Security and compliance for companies without a security team Sign in (preview) Experiencing an incident?
Private preview

Know if you’re secure. Fix what matters. Prove it.

For 25–500-person companies without a security team: one honest security number, the fixes that move it, and the proof.

Get a demo

  • Read-only
  • Nothing installed
  • Plain English

You bought tools. Still no answer.

Are we OK, and what do we fix first?

88%

of breaches at small and mid-sized businesses involved ransomware

Verizon DBIR, 2025

~$115K

median ransom, among victims that paid

Verizon DBIR, 2025

The Confidence Console

One number. One verdict. Three fixes.

Every figure says where it came from. Open the numbered points to see how.

clearfend · confidenceSample data · illustration

Where you stand

Confidence

latest snapshot · sample tenant

Confidence score

Level 2 · Coverednext: Audit-Ready

14 self-declared6 observed3 derived

1 · Score provenanceEvery input is marked self-declared, observed, derived or sample, and the number is only as confident as those inputs. Nothing shows as live unless a live source wrote it.

Verdict

Mostly. Three fixes need a decision.

One deploy key can reach customer data, and two admin accounts have no second factor.

MFA · open2 gates to Level 3
2 · The verdictOne sentence for whoever runs the company: what the number means and what needs a decision this week. Levels are gates, not averages, so good backups never hide missing MFA.

What changed · since last snapshot

  • ▼ −4Payroll vendor let its SOC 2 report lapse
  • ▲ +2Backups restored in a test
4 · What changedThe console compares the two latest snapshots and lists every change with its reason, regressions first, so a slide never hides behind a steady number.

Fix Queue · ranked by severity × reach

3 of 17 open

1crit Scope down the CI/CD deploy keyAdmin scope on the production account customer DB · 2 hops Owner: Platform lead Runbook · 6 steps 3 · A fix with an owner and a runbookThis key reaches customer data in two hops, so it outranks louder alerts. Each fix carries a named owner and runbook steps grounded in a control register, not improvised.
2high Enforce MFA on two admin accountsIdentity provider AWS prod · 3 hops Owner: IT manager Runbook · 4 steps
3ai Give the support-agent token an ownerMachine identity, never rotated ticket data · 1 hop Owner: unassigned Runbook · 3 steps

Sample data · illustration. Not a customer.Every screen shown here is in the console today.

Levels are gates, not averages.

You are the level whose requirements you fully meet.

Why a snapshot stops at Level 2: Level 3 needs proof that holds every day, so until continuous evidence is real the engine caps itself at Level 2.

See the path. Cut it once. Prove it three ways.

01 · Know where you stand

The estate as a map

Connect read-only. The graph shows what can reach your crown jewels.

02 · Fix what matters

The choke point first

A fix where paths meet cuts the most of them, so it ranks first.

03 · Prove it

Recorded once

One fix closes the finding, clears the drift and adds evidence.

OpenVerified
Scope down the CI/CD deploy key
Fix Queue #1 · owner: Platform lead
Confidence
sample
71 +9 from 62
Estate graph illustration, sample data Three attack paths start at the internet, through a staff laptop and admin account, a GitHub repo and CI/CD pipeline, and a payroll vendor and support-agent token. All three meet at one choke point, the CI/CD deploy key, which reaches the AWS production account and the customer database, the crown jewel. Scoping down the deploy key cuts the path, and the sample score moves from 62 to 71. Internet Staff laptopphishing target GitHub repoleaked token Payroll vendorSOC 2 lapsed Admin accountno MFA CI/CD pipelineruns on every push Support agentAI · admin token CI/CD deploy keyadmin scope CHOKE POINT · 3 PATHS MEET AWS prodaccount Customer DBcrown jewel CROWN JEWEL NO PATH REACHES IT Estate graph illustration, sample data Three attack paths from the internet meet at one choke point, the CI/CD deploy key, which reaches the AWS production account and the customer database, the crown jewel. Scoping down the deploy key cuts the path, and the sample score moves from 62 to 71. Internet Laptopphishing GitHub repoleaked token Payroll vendorSOC 2 lapsed Adminno MFA CI/CD pipelineevery push Support agentAI token CI/CD deploy keyadmin scope CHOKEPOINT AWS prodaccount Customer DBcrown jewel CROWN JEWEL CUT
  • Attack path
  • Choke point
  • Crown jewel
  • Cut by the fix
Illustration · sample data

Fix once. Prove three ways.

You never record the same thing twice.

Fix Queue
CI/CD deploy key over-scoped
finding closed
Controls
SOC 2 CC6.1 · logical access
drift cleared
Evidence
Audit trail
+1 evidence line

One plain question per module.

Each one says honestly whether it is in the console, in private preview, or not built yet.

In the console

What a design partner gets on day one.

Confidence

Are we OK?

One 0–100 number, every input labelled with its source.

Fix Queue

What do I fix first?

Every finding in one list, ranked by what it can reach.

Estate

What can an attacker reach?

Choke points and crown jewels on one graph.

Controls

Are we audit-ready?

Plain-English controls scored net of drift. A readiness view, not a certificate.

Evidence

Can we prove it?

An evidence trail you can show a customer; auditor-grade signing is in build.

Leadership summary

What does the owner read?

One page for the person who signs, every figure sourced.

Sources

How does my real data get in?

Every source, its scope and when it last answered. The read-only readers are still being built.

Private preview

Built, off the main menu. Ask us to switch it on.

Application Security

Is our code safe to ship?

