How it works Why us Pricing For MSPs FAQ Book a scoping call →
CONTINUOUS COVERAGE FOR SMBs & THEIR MSPs

AI-speed.
Human-verified.

A cheap “automated pentest” is a scanner in a trenchcoat — and buyers know it. Divilight Continuous Security is the compliance-mapped service that lives between your annual pentests: every finding validated by a human, written in plain English, with the fix and the proof it worked.

Book a scoping call → See how it works
Human-reviewed reports Non-destructive by default Insured & accountable
Scan Triage Human verify Report Re-validate a loop, not a one-off
01 The trap everyone else falls into

The SMB market was trained to distrust cheap “AI pentests.”

Buyer guides say it plainly: a web-app pentest priced under ~$3,000 almost always means automated scanning relabeled as a penetration test. So every “automated & cheap” competitor lands in the one category buyers reflexively reject. We don't compete there.

A vulnerability scan

Generates a ranked list of known issues — mostly “possibly vulnerable to CVE-X.” No proof, no context, no business impact. Buried in false positives your team has no time to triage.

— Noisy, unvalidated output — “Possibly vulnerable,” no verification — No remediation you can execute
A real penetration test

Documents exploited vulnerabilities, their business impact, and how to fix them. That's the gap we close — continuously, and at a price the annual-consultant model structurally can't.

✓ Validated, de-duplicated findings ✓ Plain-English impact + step-by-step fix ✓ Re-tested proof the fix worked

The LLM is our cost structure and our triage engine. Our differentiation is everything wrapped around it — the verification, the report, and the way we go to market.

02 How it works

Scan → triage → verify → report → re-validate.

A loop, not a one-off. When phase 05 ends, phase 01 begins again — coverage that repeats every cycle instead of expiring after a yearly report. Select any phase to see what it does.

Continuous phase 05 hands back to phase 01 — every cycle
01 Scan02 Triage03 Verify04 Report05 Re-validate
05 hands back to 01 — every cycle

Step 01 — Automated · on a schedule

Discover & scan

Mature free tooling maps your scoped, signed-off attack surface on a recurring cadence — not once a year.

— nmap for host & service discovery— nuclei for templated vuln checks— ffuf for content & endpoint discovery— TLS / exposed-service / OWASP checks

Step 02 — Automated · the noise killer

LLM triage

The model does the work a raw scanner can't: it separates signal from noise before a human ever looks.

— De-duplicates & clusters findings— Cross-checks versions vs. real CVE applicability— Rewrites issues in plain English + impact— Drafts step-by-step remediation

Step 03 — Human-led · the trust step

Human verification

A named analyst reviews every report before it ships. A confidently-wrong finding never reaches you.

✓ Ground truth = tool output, not narration✓ False positives killed; real risks confirmed✓ Accountable, insured, signed off by a person✓ Every correction trains what we automate next

This is the step that lets us honestly not call the product “fully automated” — which is exactly how we escape the scanner-distrust zone.

Step 04 — The deliverable · the product

Compliance-mapped report

You get an auditor-friendly report your team, your auditor, or your cyber-insurer can actually use.

— Mapped to your framework (SOC 2 to start)— Prioritized by real business impact— Fixable by a non-security generalist— Evidence & context an auditor accepts

Step 05 — Free retest window

Fix & re-validate

Detection is table stakes. We re-test your fixes and prove they worked — the part SMBs value most.

— Free re-validation of remediated findings— Proof-of-fix your auditor / customer sees— Continuous coverage between named pentests— Renewals driven by demonstrated risk reduction
03 What “verified” actually means

Same scan. One is noise. One is a decision.

