Frequently asked questions
Everything customers ask us about vulnerability scanning, penetration testing, managed security services, compliance, pricing, and account security. Can't find your answer? Contact us.
Getting Started
What Cyvex is, how to sign up, and what to expect on day one.
What does Cyvex do?Getting Started
Cyvex provides continuous vulnerability scanning, penetration testing, managed security services, and compliance automation for SMEs worldwide, translating technical risk into clear, actionable business insight — without requiring you to hire a full in-house security team.
How do I get started with Cyvex?Getting Started
Start a free trial or book a demo from the pricing page. In your first hour you invite your team, connect a first asset (a domain, cloud account, or code repo), and configure where alerts should go — most customers see real findings by the end of day one.
Is there a free trial?Getting Started
Yes. The Standard scanning plan, designed for small organisations of up to 20 users, includes a 7-day free trial so you can see real findings before committing to a paid plan.
Do I need an in-house security or IT team to use Cyvex?Getting Started
No. Cyvex is built for founder-led teams with limited IT capacity — you get clear, prioritised actions rather than a raw vulnerability dump. If you want hands-on help, our managed security services team can act as a fractional security function alongside whatever internal capacity you already have.
Vulnerability Scanning
Continuous scanning, the engines behind it, and how it fits your environment.
What is the difference between continuous vulnerability scanning and a one-off scan?Vulnerability Scanning
A one-off scan is a point-in-time snapshot that ages out within days — by the time the report is delivered, your environment has already changed. Continuous scanning reruns on every change and on a nightly full-scope pass, so the list you act on today reflects the environment you have today. For SOC 2, ISO 27001, and cyber insurance renewal, continuous is now the expected posture.
Which scanning engines does Cyvex orchestrate?Vulnerability Scanning
Cyvex orchestrates OpenVAS for network and host coverage, OWASP ZAP, Wapiti, and w3af for dynamic web application testing, Nikto for web server checks, and Lynis for Linux system hardening. We normalise findings across all six into a single deduplicated queue instead of six separate reports.
Will scanning disrupt our production systems?Vulnerability Scanning
Scans are throttled and scheduled around your maintenance windows by default. Authenticated scans use least-privilege service accounts, and we support read-only agent modes for change-sensitive environments.
Do small businesses really need vulnerability scanning?Vulnerability Scanning
Yes. SMEs are frequently targeted because they are perceived as easier to breach, and insurers increasingly expect evidence of regular scanning as a condition of cover. Continuous scanning platforms like Cyvex are priced for SMEs, removing the need for expensive one-off assessments.
Penetration Testing
Penetration testing timelines, pricing, and retests.
Can we see a sample pen test report before we buy?Penetration Testing
Yes. Request a sanitized sample report from the penetration testing page — we share a redacted external-network and web-application report so you can review our writing, CVSS scoring, and remediation detail before committing.
How long does a penetration test take?Penetration Testing
A typical SME external and web-application test runs 5–10 working days end-to-end, with a further 5 working days for reporting. Larger or red team engagements run 3–6 weeks.
How much does a penetration test cost?Penetration Testing
Most SME engagements land between $7,500 and $22,500 depending on scope and test type. We issue a fixed-fee proposal after a 30-minute scoping call.
Does continuous vulnerability scanning replace penetration testing?Penetration Testing
No — and it should not. Continuous scanning catches the known and the automatable; penetration testing catches the business-logic and chain-of-attack issues scanners will miss. Customers typically run both: continuous scanning year-round, a professional pen test annually.
Do you offer a retest after remediation?Penetration Testing
Yes. A retest of all High and Critical findings is included within 90 days of the final report, with an updated attestation letter for customers, auditors, and insurers.
Managed Security
Fractional security teams, incident response, and who Cyvex is built for.
What size company is Cyvex’s managed security service built for?Managed Security
We are opinionated about SaaS and regulated SMEs between 10 and 500 staff. Under 10 you may be better served by our self-serve tier; over 500 we introduce additional analysts and a dedicated customer success manager.
How is this different from a compliance SaaS tool plus a separate MSSP?Managed Security
Bundling a compliance tool with a separate MSSP is essentially two contracts and two integrations you have to stitch together. Cyvex runs the scanners, the evidence, the vendor register, and incident response from one platform and one accountable team — one contract, one SLA, one escalation path.
What happens during an active security incident?Managed Security
Call the 24/7 line or trigger the in-platform P1 alert. A named incident commander engages within 15 minutes, and we co-ordinate containment, forensic partners (if needed), and regulator communications alongside your team. You get a formal post-incident report within five working days.
Will Cyvex replace our in-house security team, or work alongside it?Managed Security
Both are common. For earlier-stage teams we act as a fractional security function. For teams with a CISO or Head of Security we act as the delivery engine — running the scans, triaging findings, and owning vendor risk so your internal team can focus on architecture and strategy.
Compliance
SOC 2, ISO 27001, timelines, cost, and evidence reuse across frameworks.
Can we really get SOC 2 Type II in 90 days?Compliance
Yes, for Security-only scope with a three-month observation period. It requires engineering buy-in from day one, a single environment in scope, and remediation of Cyvex-identified gaps front-loaded into weeks 1–4. Larger scopes or multiple products typically add 30–60 days.
