Scroll to discover

/ The problem

One annual pentest doesn't actually cover anything.

/ The old way

  • $50,000per engagement, once a year
  • 3 weeksof waiting for the report
  • 1 PDFstale on arrival
  • 12 monthsof silence between scans

/ The SolEye way

  • $99 / moStarter, no enterprise lock-in
  • 5 minutesto your first findings PDF
  • Continuousdaily, weekly, on every release
  • Live diffwhat changed since last scan
/ Feature 01 of 05

Verified scope, no exceptions

Every target is proven yours via DNS TXT, HTML meta, or a .well-known file. The sandbox firewall pins egress to those IPs only — the agent physically can't reach anything else.

Recipe catalog

Thirteen deterministic recipes.

Predictable coverage before the agent ever ships a packet. Pick by stack, schedule by cron, extend with your own.

RCP_001

Web · Generic

Target · URL

nuclei · ffuf · wapiti

RCP_002

Web · WordPress

Target · URL

wpscan · nuclei[wp] · sqlmap

RCP_003

Web · Shopify

Target · URL

nuclei · katana · custom

RCP_004

Web · Drupal

Target · URL

nuclei[drupal] · droopescan

RCP_005

Web · Joomla

Target · URL

joomscan · nuclei

RCP_006

Web · SPA

Target · URL

katana · linkfinder · jsmon

RCP_007

API · REST

Target · API

kiterunner · nuclei[api]

RCP_008

API · GraphQL

Target · API

graphql-cop · clairvoyance

RCP_009

Subdomain enum

Target · Domain

amass · subfinder · dnsx

RCP_010

TLS · deep

Target · Domain

testssl.sh · sslscan

RCP_011

Network · portscan

Target · IP / CIDR

nmap · masscan

RCP_012

Tech stack

Target · URL

wappalyzer · whatweb

RCP_013

Secrets · grep

Target · Domain

trufflehog · gitleaks

Plus 10 scripted AI actions the agent can call after — typed parameters, pre-vetted, no freeform shell.

A new approach

It's time for a new approach.

targets / verify

example.com

verified

DNS TXT

soleye-verify=8f3a92b1

203.0.113.42 ALLOWED

203.0.113.43 ALLOWED

0.0.0.0/0 DENIED

/ Step 01

Verify the scope.

60 seconds. DNS TXT, meta, or .well-known. Then the firewall pins egress to your IPs only.

new scan

web-wordpress
web-shopify
api-graphql
subdomain-enum

/ Step 02

Pick a recipe, run it.

Deterministic toolkit — nuclei, sqlmap, wpscan, ffuf. Or schedule it on cron.

ai mission · running

claude-4-6

shell — http GET /admin
200 OK · 4.2KB
run_action(nuclei_tags)
found: cve-2024-2962
·chaining auth bypass…

/ Step 03

Agent chains the rest.

Pre-vetted scripted actions, typed parameters, no freeform shell. Cost-capped, audit-logged.

executive.pdf

Q1 attack surface review

1 critical

3 high

5 medium

2 low

/ Step 04

Reports land in your inbox.

Executive PDF for leadership, technical PDF with reproduction commands, JSON for Jira.

Pricing

Three doors. Same engine.

Premium positioning — no free tier. 14-day pilot for $1.

01/ Starter

Starter

$99/ month

Solo founders, single-domain SaaS, side-projects you still ship.

  • 1 verified target
  • 9 scans / month
  • 1 weekly schedule
  • 3 starter recipes
  • Executive + technical PDF
  • Email alerts
  • AI offensive mission
Most popular
02/ Growth

Growth

$299/ month

The one most teams pick. AI agent on, daily scans, full recipe library.

  • 5 verified targets
  • 60 scans / month
  • 10 schedules
  • Full recipe library — all 13
  • AI offensive mission included
  • Slack / Telegram / webhook alerts
  • Per-org Anthropic key supported
03/ Enterprise

Enterprise

Custom/ talk to us

Custom recipes, dedicated AI tuning, white-label PDF, SLA, self-host option.

  • Unlimited targets & scans
  • Custom recipes for your stack
  • White-label PDF reports
  • Dedicated AI cost ceiling
  • SOC 2 evidence pack
  • Self-host license available
  • Named slack channel + SLA

/ Get started

Stop hoping no one's looking.
Start scanning.

14-day pilot for $1. First findings PDF in five minutes.

SolEye community

Got a question or want to swap notes with other red-teamers? Drop into our Telegram — support lives there too.

Join the channel →