Cutting scanner false positives is the single most valuable thing an LLM layer does here — and a human confirms it before it ships. Flip the switch.

scan-output.txt divilight-report — findings.md
47 findings — “possibly vulnerable.” Now what?
[CRIT]Possibly vulnerable to CVE-2023-44487 (HTTP/2)
[HIGH]Outdated OpenSSL 1.1.1 detected — CVE-2022-3602
[HIGH]SQL injection suspected on /search?q=
[MED]Missing HSTS header on www host
[MED]Directory listing enabled (possible)
[MED]TLS 1.0 supported (legacy)
[LOW]Server banner discloses version
[INFO]robots.txt references /admin
… and 39 more

No context, no proof, no priority. Your team either ignores it or burns a week chasing ghosts.

✓ 3 real, prioritized ✕ 41 false positives killed ✕ 3 duplicates merged
HIGH

SQL injection on /search

Impact: An unauthenticated attacker can read your customer table. Confirmed with a safe, read-only proof — not a guess.

Fix: Parameterize the query in search_controller.rb:42. We re-test after you deploy.

MED

Missing HSTS on primary domain

Impact: Lets an attacker downgrade a visitor to plain HTTP on first visit. Low effort, real exposure.

Fix: Add Strict-Transport-Security at the load balancer. One line; we verify it.

LOW

Version banner disclosure

Impact: Tells attackers exactly which exploits to try. Minor on its own — worth 5 minutes.

Fix: Suppress the Server header. Snippet included in the report.

Three things worth fixing this week — each with proof it's real and a plan to close it.

04 The deliverable is the product

Your competitors dump findings. We hand you a decision.

SMBs rarely have security staff to interpret raw output. So the report — plain-English impact, a fix an IT generalist can run, and proof it worked — is worth more than the finding itself.

Written for someone with no security background
Mapped to the compliance framework your auditor asks for
Prioritized by real business impact, not raw CVSS
Remediation guaranteed — we re-test and prove the fix
FINDING DV-014 · SAMPLE EXCERPT HIGH

SQL injection in the product search endpoint

What it means for you

An attacker who isn't logged in can read your customer database through the search box. We confirmed this with a safe, read-only test — it is not a “maybe.”

How to fix it

  1. Open search_controller.rb, line 42.
  2. Replace the string-built query with a parameterized query.
  3. Deploy and tell us — we re-test within one business day.
Proof of fix: once re-tested, this finding closes with evidence your auditor accepts.
FrameworkSOC 2 — CC6.1, CC6.6
Reviewed byA named analyst (not a bot)
StatusRe-test scheduled after fix
05 Why we're different

The edge isn't a better model. It's everything around it.

The scanning engine is commoditized — it won't differentiate anyone. The durable advantages are in the product and the go-to-market.

01

Continuous, not annual

Coverage lives between your pentests, on a subscription — the recurring model the annual consultant structurally can't offer.

02

Human-verified, not scanner

A named, accountable analyst signs off on every report. AI-speed with a human on the hook — the opposite of the cheap-automation crowd.

03

Remediation guaranteed

We don't just detect. We hand you the fix and re-test to prove it worked — the thing SMBs are desperate for and renew on.

04

Built for your stack

One vertical, one framework, pre-built playbooks. “SOC 2 for seed-stage SaaS” beats “pentest for everyone.”

Capability Cheap scan Annual consultant Divilight continuous
Continuous coveragepartial
Validated, low-false-positive findings
Plain-English, fixable remediationpartial
Free fix re-validationpartial
Compliance-mapped reportpartial
SMB-affordable (recurring)
Named, accountable human
06 Pricing

Two tiers, on purpose.

The subscription funds the business and gives you continuous coverage. The named pentest carries the credibility. SMBs typically budget $5K–$15K/year for one web app and external network — this splits that into coverage you actually feel.

Start here

Continuous Monitoring

Deliberately not called a “penetration test.”

$300–$1,000/ month
Scheduled discovery + scanning of your scoped surface
LLM triage — false positives killed, findings in plain English
Human-verified, compliance-mapped report each cycle
Free re-validation of your fixes
The recurring layer between your named pentests
Start with monitoring →

Named Penetration Test

Human-led, quarterly or annual. The credibility artifact.

