Your external security posture, measured continuously. Evidence, not assertions.
Every finding is returned with its raw evidence and its timestamp, mapped to OWASP Top 10 (2021), NIS2 Article 21(2), ISO/IEC 27001:2022 Annex A and DORA. An automated external-surface analysis, complementary to a manual penetration test.
No account required · Free forever · Results in under 60 seconds
66 checks · 25 categories · A–F grade
OWASP, NIS2 & ISO 27001 mapping included
Built for SaaS, fintech, healthtech, and MSPs across the EU
How It Works
From measurement to an auditable file in 3 steps
No onboarding call. No agent to install. Enter your URL and let SaaSFort handle the rest.
Scan Your Domain
< 1 hourEnter your URL — SaaSFort runs a full OWASP Top 10, CVE, SSL/TLS, and API security scan automatically. No agent to install, no config required.
Get the Evidence Report
< 24 hoursA PDF that carries each finding with its raw evidence and timestamp, mapped to OWASP Top 10 (2021), NIS2 Article 21(2), ISO/IEC 27001:2022 Annex A and DORA.
Hand it to the reviewer
Days, not weeksA security department can verify each observation, contest it, and have the check re-run on the same control set. The file stands on its own.
Product
Measurement that holds up under review
Every capability exists for one reason: a finding a reviewer can verify, contest and re-run.
Continuous Web Scanning
OWASP Top 10, CVE tracking, SSL/TLS, and API security — automated on a schedule matching your release cadence. Weekly, daily, or continuous.
Evidence Reports
Each finding carries the raw evidence behind it — observed headers, certificate chain, negotiated cipher suites, DKIM selectors tested, response excerpts — and its timestamp.
Remediation Copilot Soon
Fix guidance ordered by measured exposure, with the observed evidence attached to each recommendation. Code snippets per stack included.
Exposure Confirmed, Not Guessed
Any exposed file or sensitive path is confirmed by content signature and compared with a reference response, which rules out catch-all handlers and soft-404s.
CI/CD Integration
Connect to GitHub Actions, GitLab CI, or Jenkins. Catch vulnerabilities before they reach production — and before your customer finds them.
NIS2 & ISO27001 Mapping
Map findings to compliance frameworks automatically. Answer security questionnaires in hours, not weeks. Available on Scale plan.
Evidence standard
What a security department gets, check by check
66 controls across 25 categories
A fixed, published control set. The same domain measured twice yields the same result, so a finding can be contested, re-run and compared.
Raw evidence and a timestamp on every finding
Observed headers, certificate chain, negotiated cipher suites, DKIM selectors tested, response excerpts. A reviewer verifies the observation instead of trusting a score.
Mapped to OWASP Top 10 (2021), NIS2 Article 21(2), ISO/IEC 27001:2022 Annex A and DORA
Mapping happens in the engine, so the export goes to the auditor without re-formatting.
Exposure confirmed by content signature
Any exposed file or sensitive path is confirmed by signing the content and comparing it with a reference response, which rules out catch-all handlers and soft-404s.
SaaSFort performs automated external-surface analysis. It is complementary to a manual penetration test, not a replacement for one, and it does not detect business-logic flaws.
Context
What a third-party security review costs today
Published figures, each with its source. Nothing here comes from our own customer base.
of B2B SaaS deals are delayed by security reviews
Vanta State of Trust Report 2024cost of a single traditional pen test engagement
SANS Pen Test Survey 2024of CTO time spent on security questionnaires during enterprise sales
Cisco CISO Benchmark Report 202417,500 German companies missed the BSI NIS2 deadline. Enforcement is active — prove your compliance posture today.
Try a Free ScanWhy SaaSFort
Where an automated external analysis fits
A manual penetration test and an automated external analysis answer different questions. This is what each one covers, and where SaaSFort sits.
| Manual Pen Test | Detectify / Intruder | SaaSFort | |
|---|---|---|---|
| Price | €5K–€20K per test | €90/mo | €49/mo |
| Time to first report | 4–8 weeks | < 24h (dev only) | < 10s scan · < 24h Evidence Report |
| Raw evidence per finding | Yes, manual write-up | Partial | Yes, with timestamp |
| Continuous monitoring | No | Yes | Yes |
| CI/CD integration | No | Yes | Yes |
| NIS2 & ISO 27001 mapping | No | No | Yes |
| Business-logic flaws | Yes | No | No — out of scope |
| Synack, HackerOne | Detectify, Intruder, Probely | Try Free Scan |
Embed your security grade badge
on every page you ship.
Publish the grade you actually measured. Drop a live badge on your homepage footer, security page, vendor portal, or docs, and every visitor click runs a fresh measurement of your domain. The badge always reflects the latest scan, never a cached claim.
- Auto-refreshing: badge always shows your latest scan grade
- One
<img>tag. No JS, no iframe, no tracker - Works in your footer, GitHub README, vendor portal, or trust page
No account required for the scan. Badge becomes available the moment your scan finishes.
<a href="https://saasfort.com/scan?domain=yourapp.com">
<img src="https://api.saasfort.com/api/widget/badge?domain=yourapp.com"
alt="SaaSFort Security Grade" />
</a>
Replace yourapp.com with your domain after your first scan. The badge automatically reflects your latest grade.
SaaS Security Leaderboard
How do Stripe, Slack, GitHub score on NIS2 external checks?
Public grades for 8 well-known SaaS domains: HTTP headers, DMARC, DNSSEC. See who passes, who fails, and where your own domain lands.
Free Whitepaper -- 30 Pages
The SaaS Security Playbook 2026
Enterprise buyers check 7 security control categories before signing. 78% of SaaS deals are delayed by security reviews. Our free playbook shows you exactly how to prepare -- with a 30-day action plan from Grade C to Grade A.
Pricing
Priced per measured perimeter.
Starter €49/month, Growth €149/month, Scale €399/month. 14-day free trial, no credit card required.
Annual billing bills 10 months instead of 12. An automated external-surface analysis is complementary to a manual penetration test, not a replacement for one.
See all plansFrequently asked questions
How is SaaSFort different from Detectify or Intruder?
How fast is the first scan?
Is this a replacement for a traditional pen test?
How does the Evidence Report help with procurement?
Can I integrate SaaSFort into my CI/CD pipeline?
Where is my data stored?
29,000+ EU entities must comply with NIS2 cybersecurity requirements. SaaSFort maps your scan results to NIS2 controls automatically. Prove compliance before the deadline.
Reference guides: SaaS Security Leaderboard: public NIS2 grades ·Security scan by use case ·NIS2 supplier questionnaire ·Prove SaaS security to enterprise buyers ·NIS2 audit evidence requirements ·NIS2 supply chain Article 21 ·How to answer a security questionnaire fast ·Vendor security assessment guide ·What a NIS2 audit costs
Measure your external surface.
Every finding comes back with the evidence behind it and its timestamp. Under 60 seconds.
No account needed · Results in seconds · Free forever