Offensive + defensive security · AI governance · self-hosted

One platform for offensive and defensive security.

Checkii runs authorised penetration testing and a defensive SOC with AI governance from a single self-hosted base — where every action is bound by policy code to an approved scope, and the evidence to prove it is generated as you go.

Defensive

Monitor, govern, respond

Vulnerability management, ML intrusion detection, SIEM and remediation — with an AI & security governance layer for the EU AI Act and ISO 42001.

  • VM · IDS · SIEM · remediation
  • System & risk register + assessments
  • Audit chains & encrypted evidence
Offensive

Test, within authorisation

Authorised penetration testing bound by a deterministic control plane — every job authorised, every target verified, all traffic egress-enforced.

  • Control-plane-bound engagements
  • Executor-verified asset ownership
  • Egress-enforced, signed-manifest execution
Governance
EU AI Act · ISO 42001
register · assessments · evidence
Live today
Executing now
forced-RLS · SSO · signed audit
Behind the gate
Built · lab-proven
awaiting exit-gate sign-off
Principles

Honest by default

Both products are built on the same discipline: we publish what runs, what's gated, and what we deliberately don't do. Not claiming these is the product.

Not offered

Self-healing remediation. Agents draft; a human approves; a human or a separate system does the work. The agents cannot execute, by design.

Not a headline number

One big detection accuracy figure. Off its training distribution the IDS degrades — we show it, and hand you the retrain loop instead.

Gated, not live

Production pentesting against your targets. The engine is built and lab-proven; enabling real targets waits for the exit gate and human approval.

Operational, not code

A 24/7 SOC or endpoint agent. This is a transparent, self-hostable base you fully control — not a managed service.

Products

Two products, one platform

Choose the side you're here for. They share identity, tenancy, evidence and governance — their executable workers and network planes stay isolated.

Authorised penetration testing bound by a deterministic control plane. A job is either inside the authorised boundary — and runs — or beyond it, and it doesn't.

Inside the boundary — live today

Active assessment engine

Playwright, Nuclei, OWASP ZAP, OpenAPI and authenticated Postman — through an enforcing, DNS-pinned egress proxy with per-hop redirect re-authorization and rate budgets.

Qualified against the synthetic lab

Continuous, authority-bound automation

Recurring passive, repository, controlled-active and retest schedules dispatch jobs and re-verify scope at runtime, suspending on any policy change.

Runs today

Executor-observed asset ownership

Every target proven before use — DNS TXT, fixed-path HTTP, GitHub App, GitLab/Bitbucket, AWS / GCP / Azure — digest-only and independently approved.

Runs today

Findings & client-ready reports

Canonical cross-job dedup, human review with expiring risk acceptance, retest lineage, and multi-format reports with full provenance.

Runs today
Exit gate
Phase 0 governance baseline · human review + containment approvals required to cross
STATUS: NOT YET SIGNED
Behind the gate — built, awaiting sign-off

Production customer-target execution

The engine that runs against the synthetic lab today is the same one that will run against your estate. Enabling real customer targets ships only after the exit gate clears.

Built · engine lab-proven · gated

Live cloud & provider qualification

Cloud/repository executors and model providers are implemented; live acceptance is environment-specific, completed per deployment.

Built · deployment-qualified
How a job gets authorised

Engagement & rules of engagement

Approved target classes and methods, exclusions, emergency contacts, absolute testing windows, and triggerable stop conditions.

Human-defined

Written authorisation, independently approved

Approved by a different principal, fingerprinted over the exact operating controls it permits.

Separation of duties

Asset ownership verified

Each target proven — DNS, HTTP, GitHub/GitLab/Bitbucket, or cloud — observed by an executor, digest-only, independently approved.

Executor-observed

Immutable scope version

Scope is frozen; any drift in authority or assets invalidates dependent jobs, schedules and reports.

Drift-invalidated

Signed manifest → egress-enforced execution

A signed, expiring manifest and short-lived credentials; the worker runs only through the enforcing proxy. Results return dual-authenticated.

Enforced at the wire
For offensive teams & MSPs

Test aggressively, prove you stayed in scope

You run authorised testing — often across many clients — and every engagement has to be defensible after the fact. Checkii makes the authority boundary the thing that runs the job.

Scope an engagement that can't drift

Written authorisation, immutable scope, verified targets. Any drift invalidates dependent jobs automatically.

Prove you touched only what was allowed

Signed manifests, egress-enforced execution, dual-authenticated results. A complete per-job audit trail, at the wire.

Run continuous assessment on a leash

Schedules revalidate authority at dispatch; tenant and global kill switches. Automation that can't outrun its authorisation.

Deliver client-ready findings

Canonical dedup, retest lineage, provenance. Reports in Markdown/JSON/CSV/SARIF/PDF/DOCX.

A defensive SOC and an AI & security governance layer in one pane. Monitor your estate, prove your controls, and respond — with the evidence generated as you work.

Security operations

Vulnerability & asset management

CVE correlation and contextual risk scoring across your assets — the inventory the rest of the platform reasons over.

Checkii VM · :8000

ML intrusion detection

Network intrusion detection enriched by asset context, with PSI drift monitoring that raises a SIEM alert on high drift.

Checkii IDS · :8100

SIEM & remediation

Ingest logs, parse auth/firewall events, raise correlation alerts; track remediation open → approved → done with full audit.

Checkii Platform · :8200

Analyst-augmentation agents

Triage, ticketing, hunt and reporting agents that read, correlate and draft — and structurally cannot approve, block or execute.

Checkii Agents · :8300
Governance & compliance
System & risk register

Know what AI you run, and its risk

A tenant-scoped register of AI systems and risks mapped to a control framework catalogue — the inventory an EU AI Act or ISO 42001 programme is built on.