$5,000–$10,000/ engagement
Deeper, human-driven testing and manual exploitation
The formal report auditors and insurers expect
Business-logic and chained-attack review
Included fix-retest window
Reserve the term “pentest” for what earns it
Scope a pentest →

Figures are illustrative market ranges to frame the model, not a quote. Every engagement is scoped and priced after a signed authorization.

07 The edge almost nobody executes

Sell through MSPs, not one SMB at a time.

SMBs don't buy security tools — their IT is outsourced to a Managed Service Provider. An MSP serving 40 small clients is a single sale that reaches 40 businesses, and they want exactly what we produce: audit-ready reports and fixable findings, under their own brand.

Explore the white-label partnership →

Designed white-label from day one

White-labeled under your brand from day one
One sale distributes to your entire client base
Audit-ready reports your techs can action
Recurring revenue you resell, with margin
08 Trust & safety

The guardrails are the product too.

SMBs are genuinely afraid an automated tool will break production. Our safety controls double as sales assets — they're why an MSP or a client picks an accountable provider over the cheap crowd.

01 · Authorization

Signed authorization first

Nothing is touched without a scope agreement and explicit written permission. Scanning without it is illegal — for us and for you.

02 · Safety

Non-destructive by default

Read-only, safe checks by default. Scope is enforced at the infrastructure level — allowlists, sandboxing, target validation — never left to a prompt.

03 · Accountability

A named human on the hook

Every report is reviewed and signed off by an accountable analyst. You always know who verified your findings.

04 · Insurance

Insured & accountable

Professional liability and cyber insurance carried before the first engagement — the trust signal the anonymous cheap-automation crowd can't match.

09 Straight answers

The honest version.

No — and that's deliberate. Autonomous agents do well on narrow, bounded tasks and degrade sharply on real, full-scope engagements. The valuable, hard part of a pentest — chaining a foothold, a misconfiguration, and a trust relationship into real impact — is exactly where today's models are weakest. So we run a human-in-the-loop model: automation does the grind, a human owns the judgment.

A scanner hands you a ranked list of “possibly vulnerable.” We add the layer that turns that into a decision: the LLM kills false positives by checking whether a detected version is actually in the vulnerable range, rewrites each real issue with business impact and a fix, and a human verifies it before it ships. You get validated findings and proof, not noise.

You shouldn't have to — that's why ground truth comes from tool output, not the model's narration of it, and why a named analyst reviews every report. A confidently-wrong finding never reaches you. The verification step exists precisely because an LLM left unchecked will occasionally claim an exploit “succeeded” when it didn't.

Everything is non-destructive and read-only by default, and scope is enforced at the infrastructure level — allowlists, sandboxing, and target validation — not left to a prompt. We only touch systems named in a signed scope agreement, and we carry professional liability and cyber insurance.

It depends on the engagement's data-sensitivity. A hosted frontier model gives stronger multi-step reasoning; a self-hosted open model (DeepSeek-R1, Llama, Qwen) keeps everything local with zero data egress. For sensitive client data we lean local — often a hybrid: local model for the bulk grind, escalation only for hard reasoning where no sensitive data is in the prompt.

We start with SOC 2 — the easiest SMB entry point — and map every report to it. If your auditor, cyber-insurer, or a customer's vendor questionnaire demands a specific framework, that's the artifact we build toward. The report is the product.

Yes — it's designed white-label from day one. You resell audit-ready, fixable-finding reports under your own brand, as recurring revenue, across your whole client base. Talk to us about the partnership.

10 Book a scoping call

Let's see if we're a fit.

Grab 30 minutes directly on the calendar, or use the form if you'd rather write out the details first. A real person replies within one business day — no autoresponder, no sales bot.

Book a 30-min scoping call →
Nothing is scanned until you sign a scope agreement. Everything runs non-destructive by default, and every report is human-verified.

Something went wrong sending your request. Please email [email protected] instead.

We'll only use your details to reply. No spam, ever.

Request received.

A real person — not a bot — will reply within one business day. Nothing is scanned until you sign a scope agreement.