Introducing SecureIQ Lite: Free Security Assessment & 72 Hour Pentesting

/

Somewhere right now, a twenty-person company is reading an email from its largest customer. Halfway down the vendor security questionnaire is a line asking for the results of their most recent penetration test. They’ve never had one, and the renewal is in three weeks.

So they start calling security firms. The first one answers in two days and wants a scoping call. The scoping call gets booked for the following week. Then comes a proposal, a redline, a kickoff, and a wait for a testing window. The report arrives sometime after the deadline that started the whole thing.

Nobody in that chain did anything wrong. That’s what buying enterprise security looks like, and for enterprises it works. For everyone else, it’s a closed door.

Today we’re opening it. SecureIQ Lite is live: a free security assessment that runs in under an hour, and a 72 hour penetration test you can book yourself.

Why we built SecureIQ Lite

TL;DR: Security testing has been sold almost exclusively to companies that already have security teams, which leaves smaller organizations facing questionnaires, audits, and insurance renewals with no practical way to get started.

SecureIQ, our enterprise Threat Exposure Management platform, deserves a more in-depth sales cycle. Enterprises have thousands of assets across business units nobody has fully inventoried, cloud accounts in three providers, auditors who show up every quarter, and a rollout plan that has to survive contact with procurement. That work deserves a scoping call, an architecture conversation, and a proper onboarding.

Now run that same cycle against an SMB with one domain, forty employees, and an audit deadline. Every part of it turns into friction, because they’re not evaluating a security program. They need to know where they stand, and a penetration test report they can send to their customer – all before the end of the month.

The companies with the most exposure are usually the ones with the least tooling. So we took the same engines, testers, and report standard, and we opened that front door for SMBs that are often left to fend for themselves. 

How SecureIQ Lite works

TL;DR: SecureIQ Lite pairs a free security assessment of your external attack surface and primary web application with self-service human penetration testing, delivered as a written report within 72 hours.

SecureIQ Lite comes in two parts.

Start with the free security assessment

Sign up with your business email using Google SSO, Microsoft SSO, or an email and password. Click the link we send you and your first scan starts on its own.

The free external network vulnerability scan maps everything an attacker can reach from the outside: subdomains, DNS records, open ports and running services, web technologies, and TLS posture. On top of that, a free web application vulnerability scan runs automated dynamic testing against your primary site. You watch it work while it runs, and results typically land within the hour.

The scan on your signup domain is free, it stays free, and you can re-run it on-demand.

Then book a 72 hour penetration test

Automated scanning finds exposure. It can’t tell you which of those findings a human could chain into an actual breach, and it isn’t what your auditor asked for. For that you need people.

Book a 72 hour external network penetration test from your dashboard and our team delivers the written report within 72 hours of the engagement starting. With SecureIQ Lite, you avoid long timelines, scoping calls, and back-and-forth proposals. All it takes is three days, in the same report format we hand to enterprise clients. A 72 hour web application penetration test is available the same way, covering up to five endpoints with their own credentials so our testers reach the authenticated areas that matter.

Key highlights

TL;DR: A shareable letter grade, findings ranked by what to fix first, priorities that track live exploit activity, compliance context on every result, and human penetration testing booked without a sales call.

  • A grade you can share: A+ through F, a 0 to 100 score, and a plain-language rating, scored on real exposure: finding severity, weighted by TLS posture and risky internet-facing ports.
  • Findings ranked by what to fix first: Every finding carries a priority of Immediate, Urgent, Significant, or Routine, and a Remediation Priorities panel surfaces the five fixes that generate the biggest ROI.
  • Priorities that track live exploit activity: CVE enrichment escalates anything being actively exploited in the wild. It only ever escalates, so nothing downgrades a serious finding.
  • Compliance and OWASP context on every finding: Results map live against NIST 800-53, ISO 27001, PCI DSS, HIPAA, OWASP Top 10, OWASP ASVS, MITRE ATT&CK, MITRE CAPEC, and DISA STIG, with CWE and full evidence on web findings.
  • Self-service penetration testing, booked in four steps: Choose the test type, define your scope, pick a start date, and review. Scope validation and DNS-based domain verification run before anything gets tested.
  • A written report in 72 hours: Findings appear in your dashboard as our testers validate them, and the report lands in the same format we hand to enterprise clients.
  • Room to grow, without a sales cycle: Attack surface management, web application DAST, leaked credential intelligence, cloud posture, internal network and Active Directory, and code analysis all unlock via self-serve add-ons.

Who SecureIQ Lite is for

TL;DR: It’s built for SMBs that need credible security testing and evidence without an enterprise security team, a procurement process, or a budget cycle behind them.

