Scroll to discover

/ Stacks we audit

/ Feature 01 of 05

Verified scope, no exceptions

Every target is proven yours via DNS TXT, HTML meta, or a .well-known file. The sandbox firewall pins egress to those IPs only — the agent physically can't reach anything else.

A new approach

It's time for a new approach.

targets / verify

example.com

verified

DNS TXT

soleye-verify=8f3a92b1

203.0.113.42 ALLOWED

203.0.113.43 ALLOWED

0.0.0.0/0 DENIED

/ Step 01

Verify the scope.

60 seconds. DNS TXT, meta, or .well-known. Then the firewall pins egress to your IPs only.

new scan

web-wordpress
web-shopify
api-graphql
subdomain-enum

/ Step 02

Pick a recipe, run it.

Deterministic toolkit — nuclei, sqlmap, wpscan, ffuf. Or schedule it on cron.

ai mission · running

claude-4-6

shell — http GET /admin
200 OK · 4.2KB
run_action(nuclei_tags)
found: cve-2024-2962
·chaining auth bypass…

/ Step 03

Agent chains the rest.

Pre-vetted scripted actions, typed parameters, no freeform shell. Cost-capped, audit-logged.

executive.pdf

Q1 attack surface review

1 critical

3 high

5 medium

2 low

/ Step 04

Reports land in your inbox.

Executive PDF for leadership, technical PDF with reproduction commands, JSON for Jira.

/ No-risk offer

Industry pentest starts at $50,000

$50,000

For you, the audit is free.

We run the full pentest. You read the report. You only pay if you decide to continue.

  1. Step 01

    Send the link

  2. Step 02

    We audit it free

  3. Step 03

    You get the proof

  4. Step 04

    We help fix it

Request a free audit

Free queue · 2–3 business days

Paid customers — scans start instantly

After the audit

We don’t just find it. We fix it.

A pentest report is half the work. Our engineers ship the patches, harden the stack, and review the next batch of code before it reaches prod.

Patch the findings

Critical SQLi, XSS, broken auth — our engineers ship the fix as a PR you can review.

Harden the stack

CSP, HSTS, secure cookies, WAF rules, secrets rotation — the boring stuff that closes 80% of risk.

Secure code review

We read the diff before you ship. Catches the next batch of bugs before they reach prod.

Incident retainer

Pager-style availability when something goes wrong at 3am. Ongoing security partnership.

Book a fix call

Free 15-min scoping · priced per finding or by retainer

/ Confidentiality

What we find stays with you.

  • / Encrypted

    Encrypted at rest

    AES-256 in your tenant. Per-org keys. We can't read your raw data even if we wanted to.

  • / Private

    Never shared

    No third-party sharing. No training. No marketing. Findings exist only between us and you.

  • / Deleted

    Wiped on request

    After the engagement closes, raw scan artefacts are purged. One click to delete everything early.

Pricing

One audit. Then we fix it.

One-time $99 audit. If we find issues, pick a fix package — priced by how serious the report turns out to be. No subscriptions, no auto-renewals.

/ Start here

Audit

$99one-time

One-time, per domain.

SLA · 1 business day

  • Full audit · engine baseline + manual review
  • PDF report + finding list + recommendations
  • Severity-tiered prioritisation
  • Personal manager throughout
Buy audit — $99

No subscription · one-off purchase

/ If we find issues

Pick a remediation tier — we fix it for you.

Tiers are framed by how many critical findings we patch — all other severities (high · medium · low · info) are included in every tier.

Fast turnaround, focused scope.

Quick Fix

$399one-time

1–2 critical findings · all other findings included.

SLA · 2 business days

  • Patch critical findings (up to 2)
  • All medium / low / info findings addressed
  • One config-fix (CSP / TLS / cookies)
  • Re-scan after fix to confirm closure

The default for most reports.

Standard

$899one-time

3–4 critical findings · all other findings included.

SLA · 3 business days

  • Patch critical findings (up to 4)
  • All other findings addressed
  • PR submitted for your code review
  • 30-day fix-warranty

When the report is rough.

Major

$1999one-time

Unlimited critical findings · everything addressed.

SLA · 5 business days

  • Patch every critical finding — no cap
  • All other findings addressed
  • Full hardening pass · CSP · HSTS · WAF
  • 60-day fix-warranty

/ Custom · Quote on scope.

Bigger system? Compliance scope? Multi-service?

Large systems · compliance · multi-service · retainer-style work.

SOC · Live
$soleye watch --tenant *
  • OKtg/@soleyeonline
  • OKemail/supportonline
  • triage queueactive
  • *uptime99.98%
  • *response<30 min

Operator · just now

“On it — give me 5 min.”

/ Your dedicated manager

A real human, always on call.

Every paid request gets a dedicated account manager. Questions about the report, scope changes, late-night incident triage, or just figuring out where to start — one chat away.

  • Avg response

    <30 min

    on Telegram, working hours

  • Office hours

    9–21 UTC

    incidents — 24/7

  • Languages

    EN · RU · DE

    no jargon, real answers

/ Get in touch

Start scanning.

A real human reads every message. Whether you want a free audit, a trial, or just a sanity check — pick a channel.

/ New request

Free queue · 2–3 business days · paid customers go first

/ Sister product

Skopio

Open-source intelligence on people, companies, infrastructure and leaks. Same engine that powers SolEye’s recon, but pointed at the public web — investigations, due-diligence, threat intel, brand monitoring.

  • Recon
  • Threat intel
  • Brand monitoring
  • Leak tracking
  • Due diligence
Explore skopio.io

When defence isn’t enough — see what attackers see.

/ Built by

Traflo Connection

Full-stack IT development studio. We ship web apps, SaaS platforms, AI tooling, and mobile products for fast-moving teams. SolEye is one of them.

  • Web · Next.js
  • Mobile · React Native
  • SaaS
  • AI agents
  • Cybersecurity
Visit trafloconnection.com

Need a custom build? Same team, different briefs.

SolEye community

Got a question or want to swap notes with other red-teamers? Drop into our Telegram — support lives there too.

Join the channel →