continuous security for early-stage teams

No security team. Ship anyway.

A standing pentest on your external web and API surface: after every release, human-verified, one flat annual fee. From your first enterprise questionnaire to Series A.

A 3D map of a company's external surface, root domain, hosts and endpoints, is drawn in green; one endpoint is flagged red as a high-severity signal and written up in a short report.

the shrinking window

Exploited long before it is known.

32.1 % of the vulnerabilities on CISA's Known Exploited Vulnerabilities list were already exploited before they were publicly disclosed. Mean time to exploit: 6 days in 2023, 4 hours in 2024.

source: VulnCheck, State of Exploitation 1H-2025

An annual pentest is a photo of one day. The window has closed. Coverage that runs after every release is what's left.

The same pipeline hunts live bounty programs.

Your hunt runs on the same pipeline, with a named researcher who verifies every PoC and signs the report.

Vercel
Zooplus
Exness
Crypto.com
RHE-009criticalCVSS 9.0Pending disclosure

Incorrect Authorization

Superhuman (formerly Grammarly) · Aug 28, 2026

  • RHE-003criticalEXNESS
  • RHE-018highWeb.com Bug Bounty

19 findings

Named researcher in every contract. Signed report with NIS2 / ISO 27001-ready evidence, CVSS-scored. A working PoC per finding.

We look at your live site first.

Read-only, in ~20 minutes: at most ~300 page requests at ~1 per second, from one US IP. No logins, no test payloads, no port scanning. Nothing reaches your systems.

You get a short written report: every item, what we saw, what an attacker could realistically do with it, and what it would cost you. It is yours whether or not anything follows.

How we check

Nothing scans until a researcher confirms your request. We reply within one business day.

Two buyers, one signed report.

One for your startup, one for the fund behind it. The signed report is the evidence both hand over.

startups, pre-revenue to Series A

The request is coming.

The first enterprise deal wants a security questionnaire; your API is exposed and you don't know it yet. The free check shows what an attacker sees. The signed report is what you hand over, retested after every release.

start with the free check
vc funds & accelerators

One security program for the whole portfolio.

Every portfolio company on the same signed, continuous coverage, with a single posture report across the batch. Diligence that does not cost you a deal. One group rate, one partner.

the portfolio program
three doors

One surface. Three doors.

standing hunt

The hunt, always on.

Your whole external surface, retested after every release. One flat annual fee, signed report, named signatory.

from €9,900 / year

how the hunt runs
deep audit

The one-off report.

One deep snapshot of your web app + API in 3–5 days: signed NIS2 / ISO 27001 report, a PoC per finding, one retest included.

€3,500 fixed

the audit, in writing
code-assisted

The code, read like an attacker.

Every release diff read for data-flow issues, missing auth checks and framework misconfigs — findings with file:line and a working PoC.

+€5,000 / year · +€1,500 audit

the code-assisted door

A report, or the hunt.

standing hunt · every release

from

€9,900/ year

Your whole external surface, retested after every release. Your external CISO on one flat annual fee, monthly on request, built for teams shipping monthly+ who need current, signed evidence. The fee does not grow with your release count.

How the hunt runs

A failed SOC 2 costs the enterprise deal you're trying to close. Your last pentest was a photo of one day; the standing hunt stays on, at one flat annual fee.

Replace the yearly snapshot.

Book 20 minutes and leave with a written annual fee, or a written decision not to proceed.