Know if you’re secure. Fix what matters. Prove it.
For 25–500-person companies without a security team: one honest security number, the fixes that move it, and the proof.
- Read-only
- Nothing installed
- Plain English
You bought tools. Still no answer.
Are we OK, and what do we fix first?
of breaches at small and mid-sized businesses involved ransomware
Verizon DBIR, 2025
median ransom, among victims that paid
Verizon DBIR, 2025
One number. One verdict. Three fixes.
Every figure says where it came from. Open the numbered points to see how.
Where you stand
Confidence
latest snapshot · sample tenant
Confidence score
Level 2 · Coverednext: Audit-Ready
14 self-declared6 observed3 derived
Verdict
Mostly. Three fixes need a decision.
One deploy key can reach customer data, and two admin accounts have no second factor.
What changed · since last snapshot
- ▼ −4Payroll vendor let its SOC 2 report lapse
- ▲ +2Backups restored in a test
Fix Queue · ranked by severity × reach
3 of 17 open
Sample data · illustration. Not a customer.Every screen shown here is in the console today.
Levels are gates, not averages.
You are the level whose requirements you fully meet.
Why a snapshot stops at Level 2: Level 3 needs proof that holds every day, so until continuous evidence is real the engine caps itself at Level 2.
Exposed. Basic gaps are open and nobody is assigned to look.
Covered. The five core controls hold. The next questionnaire stops being a guess.
Audit-Ready. Controls proven every day, not set up once.
Resilient. You can detect, respond and recover, and have shown it.
Adaptive. Exercised and improving. Most companies never need it, and we’ll say so.
See the path. Cut it once. Prove it three ways.
The estate as a map
Connect read-only. The graph shows what can reach your crown jewels.
The choke point first
A fix where paths meet cuts the most of them, so it ranks first.
Recorded once
One fix closes the finding, clears the drift and adds evidence.
sample 71 +9 from 62
- Attack path
- Choke point
- Crown jewel
- Cut by the fix
Fix once. Prove three ways.
You never record the same thing twice.
One plain question per module.
Each one says honestly whether it is in the console, in private preview, or not built yet.
What a design partner gets on day one.
Confidence
Are we OK?
One 0–100 number, every input labelled with its source.
Fix Queue
What do I fix first?
Every finding in one list, ranked by what it can reach.
Estate
What can an attacker reach?
Choke points and crown jewels on one graph.
Controls
Are we audit-ready?
Plain-English controls scored net of drift. A readiness view, not a certificate.
Evidence
Can we prove it?
An evidence trail you can show a customer; auditor-grade signing is in build.
Leadership summary
What does the owner read?
One page for the person who signs, every figure sourced.
Sources
How does my real data get in?
Every source, its scope and when it last answered. The read-only readers are still being built.
Built, off the main menu. Ask us to switch it on.
Application Security
Is our code safe to ship?
15 pattern checks and secret detection on an allow-listed GitHub repo. Deterministic pattern matching, not an AI review. Dependency scanning and SBOM are not built yet.
Secure by Design
Is this project safe to launch?
For in-house projects: classify the data, review the architecture, assess against NIST CSF 2.0, and take gaps to a go-live gate with owner-approved exceptions. Vendor and partnership intake are not built yet.
Vendor Risk Assessment
Is this vendor safe to onboard?
A company baseline, AI and NIST checklists and a structured SOC 2 review, scored green, amber or red, with a self-service questionnaire link for the vendor. Document upload is not built yet.
Pen Testing & Threat Modeling
Can we be broken into?
A passive external web scan runs on any public target with just an acknowledgement; active checks need you to prove you own the target. Not a human red team; threat modeling is not built yet.
Cloud & Identity
Is our cloud configured safely?
CIS-style checks over what you declare today.
AI Estate
What AI is running, and is it governed?
Apps, agents, MCP servers and the keys behind them.
Human Risk
Will my team get phished?
Access and training per person, from the roster you declare.
Risk Register
What have we accepted, and who signed for it?
Accepted risk with an owner, a treatment and a date.
Named, because hiding the gap would be dishonest.
Triage & Threat Intel
Is something happening right now?
Not built. No alert ingestion, queue or on-call.
How we protect your data.
Enforced in code today. Anything still being built is labelled.
Built to align with SOC 2, ISO 27001, NIST CSF, the NIST AI Risk Management Framework, and ITIL practices.
- A closed databaseThe API is its only client. No public endpoint.
- Tenant isolation that fails closedRow-level security on every tenant table; no tenant context, no rows.
- Read-only, yours to revokeTime-boxed access. No passwords asked, nothing changed.
- Tamper-evident audit trailAppend-only and hash-chained, re-verified on export.
- AI that cannot actIt explains with citations. Prompts are scrubbed of emails, tokens and keys.
- Your data stays yoursNever sold, shared, or used to benchmark anyone else.
- Every number sourcedSelf-declared, observed, derived or sample. Missing evidence shows stale, never green.
- Honest statusIn the console, private preview, or not built yet, on every module.
Plain pricing, published before launch.
Three tiers, priced per user. No quote wall.
Know where you stand
free
- Your confidence score and maturity level
- Your top fixes, in plain English
The full console
per user · published at launch
- Fix Queue, Risk Register and Estate
- Controls, scored net of drift
- An evidence trail you can show a customer; auditor-grade signing is in build
- Continuous monitoring as read-only sources land
Every living program
per user · published at launch
- Everything in Team
- Vendor Risk Assessment, Secure by Design, AI Estate, Human Risk Private preview
- Pen Testing & Threat Modeling and Application Security Private preview
- Triage & Threat Intel Not built yet
- Every price published before launch
- Renewal increases capped in the contract
- The waitlist locks the launch price for your founding term
Questions a skeptic would ask
Terms like living program and drift are in the glossary.
How new are you, really? Do you have customers?
Is this an audit, a pentest, or a certification?
Do you install anything? What access do you need?
Where does the confidence number come from today?
How is this different from Vanta or Drata?
What happens to our data?
One honest number. Then the fixes.
See the console on your own estate, read-only.
We’re choosing our first design partners now.
- You get the console on your own estate, the people building it, and the launch price locked for your founding term.
- We ask for a fortnightly call while you onboard, and patience with anything in preview.
- It suits 25–500 people facing a SOC 2 request, a questionnaire, a board asking “are we OK?”, or AI to govern.
Experiencing an incident?
Send us the details and a person at admin@clearfend.com will read them.