What buyers, security teams and legal ask before they commit: how continuous works, what it costs, what we touch, and where data lives.
Agents hunt your live external web and API surface on a standing schedule. After each customer-approved release we run an intensive pass; between releases we keep quieter overwatch. Findings ship with a working PoC and a pipeline-signed report — not a scan dump.
See the product →A scanner lists what might be there; you verify every flag yourself. We prove what an attacker can actually do on the live system: PoC, severity, retest after you fix. Scanners still have a job — this is the standing hunt that follows releases.
Start the free check →Fixed scope, fixed price, report on a timeline. A bounty has no coverage guarantee and no cadence. You need a dated report for SOC 2 and customer questionnaires; that is what the standing hunt produces.
Sample report →Yes. Growth and above can trigger an intensive pass from your pipeline after a release you approved. Quiet overwatch keeps running between those kicks. The portal shows mandate status and findings.
See pricing →The free check is a short read-only pass (~20 minutes) with a written note. On a paid plan, the first intensive hunt typically lands within the first cycle after authorization is signed and the plan is live — exact timing depends on surface size.
Start the free check →We pause the affected path. You hear about it within 4 hours on the agreed channel. Nothing destructive runs without written sign-off.
Sample report →Published flat tiers: Starter €99/month (one deep hunt/month), Growth €499/month (continuous on one app), Pro €999/month, Business €2,499/month. Annual billing saves about 20%. No per-scan fees.
See pricing →Agents hunt; findings are validated with PoCs; you get a pipeline-signed report. If a contract requires a named third-party human tester letter, budget that engagement separately — that is not this product.
Pricing FAQ →Onboarding and scoping in the portal, validated findings with PoC, retests on the plan surface, and a downloadable report. Retests of fixed findings are not an add-on meter.
Trust →Monthly plans renew until you cancel in the billing portal. Upgrade or switch interval there as well. Annual is billed up front for the year.
Account billing →Surface count and cadence. Starter is one deep hunt per billing period on one app; Growth+ is continuous with release-triggered CI. Before the first hunt you verify domain ownership (DNS TXT on `_rheono-challenge` or a well-known file) and sign the written authorisation. Bigger estates move to Pro, Business, or Enterprise (custom, in writing).
See pricing →External web apps and APIs you authorize in writing. Internal networks, mobile binaries, and red-team social engineering are out of scope for the standing hunt — ask sales if you need a separate engagement.
Pentest page →Read-only: at most ~300 page requests at ~1/sec from one US IP. No logins, no exploit payloads, no port scanning. Permanent opt-out is one word. Method is written on /security.
How we check →Yes as a flat add-on, in writing. With repo access the agent reads each release diff for data-flow and auth issues; findings include file:line plus a working PoC.
Contact →The pipeline produces a signed report with NIS2 / ISO 27001-ready evidence mapping and CVSS. A named person is accountable in the contract; today that is Samir Abis.
Trust →In the EU only. Sub-processors: Google Cloud (EU region) and PostHog Cloud EU (Frankfurt), used only after your consent. Encrypted in transit and at rest, least-privilege access, append-only logging.
Privacy →You are the controller, we are the processor, under a DPA (Art. 28 GDPR). A data-protection incident is reported to you within 24 hours.
DPA (Art. 28) →The report is signed with an advanced electronic signature (eIDAS, PAdES-B-T) plus a qualified timestamp, and kept for 10 years. It is yours.
Sample report →Insurance: €50M per claim, without deductible (AGB §14). Before anything runs, your written authorization with rules of engagement is in force for 90 days.
Trust →Ask it directly; a named person answers, in writing, the same day.