, the OWASP category and a concrete fix, exportable straight into a compliance report.
Live Scan
From a command to a fix list.
Point Cystene at a URL and watch it run: it scores your posture and ranks exactly what to fix, worst first.
One weighted score across every engine, trending as you close findings.
5 issues, ranked
Block dotfiles at the edge and rotate every leaked secret.
Enable RLS policies so a user can only read their own rows.
Set CSP, HSTS and X-Content-Type-Options.
Disable legacy protocols; require TLS 1.2 or newer.
Return generic errors; keep details in server logs only.
The Platform
Your whole security posture, on one screen
Every target, its score, its open ports and its findings by severity, reconciled and always current.

Platform
Features
One scan fans out into 20 engines, then confirms what's actually exploitable and ranks it by confidence.
Port Scanning
Discover every open port and the service behind it across your hosts, from common web ports to forgotten admin panels.
DNS Enumeration
Map subdomains, records and mail configuration to surface the full footprint an attacker would enumerate first.
SSL/TLS Analysis
Grade every certificate and cipher: expiry, chain of trust, protocol versions and weak configurations.
Web & App Security
Actively confirm injection, broken access control (IDOR / BFLA) and auth-bypass against the OWASP Top 10, not just flag it.
Security Score Tracking
A single 0 to 100 score per target that trends over time, so you can watch posture improve scan after scan.
Scheduled Scans
Run scans daily, weekly or on every deploy, and get alerted the moment something regresses.
Compliance Reports
Export audit-ready reports mapped to SOC 2, ISO 27001 and OWASP, ready to hand to auditors.
Asset Discovery
Continuously discover new hosts, subdomains and services so nothing slips outside your known surface.
Secrets & Data Exposure
Catch API keys leaked in JS bundles and BaaS databases (Supabase, Firebase) left readable without access control.
Workflow
How It Works
From a target to a ranked list of fixes, in four steps.
Add Target
Point Cystene at a URL, domain or host. No agent to install, no code to change.
Configure
Pick the engines, depth and schedule, or accept the sensible defaults and go.
Run
One scan fans out across all 20 engines and maps the whole surface in minutes.
Review
Read findings ranked by severity, each with the CWE, the OWASP class and a concrete fix.
Who it's for
Freelance Dev
Ship client sites knowing they are clean. Run a scan before every handoff and attach the report.
DevOps
Wire scans into CI so every deploy is gated on a passing security score, with no manual step.
Security & Compliance
Track posture across every asset, export audit-ready evidence and prove controls to auditors.
Scan → Rank → Fix → Sealed
Every host, every port, every finding, closed.
CLI & API
Scan from your terminal or CI.
A scan is one command away, on your machine or on every deploy.
Cystene CLI
Scan from your shell in one command, no dashboard needed.
GitHub Action
Drop it into CI and gate every deploy on a passing security score.
REST API
Kick off scans and pull ranked findings straight into your own tooling.
Install it, then scan your app right now:
MCP
Scan from your AI assistant.
Run scans and read findings in plain English. Connect your favorite AI tool to the Cystene MCP server.
Claude Desktop
Anthropic's desktop app for macOS & Windows
VS Code / Cursor
IDE extensions with MCP support
Claude Code / CLI
Terminal-based AI coding assistants
Connect remotely with zero install. Paste the URL in your client:
Pricing
Simple pricing. Scale when you ship.
Base scans your sites on demand. Pro adds scheduled monitoring, automation and compliance. Enterprise adds credentialed internal scanning for SSH, cloud and AD/LDAP.
Base
For a couple of sites, scanned on demand.
- 2 targets / month
- Full external scanning suite
- On-demand scans
- Security score and findings
- Standard reports
Pro
For teams shipping to production.
- 10 targets / month
- Full external scanning suite
- Scheduled scans (daily, weekly, monthly)
- CI and GitHub Action
- REST API and MCP access
- Compliance reports (SOC 2, ISO 27001)
Enterprise
For security teams and pentesting firms.
- 50 targets / month
- Everything in Pro
- Credentialed internal scans (SSH, cloud, AD/LDAP)
- Team members and roles
- Executive and delta reports
- Priority support and commercial usage
Contact
Talk to us
Have a target you want scanned, or a question about the platform? Reach out and we'll get back to you.
Studio
52 Grigore Alexandrescu Street, Bucharest