A cheap “automated pentest” is a scanner in a trenchcoat — and buyers know it. Divilight Continuous Security is the compliance-mapped service that lives between your annual pentests: every finding validated by a human, written in plain English, with the fix and the proof it worked.
Buyer guides say it plainly: a web-app pentest priced under ~$3,000 almost always means automated scanning relabeled as a penetration test. So every “automated & cheap” competitor lands in the one category buyers reflexively reject. We don't compete there.
Generates a ranked list of known issues — mostly “possibly vulnerable to CVE-X.” No proof, no context, no business impact. Buried in false positives your team has no time to triage.
Documents exploited vulnerabilities, their business impact, and how to fix them. That's the gap we close — continuously, and at a price the annual-consultant model structurally can't.
The LLM is our cost structure and our triage engine. Our differentiation is everything wrapped around it — the verification, the report, and the way we go to market.
A loop, not a one-off. When phase 05 ends, phase 01 begins again — coverage that repeats every cycle instead of expiring after a yearly report. Select any phase to see what it does.
Step 01 — Automated · on a schedule
Mature free tooling maps your scoped, signed-off attack surface on a recurring cadence — not once a year.
Step 02 — Automated · the noise killer
The model does the work a raw scanner can't: it separates signal from noise before a human ever looks.
Step 03 — Human-led · the trust step
A named analyst reviews every report before it ships. A confidently-wrong finding never reaches you.
This is the step that lets us honestly not call the product “fully automated” — which is exactly how we escape the scanner-distrust zone.
Step 04 — The deliverable · the product
You get an auditor-friendly report your team, your auditor, or your cyber-insurer can actually use.
Step 05 — Free retest window
Detection is table stakes. We re-test your fixes and prove they worked — the part SMBs value most.
Cutting scanner false positives is the single most valuable thing an LLM layer does here — and a human confirms it before it ships. Flip the switch.
No context, no proof, no priority. Your team either ignores it or burns a week chasing ghosts.
Impact: An unauthenticated attacker can read your customer table. Confirmed with a safe, read-only proof — not a guess.
Fix: Parameterize the query in search_controller.rb:42. We re-test after you deploy.
Impact: Lets an attacker downgrade a visitor to plain HTTP on first visit. Low effort, real exposure.
Fix: Add Strict-Transport-Security at the load balancer. One line; we verify it.
Impact: Tells attackers exactly which exploits to try. Minor on its own — worth 5 minutes.
Fix: Suppress the Server header. Snippet included in the report.
Three things worth fixing this week — each with proof it's real and a plan to close it.
SMBs rarely have security staff to interpret raw output. So the report — plain-English impact, a fix an IT generalist can run, and proof it worked — is worth more than the finding itself.
What it means for you
An attacker who isn't logged in can read your customer database through the search box. We confirmed this with a safe, read-only test — it is not a “maybe.”
How to fix it
search_controller.rb, line 42.The scanning engine is commoditized — it won't differentiate anyone. The durable advantages are in the product and the go-to-market.
Coverage lives between your pentests, on a subscription — the recurring model the annual consultant structurally can't offer.
A named, accountable analyst signs off on every report. AI-speed with a human on the hook — the opposite of the cheap-automation crowd.
We don't just detect. We hand you the fix and re-test to prove it worked — the thing SMBs are desperate for and renew on.
One vertical, one framework, pre-built playbooks. “SOC 2 for seed-stage SaaS” beats “pentest for everyone.”
| Capability | Cheap scan | Annual consultant | Divilight continuous |
|---|---|---|---|
| Continuous coverage | partial | — | ✓ |
| Validated, low-false-positive findings | — | ✓ | ✓ |
| Plain-English, fixable remediation | — | partial | ✓ |
| Free fix re-validation | — | partial | ✓ |
| Compliance-mapped report | partial | ✓ | ✓ |
| SMB-affordable (recurring) | ✓ | — | ✓ |
| Named, accountable human | — | ✓ | ✓ |
The subscription funds the business and gives you continuous coverage. The named pentest carries the credibility. SMBs typically budget $5K–$15K/year for one web app and external network — this splits that into coverage you actually feel.
Deliberately not called a “penetration test.”
Human-led, quarterly or annual. The credibility artifact.
Figures are illustrative market ranges to frame the model, not a quote. Every engagement is scoped and priced after a signed authorization.
SMBs don't buy security tools — their IT is outsourced to a Managed Service Provider. An MSP serving 40 small clients is a single sale that reaches 40 businesses, and they want exactly what we produce: audit-ready reports and fixable findings, under their own brand.
Explore the white-label partnership →Designed white-label from day one
SMBs are genuinely afraid an automated tool will break production. Our safety controls double as sales assets — they're why an MSP or a client picks an accountable provider over the cheap crowd.
01 · Authorization
Nothing is touched without a scope agreement and explicit written permission. Scanning without it is illegal — for us and for you.
02 · Safety
Read-only, safe checks by default. Scope is enforced at the infrastructure level — allowlists, sandboxing, target validation — never left to a prompt.
03 · Accountability
Every report is reviewed and signed off by an accountable analyst. You always know who verified your findings.
04 · Insurance
Professional liability and cyber insurance carried before the first engagement — the trust signal the anonymous cheap-automation crowd can't match.
No — and that's deliberate. Autonomous agents do well on narrow, bounded tasks and degrade sharply on real, full-scope engagements. The valuable, hard part of a pentest — chaining a foothold, a misconfiguration, and a trust relationship into real impact — is exactly where today's models are weakest. So we run a human-in-the-loop model: automation does the grind, a human owns the judgment.
A scanner hands you a ranked list of “possibly vulnerable.” We add the layer that turns that into a decision: the LLM kills false positives by checking whether a detected version is actually in the vulnerable range, rewrites each real issue with business impact and a fix, and a human verifies it before it ships. You get validated findings and proof, not noise.
You shouldn't have to — that's why ground truth comes from tool output, not the model's narration of it, and why a named analyst reviews every report. A confidently-wrong finding never reaches you. The verification step exists precisely because an LLM left unchecked will occasionally claim an exploit “succeeded” when it didn't.
Everything is non-destructive and read-only by default, and scope is enforced at the infrastructure level — allowlists, sandboxing, and target validation — not left to a prompt. We only touch systems named in a signed scope agreement, and we carry professional liability and cyber insurance.
It depends on the engagement's data-sensitivity. A hosted frontier model gives stronger multi-step reasoning; a self-hosted open model (DeepSeek-R1, Llama, Qwen) keeps everything local with zero data egress. For sensitive client data we lean local — often a hybrid: local model for the bulk grind, escalation only for hard reasoning where no sensitive data is in the prompt.
We start with SOC 2 — the easiest SMB entry point — and map every report to it. If your auditor, cyber-insurer, or a customer's vendor questionnaire demands a specific framework, that's the artifact we build toward. The report is the product.
Yes — it's designed white-label from day one. You resell audit-ready, fixable-finding reports under your own brand, as recurring revenue, across your whole client base. Talk to us about the partnership.
Grab 30 minutes directly on the calendar, or use the form if you'd rather write out the details first. A real person replies within one business day — no autoresponder, no sales bot.
Book a 30-min scoping call →A real person — not a bot — will reply within one business day. Nothing is scanned until you sign a scope agreement.