SecureIQ Lite is for the SMB that just received its first vendor security questionnaire. For the early-stage startup whose cyber insurance renewal is asking for evidence of testing. For the team walking into its first audit with no idea where they stand. For the IT lead who owns security alongside four other jobs and needs to know what’s exposed before an attacker does.

If you’ve been searching for penetration testing for small business and finding nothing but contact forms, this is the shortest path we know how to build.

Plenty of companies come to us for one report and leave with one report. That’s an outcome we’re ok with, and you can always re-run the scan as your security posture changes.

If you want more capabilities, the rest of the platform is sitting behind a checkout button rather than a sales team. Full attack surface management across every asset you own. Web application DAST across your whole portfolio. Threat intelligence for leaked employee credentials. Cloud posture across AWS, Azure, and GCP. Internal network and Active Directory static analysis on every change to your repositories. 

Add any of these modules and it unlocks instantly. Add a second and it’s prorated onto the same bill. Cancel one yourself, prorated, without opening a ticket. Own two or more and Insights unlocks at no extra cost: your findings mapped across 18 compliance frameworks, quantified risk analysis with FAIR loss modelling and SSVC prioritization, and one de-duplicated findings feed across everything you run.

The compliance mapping matters more than it sounds. When your customer asks whether an issue touches your SOC 2 story, or your auditor wants to know how a finding lines up against PCI DSS or ISO 27001, the answer is already on a report rather than in somebody’s head.

How to get started

TL;DR: Sign up at safehill.com with your work email, confirm your address, and your free security assessment starts automatically with results usually back inside the hour.

1. Sign up. Business email only, using Google SSO, Microsoft SSO, or email and password. Your account, workspace, and file delivery folder are provisioned for you.

2. Confirm your email. Clicking the link kicks off your first scan. A guided product tour opens on first login and replays any time you want it.

3. Get your grade. Watch live progress while the scan runs and the dashboard updates itself. Results typically land within the hour.

From there, work the Remediation Priorities panel, and book a penetration test from your dashboard when you need a report with a human behind it.

See your grade. Book your penetration test.

Security testing has been sold to companies with security teams for so long that everybody else got left with a marketing site and a Contact Sales button. Meanwhile, the questionnaires keep coming, the insurance renewals keep asking, and the audits keep landing on companies that have never had a pentest and don’t know where to start.

SecureIQ Lite is the SafeHill platform with the front door open. Start with the free security assessment, find out where you stand this afternoon, and book a 72 hour penetration test when the deadline is real.

Get your free security assessment today. Results within the hour. Penetration test report in 72 hours.

SecureIQ Lite FAQ
What is SecureIQ Lite?

SecureIQ Lite is the self-service version of SafeHill’s SecureIQ Threat Exposure Management platform. It gives any organization a free security assessment of its external attack surface in under an hour, plus 72 hour penetration testing booked directly from the dashboard.

Yes. The free security assessment on your signup domain is free, it stays free, and no credit card is required to run it. You can re-run it on demand.

The free external network vulnerability scan discovers subdomains, DNS records, open ports and running services, web technologies, and TLS/SSL posture. Results come back as a letter grade from A+ to F, a 0 to 100 score, a severity breakdown, and a prioritized findings table.

Yes. A free web application vulnerability scan runs automated dynamic testing (DAST) against your primary site as part of the same assessment. Web findings carry their OWASP Top 10 category and CWE, with full evidence and remediation guidance.

Yes. The written report is delivered within 72 hours of the engagement starting. Findings also appear in your dashboard as testers validate them, so you’re not waiting in silence for the report to arrive.

A 72 hour external network penetration test is human testing against the internet-facing IPs you put in scope, followed by a written report delivered within 72 hours of the engagement starting, in the same format SafeHill hands to enterprise clients.

Yes. A 72 hour web application penetration test covers up to five endpoints, each with its own credentials, so testers reach the authenticated areas of your application rather than only the public marketing pages.

No. Signup, scanning, module activation, and penetration test booking are all self-service. SafeHill’s team is available if you need additional support, but nothing in SecureIQ Lite requires a sales call.

They both run on the same engines, testers, and report standard. SecureIQ is built for enterprise environments that need continuous coverage, custom integrations, and a guided rollout. SecureIQ Lite removes the sales cycle so smaller teams can start immediately and add coverage as they need it.

Yes. Penetration test reports are delivered in the same format SafeHill hands to enterprise clients, so they’re ready to be reviewed by your customer, auditor, insurer, or board.

Domain ownership is verified server-side through a DNS record before any paid web target is tested. Scope validation also catches private IPs, public DNS resolvers, duplicates, and malformed entries before an engagement is booked.