About SaaSFort
A security claim is worth what its evidence is worth.
SaaSFort exists because most external security reports hand over a score and ask to be believed. Ours hands over the observation: 66 controls across 25 categories, each finding carrying the raw evidence behind it and the moment it was observed.
What we build
An engine that measures an external perimeter the way a reviewer would want it measured: a fixed control set, a raw observation per finding, a timestamp, and a mapping to the framework the reviewer is accountable to.
Any exposure of a file or a sensitive path is confirmed by signing the content and comparing it with a reference response, which rules out catch-all handlers and soft-404s. A finding that cannot be demonstrated is not reported.
This is automated external-surface analysis. It is complementary to a manual penetration test, it does not replace one, it carries no certification from an accreditation body, and it does not detect business-logic flaws.
"Every finding, with the evidence it was derived from and the moment it was observed."
-- SaaSFort evidence standard
What we stand for
Verifiability
Every finding ships with the raw evidence behind it -- observed headers, certificate chain, negotiated cipher suites, DKIM selectors tested, response excerpts -- and its timestamp. A reviewer checks the observation instead of trusting a score.
Reproducibility
A fixed, published control set. The same domain measured twice yields the same result, so a finding can be contested, re-run and compared over time.
Stated scope
Automated external-surface analysis. Complementary to a manual penetration test, never a replacement for one, and it does not cover business-logic flaws. We say so on every page.
No unsourced numbers
No customer counts, no deal figures, no testimonials we cannot attribute. Third-party statistics carry their source or they do not appear.
Framework fidelity
Mapping to OWASP Top 10 (2021), NIS2 Article 21(2), ISO/IEC 27001:2022 Annex A and DORA happens in the engine, against the published text of each framework.
Evidence standard
What a security department gets, check by check
66 controls across 25 categories
A fixed, published control set. The same domain measured twice yields the same result, so a finding can be contested, re-run and compared.
Raw evidence and a timestamp on every finding
Observed headers, certificate chain, negotiated cipher suites, DKIM selectors tested, response excerpts. A reviewer verifies the observation instead of trusting a score.
Mapped to OWASP Top 10 (2021), NIS2 Article 21(2), ISO/IEC 27001:2022 Annex A and DORA
Mapping happens in the engine, so the export goes to the auditor without re-formatting.
Exposure confirmed by content signature
Any exposed file or sensitive path is confirmed by signing the content and comparing it with a reference response, which rules out catch-all handlers and soft-404s.
SaaSFort performs automated external-surface analysis. It is complementary to a manual penetration test, not a replacement for one, and it does not detect business-logic flaws.
Measure your external surface
Start with a free scan. No signup required.