Every question, answered in writing.

What buyers, security teams and legal ask before they commit: how continuous works, what it costs, what we touch, and where data lives.

How it works

What is continuous autonomous pentesting?

Agents hunt your live external web and API surface on a standing schedule. After each customer-approved release we run an intensive pass; between releases we keep quieter overwatch. Findings ship with a working PoC and a pipeline-signed report — not a scan dump.

See the product →
How is this different from a scanner?

A scanner lists what might be there; you verify every flag yourself. We prove what an attacker can actually do on the live system: PoC, severity, retest after you fix. Scanners still have a job — this is the standing hunt that follows releases.

Start the free check →
How is this different from a bug bounty?

Fixed scope, fixed price, report on a timeline. A bounty has no coverage guarantee and no cadence. You need a dated report for SOC 2 and customer questionnaires; that is what the standing hunt produces.

Sample report →
Does it plug into CI/CD?

Yes. Growth and above can trigger an intensive pass from your pipeline after a release you approved. Quiet overwatch keeps running between those kicks. The portal shows mandate status and findings.

See pricing →
How fast do I see findings?

The free check is a short read-only pass (~20 minutes) with a written note. On a paid plan, the first intensive hunt typically lands within the first cycle after authorization is signed and the plan is live — exact timing depends on surface size.

Start the free check →
What happens if you find a critical?

We pause the affected path. You hear about it within 4 hours on the agreed channel. Nothing destructive runs without written sign-off.

Sample report →

Pricing

What does it cost?

Published flat tiers: Starter €99/month (one deep hunt/month), Growth €499/month (continuous on one app), Pro €999/month, Business €2,499/month. Annual billing saves about 20%. No per-scan fees.

See pricing →
Is this a certified human pentest letter? No.

Agents hunt; findings are validated with PoCs; you get a pipeline-signed report. If a contract requires a named third-party human tester letter, budget that engagement separately — that is not this product.

Pricing FAQ →
What is included?

Onboarding and scoping in the portal, validated findings with PoC, retests on the plan surface, and a downloadable report. Retests of fixed findings are not an add-on meter.

Trust →
Can I cancel or change plan?

Monthly plans renew until you cancel in the billing portal. Upgrade or switch interval there as well. Annual is billed up front for the year.

Account billing →
What moves the price?

Surface count and cadence. Starter is one deep hunt per billing period on one app; Growth+ is continuous with release-triggered CI. Before the first hunt you verify domain ownership (DNS TXT on `_rheono-challenge` or a well-known file) and sign the written authorisation. Bigger estates move to Pro, Business, or Enterprise (custom, in writing).

See pricing →

Scope & safety

What surfaces do you cover?

External web apps and APIs you authorize in writing. Internal networks, mobile binaries, and red-team social engineering are out of scope for the standing hunt — ask sales if you need a separate engagement.

Pentest page →
Is the free check safe?

Read-only: at most ~300 page requests at ~1/sec from one US IP. No logins, no exploit payloads, no port scanning. Permanent opt-out is one word. Method is written on /security.

How we check →
Can you also look at our source code?

Yes as a flat add-on, in writing. With repo access the agent reads each release diff for data-flow and auth issues; findings include file:line plus a working PoC.

Contact →
Who signs the report?

The pipeline produces a signed report with NIS2 / ISO 27001-ready evidence mapping and CVSS. A named person is accountable in the contract; today that is Samir Abis.

Trust →

Data & trust

Where does our data live?

In the EU only. Sub-processors: Google Cloud (EU region) and PostHog Cloud EU (Frankfurt), used only after your consent. Encrypted in transit and at rest, least-privilege access, append-only logging.

Privacy →
How does GDPR work here?

You are the controller, we are the processor, under a DPA (Art. 28 GDPR). A data-protection incident is reported to you within 24 hours.

DPA (Art. 28) →
What happens to the findings and the report?

The report is signed with an advanced electronic signature (eIDAS, PAdES-B-T) plus a qualified timestamp, and kept for 10 years. It is yours.

Sample report →
Who is accountable if something goes wrong?

Insurance: €50M per claim, without deductible (AGB §14). Before anything runs, your written authorization with rules of engagement is in force for 90 days.

Trust →

Something not answered here?

Ask it directly; a named person answers, in writing, the same day.