SaaSFort

About SaaSFort

A security claim is worth what its evidence is worth.

SaaSFort exists because most external security reports hand over a score and ask to be believed. Ours hands over the observation: 66 controls across 25 categories, each finding carrying the raw evidence behind it and the moment it was observed.

What we build

An engine that measures an external perimeter the way a reviewer would want it measured: a fixed control set, a raw observation per finding, a timestamp, and a mapping to the framework the reviewer is accountable to.

Any exposure of a file or a sensitive path is confirmed by signing the content and comparing it with a reference response, which rules out catch-all handlers and soft-404s. A finding that cannot be demonstrated is not reported.

This is automated external-surface analysis. It is complementary to a manual penetration test, it does not replace one, it carries no certification from an accreditation body, and it does not detect business-logic flaws.

"Every finding, with the evidence it was derived from and the moment it was observed."

-- SaaSFort evidence standard

What we stand for

1

Verifiability

Every finding ships with the raw evidence behind it -- observed headers, certificate chain, negotiated cipher suites, DKIM selectors tested, response excerpts -- and its timestamp. A reviewer checks the observation instead of trusting a score.

2

Reproducibility

A fixed, published control set. The same domain measured twice yields the same result, so a finding can be contested, re-run and compared over time.

3

Stated scope

Automated external-surface analysis. Complementary to a manual penetration test, never a replacement for one, and it does not cover business-logic flaws. We say so on every page.

4

No unsourced numbers

No customer counts, no deal figures, no testimonials we cannot attribute. Third-party statistics carry their source or they do not appear.

5

Framework fidelity

Mapping to OWASP Top 10 (2021), NIS2 Article 21(2), ISO/IEC 27001:2022 Annex A and DORA happens in the engine, against the published text of each framework.

Evidence standard

What a security department gets, check by check

  • 66 controls across 25 categories

    A fixed, published control set. The same domain measured twice yields the same result, so a finding can be contested, re-run and compared.

  • Raw evidence and a timestamp on every finding

    Observed headers, certificate chain, negotiated cipher suites, DKIM selectors tested, response excerpts. A reviewer verifies the observation instead of trusting a score.

  • Mapped to OWASP Top 10 (2021), NIS2 Article 21(2), ISO/IEC 27001:2022 Annex A and DORA

    Mapping happens in the engine, so the export goes to the auditor without re-formatting.

  • Exposure confirmed by content signature

    Any exposed file or sensitive path is confirmed by signing the content and comparing it with a reference response, which rules out catch-all handlers and soft-404s.

SaaSFort performs automated external-surface analysis. It is complementary to a manual penetration test, not a replacement for one, and it does not detect business-logic flaws.

Measure your external surface

Start with a free scan. No signup required.