Straightanswers.

What Cantic tests, how safe it is, how it supports compliance, and what it costs.

The basics

What is Cantic?
An autonomous red team for regulated companies. Our in-house model, Cantic Eclipse, maps what you expose, attacks it the way a criminal would, proves every finding with a working exploit, ships the fix, and attacks again to confirm it held.
How is it different from a vulnerability scanner?
Scanners match signatures against a database and report what might be wrong. Eclipse works through your systems the way an attacker would, chaining findings and testing authentication and business logic, and only reports what it can demonstrate.
How is it different from an annual pentest?
An annual pentest is a snapshot that arrives as a long PDF. Cantic attacks weekly or daily, proves each finding live and ships the fix, so the gap between exposure and repair is measured in hours, not quarters.
What does it cost?
The first probe is free: one domain, signed rules, findings on the table. After that, Core (weekly attacks, NVD + KEV alerts, supplier advisories) and Fortify (daily attacks, fixes within 24 hours, 10-hour incident response) are priced by scope. Ask for a quote.
Do we need to install anything?
No. Eclipse tests from the outside, the way an attacker would, so there is nothing to install or instrument.

Safety and data

Is it safe to run against production?
Yes. Eclipse is read-only by design and runs with rate limits and timeouts, so it probes and observes without touching your data or your performance.
Can it modify, delete or exfiltrate data?
No. It probes and observes; it cannot modify, delete or exfiltrate data from the systems it tests.
How do you make sure only authorised systems are tested?
Every engagement starts with a signed authorization and rules of engagement. Recurring testing additionally requires domain verification through a DNS record or file upload.
Can we stop an engagement?
Yes. A running engagement can be revoked within 60 seconds, and every action is signed into a ledger you can inspect.
How is our data handled?
Findings are encrypted at rest and handled under NDA. Free probe reports are kept for 14 days unless you subscribe. See our privacy policy.

Compliance

Does Cantic help with DORA, PCI DSS or ISO 27001?
Yes. We produce dated, signed evidence of testing, remediation and retesting that maps to the testing requirements in DORA, PCI DSS v4.0, ISO/IEC 27001, SOC 2 and NIST CSF 2.0. Your auditor decides what satisfies a control. See the mapping.
Does it replace regulator-mandated red-team tests?
No. Threat-led tests such as TLPT have their own rules for who performs them. Cantic keeps you tested continuously between those exercises, so they find less.

Findings and fixes

Are there false positives?
Every finding comes with a working exploit. If Eclipse can’t demonstrate it, it isn’t reported as a finding.
How fast does a fix arrive?
On Fortify, verified fixes arrive as pull requests within 24 hours. We then attack again to confirm the issue stays closed.
Can we watch the testing?
Yes. You can follow an engagement in real time, and every finding comes with a step-by-step replay.
Can we dispute a finding?
Yes. Tell us and a person on our team will re-check it.

Stillcurious?

Ask the people who built it. We reply within one working day.