Vulnerability assessment · PCI 11.3

We scan and advise. We never attack.

Secure Assess is defensive external and credentialed vulnerability assessment. Scheduled scans, AI-triaged findings, PCI mapping, and a PDF report. ASV-readiness is a PASS or FAIL check — not an official attestation.

Sign up or request a license at app.secure-assess.com. We scan systems you authorize. We report and advise. We never attack.

What a finding looks like. Ranked, mapped, and written so an owner can act — without us acting for them.

# report excerpt — advice, not a change
finding  TLS 1.0 accepted on :443
scope    external · 203.0.113.10
pci      11.3.1  vulnerability identified
triage   high · expired protocol on a card-data path
advice   Disable TLS 1.0; require TLS 1.2+.

readiness  FAIL  # not an official ASV attestation

The report names the finding, the PCI 11.3 mapping, and the advice. Applying the change is yours. What the product does →

External + credentialed
Two views of the same authorized scope
PCI 11.3
Vulnerability assessment. Not 11.4
PASS / FAIL
ASV-readiness only — not an official attestation
PDF
A report you can hand to an owner
The product

Scan the scope you authorize. Leave it as you found it.

Six things the product does. Each one is a report or a schedule — never a change made on your network.

External

Defensive external assessment

Scan the internet-facing surface you authorize. We identify what is exposed and what it means. We do not attack it.

Credentialed

Credentialed assessment

When you provide credentials, we assess from the inside of the systems you named. Still defensive. Still advice, not a change to the host.

PCI 11.3

PCI mapping

Findings are mapped to PCI DSS 11.3 vulnerability assessment. That is the requirement we cover. We do not perform PCI 11.4 penetration testing.

Cadence

Scheduled scans

Run on a schedule you set. Same scope, same report shape, so a quarter-to-quarter picture is comparable.

Triage

AI-triaged findings

The model ranks and explains findings so you know what to look at first. A human still decides. We do not apply fixes.

Evidence

PDF reports

A written report you can hand to an assessor, a merchant, or an internal owner. Findings, advice, and the readiness result.

Limits

What this is not

A readiness product that over-claims becomes a liability. These limits are part of the product, not fine print.

ASV-readiness is PASS or FAIL

A readiness check against the shape of an ASV scan. It is not an official ASV attestation and it is not a certificate you can present as one.

We never attack

No exploitation, no payloads, no offensive exercise. If a finding implies a path, we describe it as a finding — not as something we ran.

We report and advise

The product does not patch, remediates nothing on your behalf, and does not change the environment it scanned.

Pricing

Monthly. Sign up in the app — not a checkout on this site.

Free, Starter at $99/month, Pro at $399/month, Enterprise custom. Open the app to sign up or request a license. Enterprise talks to sales.

Starter

For a single card environment that needs a regular readiness picture.

$99 /month
Framed at $99.
  • Everything in Free
  • Priced for one environment
Start a scan

Free

Open the app and scan systems you authorize.

Free
No card required to start.
  • PCI readiness and vulnerability assessment
  • Findings with advice, not changes made for you
  • We scan and advise. We never attack.
Get started

Enterprise

Custom pricing. Contact sales.

Custom
Custom.
  • Everything in Pro
  • Custom scope and terms
Talk to sales

Compare the monthly tiers →

Start a scan on systems you authorize

We scan and advise. We never attack.