EN

Cybersecurity Suite

veyrisk

Exposure management: see what is reachable from outside

See what attackers see. Fix what matters.

veyrisk continuously collects what your organisation exposes on the network — servers, web applications, cloud accounts, identities — and ranks every finding by real risk rather than by CVSS score. Operations and data sit on our own server in Germany.

The veyrisk console: exposure score, open findings, actively exploited vulnerabilities and affected assets side by side.
veyrisk in operation.

Why veyrisk

01

PRIORITY, NOT A LIST

Every finding gets a rank from severity, known active exploitation and the importance of the affected system. What is being exploited today comes first — not what carries the highest CVSS number.

02

ACTIVE ONLY WITH PROOF

Passive checks always run. Port scans, OpenVAS and active web application scanning only once the domain is demonstrably yours — via a TXT record in DNS. Active scanning is never possible through the enquiry form.

03

A GAP BEATS A FALSE ALARM

If a query fails, no finding is created. A tool that reports when in doubt teaches its team to skim past alerts — and then attention is missing for the real one.

04

OUR OWN SERVER, NO HYPERSCALER

veyrisk runs on a self-managed machine in Germany. Scan data, findings and reports never leave it. The operator is neonotu GmbH — the same contact who picks up the phone when it matters.

HOW IT WORKS

Five areas, one ranking

The five areas do not run side by side. They feed into one shared list, in which an open cloud bucket and an unpatched library on a server are ranked by the same measure.

01

Vulnerability management

Continuously check servers, clients and network devices — agentless for everything reachable, with a light agent for devices outside the network. After patching, a follow-up scan proves the gap is genuinely closed.

02

External attack surface

What does the organisation expose on the internet — including what nobody is tracking any more? Subdomains from certificate logs, DNS, TLS, redirects, openly reachable admin interfaces, SPF and DMARC.

03

Web application scanning

Check web applications and APIs for injection, cross-site scripting and broken access control. The scope stays limited to your own host; active scanning only with explicit consent.

04

Cloud and identity security

Misconfigurations, over-broad permissions and open storage in AWS, Azure and Google Cloud. Plus Entra ID and Microsoft 365: over-privileged accounts, missing multi-factor sign-in, legacy authentication still left open.

AT A GLANCE

What gets checked

Passive means: without intervention, at any time, even without proof of ownership. Active means: connecting to the target — and therefore only after ownership of the domain has been proven.

CheckMode
Subdomains from certificate logs Passive, always
DNS, TLS, HTTPS redirect, security headers Passive, always
SPF and DMARC for mail Passive, always
Openly reachable admin interfaces Passive, always
Port scan and vulnerability scan (OpenVAS) Active, proof of ownership required
Web application scanning of your own apps Active, consent required

In comparison

Market positioning

veyrisk does not compete with the feature list of the large American platforms. It competes with their operating model: data in someone else’s hands, per-asset billing, a mountain of findings without a ranking.

Aspect Large US platforms Open-source tools veyrisk
Data residency Mostly US Self-hosted, self-run Own server in Germany
Ranking of findings Present, often opaque CVSS list Severity, exploitation, asset weight
Active scans without ownership check Partly possible Possible Blocked
Operating effort Low High Low, we run it
Contact when it matters Ticketing system Forum The same team that advises you

In practice

Three examples

How organisations use veyrisk — from the first look from outside to continuous operation.

01

The first look from outside

A service company with 60 staff has its own domain checked passively. Eleven subdomains turn up, two of which nobody in the house knew about any more — among them an old admin interface without access control. Both had been publicly visible through certificate logs long before veyrisk looked.

02

After proving ownership

The same organisation adds the TXT record to its DNS. That unlocks port scanning and OpenVAS. Of 34 findings, four carry the mark “actively exploited” — they go to the top and the rest waits. Remediation is not ticked off but confirmed by the follow-up scan.

03

In continuous operation

A company with distributed sites scans weekly. New systems appear by themselves as soon as they get a certificate. The exposure score gives the managing director one number he can explain in the monthly report — and the findings list gives the team its work queue.

NEXT STEP

Look first, decide after

The passive run needs nothing but your domain — no credentials, no installation, no intervention in your systems. What becomes visible is public anyway; the only question is whether you see it before an attacker does.

Everything beyond that — port scans, OpenVAS, web application scanning — you unlock yourself by proving ownership of the domain. Without that proof it stays at the view from outside, permanently.

More products in the suite

Sightadel

NIS2, DORA, ISO 27001 and GDPR as preconfigured control catalogues, plus a security score from 0 to 100 across six domains. Dat…

View

Strider

Signals from firewall, endpoint, identity and cloud condensed into incidents instead of alert floods. NeoI (neonotu Intelligence) correlation instead …

View

Talion

Detects, isolates and redirects to honeypots — in seconds, within a policy your organisation defines. Every action reversible a…

View

Valar

Four graded models on cyanbox hardware secure the perimeter and internal zones — from a single practice to a corporate network,…

View

Contact

Reputation takes years. Destruction takes seconds.

Talk to us before somebody else does. The first conversation is free and we reply the same business day.