About
One person, in Lithuania
You are being asked to let a stranger’s software test your production systems and hold evidence of their weaknesses. “Who exactly am I trusting” is a fair question, and a vague “we” is a worse answer than a name.
Why this exists
TBD This section is the founder’s own account and has not been written yet. It will not be filled with a generated origin story — that would be the one piece of fiction on the page whose whole value is that it is not.
How it is built
Coverage is recorded, not assumed
Every run stores what it checked and what failed. A scan that broke is never reported as a scan that found nothing.
Nothing is tested without proof of control
Verified, re-verified on a schedule, and explicit recorded consent before anything that sends attack-style traffic.
No claim of completeness
Not on this site and not in the contract. Automated testing cannot find everything, and a vendor who says otherwise is telling you something you can check.
Built to be usable
There is a published accessibility audit and a screen-reader review — read it here — which is an unusual thing for a security tool to have, and it is there because a tool nobody can operate protects nobody.
If something happens to me
A one-person vendor is a real continuity risk. Here is what already exists, rather than a reassurance.
- Your data leaves whenever you want: a full account export, and erasure that actually deletes.
- Backups that have been restored, not backups that merely exist. The recovery runbook is written and the restore has been rehearsed.
- A public status page with incident history — an odd thing to build if the plan were to hide outages.
- No lock-in worth the name: findings leave by API, by export, and into your own issue tracker.
Who to contact
TBD The company is being incorporated. Registration details and contact addresses will appear here once they exist, rather than as a placeholder pretending to be a company.