A full audit and retest every month, run by an agent that already knows your business — plus daily checks in between and a direct line to us for blue team support. We test only what you authorise.
You confirm you own the target, or hold written authorisation to have it tested. A scope you do not control is never accepted, and the scope gate is a deterministic rule — not a judgement call.
The agent reads and probes. Writes, deletions and anything persistent require an explicit flag and a second confirmation from you.
Proof is demonstrated with the smallest safe effect — a harmless echo, a canary, a boolean delta. No destructive commands, no binaries fetched, no persistence left behind.
Every attack lands on a disposable copy, never on the product your customers are using. Raw secrets stay out of the report and the logs — only the fact of exposure is recorded.
Rate limiting at ≤10 requests per second, timeouts, a circuit breaker on 5xx storms and an SSRF guard on internal addresses. You can stop a run — or the whole recurring schedule — at any moment.
Each cycle produces one report: what was tested, what was proven, the recommended fix and the re-test result. Remediation is advised — your team applies it; the agent never writes to your code.
By ticking the box you agree that Sintropyc, acting as data controller, may process the personal data you enter in this form for the purposes set out below. This consent sits alongside our Privacy Policy and Data Processing Addendum, which set out the full detail.
Only what you submit here: your first and last name, your role or position, the website or system URL you want tested, your answer about server access, and anything else you add. If you go on to pay, card details are handled by our payment provider — we never receive or store full card numbers.
Only the Sintropyc team and the service providers we need to operate — such as Paddle for payments and the providers on our Subprocessor list. We do not sell your data, and we do not use it for marketing, model training, case studies or investor materials unless you give separate, specific consent first.
Only as long as needed for the purposes above. If you don't become a customer, we delete the request once the enquiry is closed; audit findings and reports are kept for up to 12 months unless we agree otherwise; billing and tax records are kept for as long as the law requires.
Consent is voluntary and you can withdraw it at any time, and ask to see, correct or delete your data, by emailing support@sintropyc.com. Withdrawing consent does not affect processing already carried out before you withdrew it.
Thanks — we've got your details and will get in touch shortly to confirm scope, price and a start date for your continuous plan. Nothing is tested before you approve the scope in writing.