Control assessments

Evidence from live activity

Assessments auto-collect evidence from what the platform actually did — not a spreadsheet updated by hand.

Obligation artefacts

EU AI Act timelines & Art. 11 docs

Generates EU AI Act obligation timelines and Article 11 technical-documentation skeletons from your own register.

Tamper-evident record

Audit chains & encrypted evidence

Per-tenant HMAC audit chains with external, versioned keys; per-object AES-256-GCM envelope-encrypted evidence with hold-aware retention.

EU AI ActISO/IEC 42001Article 11 documentation Forced-RLS tenant isolationBYOK / external KMSLegal holds & retention
Detection, measured honestly
EvaluationDetection @ 1% FPR
In-distribution real (CICIDS2017, held-out)0.988
In-distribution real (each IDS2018 day on itself)1.000
Cross-year, same family — DoS0.999
Cross-year, same family — brute-force0.51
Cross-year — botnet0.002
Synthetic-trained → real traffic0.0 – 0.12

Essentially perfect on the distribution it was trained on; cross-year transfer works only for families that look alike; synthetic → real collapses. That is the honest reason to retrain on your own sensor traffic — the ingest loop ships in the box.

For compliance & risk teams

Walk into the audit with evidence, not assertions

You have to demonstrate control over your AI systems and security posture — and the proof usually lives in stale spreadsheets. Checkii generates it as you work.

Prepare for an EU AI Act review

Keep the register current; generate obligation timelines and Art. 11 skeletons. Arrive with the paperwork pre-structured.

Prove a control actually operates

Assessments auto-collect evidence from live activity. Backed by real events, not a checkbox ticked last quarter.

Show data never left the boundary

Forced-RLS isolation, envelope-encrypted evidence, tamper-evident audit chains. A defensible chain of custody.

Enforce retention & deletion law

Region-bound retention, legal holds, approved deletion. Purged content returns HTTP 410; custody metadata retained.

Self-service

Test your own development

Point Checkii at your own web apps and APIs. Because you own the target, testing is authorised out of the box — no engagement paperwork. Scan, triage, fix, retest, and wire it into CI. Sign up and start in minutes.

Solo
$55/mo
or $559/yr · 1 target

For a single app or API — a solo developer or one project.

  • 1 web app or API target
  • Web (DAST) + API scanning
  • Authenticated scans
  • Scheduled scans
  • SARIF / PDF export
Start testing
Most popular
Pro
$159/mo
or $1,599/yr · 1 target

For a project shipping continuously — unlimited scans and a CI gate.

  • 1 target, unlimited scans
  • Web + API (REST / GraphQL)
  • Authenticated & scheduled
  • CI/CD gate + retest lineage
  • All integrations
Start testing
Studio
$399/mo
or $3,999/yr · 5-target pool

For a team or agency testing several apps at once.

  • 5-target pool
  • Everything in Pro
  • Unlimited scans across targets
  • Team roles & shared findings
  • Priority support
Start testing

Billed per target — a target is one web app or API. Testing systems you don't own needs the authorised-testing control plane: written authorisation, asset verification, and the exit gate.

What you can test

Web apps (DAST)

Crawl and actively test your running app for injection, broken auth, and access-control flaws — the same engine the control plane uses, pointed at a target you own.

APIs

REST and GraphQL, driven from an OpenAPI spec or Postman collection, with authenticated sessions.

In your pipeline

Gate a build on new findings, export SARIF to your code host, and track retests as you fix — closing the loop before you ship.

Architecture

Two planes, one control plane

Defensive and offensive share identity, tenancy, evidence and governance through one control plane, while their executable workers and network paths stay isolated.

Control plane — authority binds everything
Permission RBACImmutable scopeSigned manifestsIdempotencyHMAC audit chainForced-RLS tenancy
Defensive plane
Checkii VMvulnerability & asset management
Checkii IDSML intrusion detection + drift
Platformremediation · threat-intel · SIEM
Governanceregister · assessments · evidence
Offensive plane
Workerspassive · repository · controlled-active
Asset verifierexecutor-observed ownership
Model relaycontained, allowlisted egress
↓  ENFORCING EGRESS BOUNDARY  ↓
Shared foundation
OIDC / SCIM identityEnvelope-encrypted evidenceVersioned recovery points
control plane · defensive offensive gated egress

Governance in the same pane

Register, risk register and control assessments for the EU AI Act and ISO 42001 — evidence collected from live activity, self-hosted.

A deterministic authority boundary

Every job bound to an approved tenant, scope, verified asset, tool and network path by policy code. You can prove what the tool was allowed to do.

AI that provably can't act

The agents read, correlate and draft — and structurally cannot approve, block or execute. The guarantee lives in the client code.

Pricing

Plans for every team

Self-hosted, single-tenant, or white-label across many clients — tailored to your tenants, frameworks and scale. Talk to us and we'll shape the right plan.

Self-host
Custom
self-managed · single tenant

For a team that wants the whole stack — offensive and defensive — in its own estate.

  • All services, single tenant
  • Defensive SOC + governance
  • Authorised-testing control plane (lab)
  • Community support
Get a quote
Most popular
Team
Custom
tailored by tenants & frameworks

For regulated orgs that need multi-tenant isolation, SSO and audit evidence.

  • Forced-RLS multi-tenancy
  • OIDC / SCIM SSO
  • Envelope encryption + BYOK
  • EU AI Act / ISO 42001 artefacts
  • Priority support
Get a quote
MSP / white-label
Let's talk
volume · per client tenant

For consultancies running authorised testing across many clients.

  • White-label console
  • Per-client tenant isolation
  • Private worker pools
  • Multi-format client reports
  • Dedicated support
Get a quote