15 pattern checks and secret detection on an allow-listed GitHub repo. Deterministic pattern matching, not an AI review. Dependency scanning and SBOM are not built yet.

Secure by Design

Is this project safe to launch?

For in-house projects: classify the data, review the architecture, assess against NIST CSF 2.0, and take gaps to a go-live gate with owner-approved exceptions. Vendor and partnership intake are not built yet.

Vendor Risk Assessment

Is this vendor safe to onboard?

A company baseline, AI and NIST checklists and a structured SOC 2 review, scored green, amber or red, with a self-service questionnaire link for the vendor. Document upload is not built yet.

Pen Testing & Threat Modeling

Can we be broken into?

A passive external web scan runs on any public target with just an acknowledgement; active checks need you to prove you own the target. Not a human red team; threat modeling is not built yet.

Cloud & Identity

Is our cloud configured safely?

CIS-style checks over what you declare today.

AI Estate

What AI is running, and is it governed?

Apps, agents, MCP servers and the keys behind them.

Human Risk

Will my team get phished?

Access and training per person, from the roster you declare.

Risk Register

What have we accepted, and who signed for it?

Accepted risk with an owner, a treatment and a date.

Not built yet

Named, because hiding the gap would be dishonest.

Triage & Threat Intel

Is something happening right now?

Not built. No alert ingestion, queue or on-call.

How we protect your data.

Enforced in code today. Anything still being built is labelled.

Built to align with SOC 2, ISO 27001, NIST CSF, the NIST AI Risk Management Framework, and ITIL practices.

  • A closed databaseThe API is its only client. No public endpoint.
  • Tenant isolation that fails closedRow-level security on every tenant table; no tenant context, no rows.
  • Read-only, yours to revokeTime-boxed access. No passwords asked, nothing changed.
  • Tamper-evident audit trailAppend-only and hash-chained, re-verified on export.
  • AI that cannot actIt explains with citations. Prompts are scrubbed of emails, tokens and keys.
  • Your data stays yoursNever sold, shared, or used to benchmark anyone else.
  • Every number sourcedSelf-declared, observed, derived or sample. Missing evidence shows stale, never green.
  • Honest statusIn the console, private preview, or not built yet, on every module.

Plain pricing, published before launch.

Three tiers, priced per user. No quote wall.

Free

Know where you stand

free

  • Your confidence score and maturity level
  • Your top fixes, in plain English
Team

The full console

per user · published at launch

  • Fix Queue, Risk Register and Estate
  • Controls, scored net of drift
  • An evidence trail you can show a customer; auditor-grade signing is in build
  • Continuous monitoring as read-only sources land
Complete

Every living program

per user · published at launch

  • Everything in Team
  • Vendor Risk Assessment, Secure by Design, AI Estate, Human Risk Private preview
  • Pen Testing & Threat Modeling and Application Security Private preview
  • Triage & Threat Intel Not built yet
  • Every price published before launch
  • Renewal increases capped in the contract
  • The waitlist locks the launch price for your founding term

Questions a skeptic would ask

Terms like living program and drift are in the glossary.

How new are you, really? Do you have customers?
We’re early, and we won’t pretend otherwise. Working software in private preview. We’re choosing our first design partners now. That is why there are no logos, testimonials or “trusted by” wall here. Being early gets you the launch price locked in, direct access to the people building the product, and a real say in what ships next.
Is this an audit, a pentest, or a certification?
No, no, and no. The console tells you where you stand and gets you ready for an auditor; it doesn’t replace one. Controls is a readiness view with drift, not a certificate. Pen Testing & Threat Modeling, in private preview, runs a passive external web scan on any public target and safe or active checks on targets you prove you own; it is not a human red team, and the threat-modeling half is not built yet.
Do you install anything? What access do you need?
Read-only by default. Any access you grant is time-boxed and revocable by you. We never ask for passwords and never change anything in your environment, and nothing goes on laptops. The read-only readers for Microsoft 365, Google Workspace, Okta and AWS are still being built, so today most inputs are declared, and labelled that way.
Where does the confidence number come from today?
From what you have declared and what modules can observe, and it says which. Every input is marked self-declared, observed, derived or sample. We do not show a “live” indicator unless a live source wrote the data. Honest and partial beats confident and wrong.
How is this different from Vanta or Drata?
They are competent products for the paperwork side of a compliance program. ClearFend starts from what an attacker can reach and treats compliance as one consequence of it: one ranked Fix Queue across controls, vendors, AI and machine identities, people, code and cloud. If checkbox automation is all you need, they’ll do.
What happens to our data?
It stays yours and is isolated per tenant inside the database. It is never sold, never shared, and never used to benchmark anyone else. Access you grant is time-boxed and revocable at any time. The trust section says how each of those is enforced.

One honest number. Then the fixes.

See the console on your own estate, read-only.

Design partners

We’re choosing our first design partners now.

  • You get the console on your own estate, the people building it, and the launch price locked for your founding term.
  • We ask for a fortnightly call while you onboard, and patience with anything in preview.
  • It suits 25–500 people facing a SOC 2 request, a questionnaire, a board asking “are we OK?”, or AI to govern.

Experiencing an incident?

Send us the details and a person at admin@clearfend.com will read them.

Report an incident

Report an incident

If you are in immediate danger or this is a crime in progress, contact local authorities.

Containment status

Required. Opens an email to admin@clearfend.com.

Get a demo

This composes an email to admin@clearfend.com. Nothing is sent until you press send in your mail app.

Required.