What is the difference between SOC 2 Type I and Type II?Compliance
Type I is a point-in-time attestation that your controls are designed appropriately. Type II covers a minimum three-month window and attests that those controls also operated effectively. Most enterprise buyers now require Type II; Type I is useful as a 60–90 day interim proof point.
How much does SOC 2 certification cost?Compliance
For a SaaS SME (15–75 staff) a full Type I + Type II programme typically lands between $30,000 and $75,000 in year one, inclusive of Cyvex consulting, platform, and partner CPA audit fees. Annual renewal costs drop to $15,000–$30,000 from year two.
How much does ISO 27001 certification cost, and how long does it take?Compliance
For a typical SME (25–100 staff, single office, SaaS product) the first-year cost is usually $22,000–$45,000, including consulting, the Statement of Applicability, policy set, internal audit, and an accredited Stage 1 + Stage 2 audit. Most clients certify in 4–6 months, or 10–14 weeks if they are already running SOC 2 controls. Annual surveillance audits from year two typically run $5,000–$10,000.
Can we reuse evidence across SOC 2, ISO 27001, and other frameworks?Compliance
Yes. We maintain a live control-to-criteria map so evidence collected once satisfies SOC 2, most of ISO 27001 Annex A, Cyber Essentials Plus, NIST CSF, NHS DSPT, and HIPAA. Teams routinely certify to ISO 27001 within 10–14 weeks of a SOC 2 Type II report.
Platform & Integrations
Ticketing, GRC tools, auditor evidence, and cloud connection permissions.
Is Cyvex a replacement for a GRC tool like Vanta or Drata?Platform & Integrations
For most SMEs, yes. The Cyvex platform covers continuous evidence, control mapping, policy management, and the audit workspace in one place. We also integrate with Drata, Vanta, and Sprinto if you already run one of those.
How do findings reach our ticketing system?Platform & Integrations
We integrate with Jira, Linear, GitHub Issues, and ServiceNow out of the box, with two-way sync so status changes in your tracker flow back to Cyvex. Custom webhooks are supported for anything else.
Will our auditor accept the evidence Cyvex produces?Platform & Integrations
Yes. We work with major audit firms across multiple regions. Evidence is timestamped, hashed, and reproducible from source so auditors can verify integrity at any time.
What permissions does Cyvex need to connect our cloud accounts?Platform & Integrations
For cloud accounts (AWS, Azure, GCP), Cyvex uses read-only IAM roles to evaluate configuration and generate findings — we never request write access. The same least-privilege approach applies to authenticated scans of internal hosts and web applications.
Pricing & Billing
Plan tiers, what drives cost, and how pricing scales with you.
How much does Cyvex cost?Pricing & Billing
Scanning plans start at $50/month (Standard, up to 20 endpoints), $150/month (Plus, up to 100 endpoints), and $300/month (Advanced, up to 250 endpoints), with a 10% discount on annual billing. Enterprise plans (unlimited endpoints, collectors, and connectors) are quoted individually. Managed security services and pen testing are priced separately, on top of or instead of a scanning plan.
Is vulnerability scanning expensive for small businesses?Pricing & Billing
It does not have to be. Continuous scanning platforms like Cyvex are priced for SMEs and remove the need for expensive one-off assessments.
How much do managed security services cost?Pricing & Billing
We price per employee per month, with clear tiers for seat count and optional add-ons (pen testing, compliance consulting). Typical SME engagements land between $1,800 and $10,000 per month, all in.
Can I change plans as we grow?Pricing & Billing
Yes. Standard, Plus, and Advanced plans scale with endpoint count (up to 20, 100, and 250 endpoints respectively), and you can move to a higher tier at any time as your footprint grows. For unlimited endpoints, collectors, and connectors, Enterprise pricing is quoted directly — contact us.
Account & Data Security
Roles, MFA and SSO, API key rotation, and audit log retention.
How do user invitations and roles work?Account & Data Security
Invites go out by email and are valid for 7 days; you can resend an expired invite from the users page. Roles range from Owner (billing, user management, destructive actions — usually 1–2 people) and Admin (configure scans, integrations, policies) to Analyst (view findings, triage, comment) and Read-only (dashboards and exports, useful for execs and auditors).
Does Cyvex support multi-factor authentication (MFA) and SSO?Account & Data Security
Yes. MFA can be rolled out as optional first and then enforced organisation-wide, with users redirected to enrolment rather than locked out. If you use SSO, we recommend enforcing MFA at the identity provider level so one policy applies everywhere instead of drifting per-tool policies.
How are API keys managed and rotated?Account & Data Security
API keys are scoped narrowly to a single system rather than issued as broad "admin" keys. We recommend rotating CI/CD keys every 90 days, production back-end keys every 180 days, and any key with access to sensitive findings every 90 days or immediately after a relevant personnel change. Every key action is logged with the key ID.
How long are audit logs retained?Account & Data Security
Audit logs — authentication events, configuration changes, user management, exports, and API key activity — are retained for 12 months on most plans. If you need longer retention for SOC 2 Type II or another framework, export logs to your SIEM or cold storage.
Related pages
Still have questions?
Book a 30-minute call and we'll walk through your environment, answer questions specific to your stack, and recommend the right plan.
