Continuous Exposure Management (CTEM) Platform

Attackers already know
where you are vulnerable
Do you?

cidguard continuously scans your digital assets, computes an auditable risk score and shows exactly where to act — before someone exploits it.

Start analysis

First results in minutes. See plans →

Cidguard
PRO
EA
Dashboard
67
-4%
Total Org Risk
(0–100)
2
2 ativos afetados
CISA KEV ·
exploradas ativamente
You
Incident Risk
CTEM Pipeline
Continuous Threat Exposure Management · estado atual em 5 fases
01
Scoping
Superfície de ataque
ATIVOS
3/25
COBERTURA
12%
02
Discovery
Achados e ameaças
ABERTOS
26
CRIT/HIGH
3/7
03
Prioritization
Score e classificação
RISK SCORE
67
URGÊNCIA
3C · 7H
04
Validation
Exposição potencial
BLAST MÉD.
58
MAIS EXPOSTO
acme.com
05
Mobilization
Remediação e progresso
REMEDIAÇÃO
42%
CORRIGIDAS
8
Exposure Benchmark
General Industry · Verizon DBIR 2025
58Sector67Jan 15Feb 20Mar 27May 1
Now
67
Sector Ref
58
Your Median
71
Open Vulnerabilities
By Severity
26
Critical
3
High
7
Medium
12
Low
4
Security Pillars
Achados por pilar · clique para detalhar
C
26Records
3Crit
7High
12Medi
4Low
Security Pillars
Peso efetivo
Application Security
C
Network Resilience
B
Identity & Trust
A
Compromised Systems
D
Mean Time to Remediate
Dias médios por severidade · vs. benchmark
Critical
22dias
benchmark: 15d +7d acima
High
28dias
benchmark: 30d 2d abaixo
Medium
55dias
benchmark: 90d 35d abaixo
Low
120dias
benchmark: 180d 60d abaixo
Fora do Prazo (Abertas)
Critical
3 vulns
avg 22d
How it works

Everything you need,
in one place

Automated scans, a dashboard to manage detected vulnerabilities, and a health score for your environment.

Step 01

Asset curation

Enter your root domain and we automatically map subdomains and exposed assets.

https://cidguard.com.br
Start
cidguard.com.brRoot domain
app.cidguard.com.brWeb app
api.cidguard.com.brPublic API
painel.cidguard.com.brAdmin panel
mail.cidguard.com.brMX / Email
status.cidguard.com.brStatus page
Step 02

Full coverage

While you read this, someone could be mapping your assets. cidguard does it first.

Application
monitored
Network
monitored
Email
monitored
Subdomains
monitored
Threats
monitored
Identity
monitored
Step 04

Continuous benchmark

See where you stand against the industry median — updated every scan cycle.

62SetorJanFevMarAbrMai
Agora
38
Setor
62
Mediana
50
Real time

Detected vulnerabilities

Prioritized by real impact on your operation.

LevelDescription
Critical
Subdomain pointing to an abandoned service
Critical
Company IP listed in a botnet feed
High
Port 8080 exposed with an accessible admin panel
Medium
SPF without -all mechanism — spoofable domain
Coverage

Know first. Your attack surface scanned and monitored

Vulnerabilities are everywhere. The question is: who finds them first, you or the attacker?

01
Application Security

Every point of your application monitored, before it becomes a problem.

Constant vigilance to surface software weaknesses.

02
Network & Infrastructure

Your infrastructure seen through the eyes of whoever tries to breach it.

Exposed services under your control and visibility.

03
Identity & Trust

Your domain is your company’s identity and reputation.

Track your domain’s security with daily monitoring.

04
Threat Intelligence

Early visibility into signs of possible incidents.

Smart monitoring against global C2 and botnet feeds.

Score

One number that says
more than a thousand reports

A 0–100 score with an A–D grade. Updated every scan, auditable.

67
C
-4% vs. last month
Org Risk Score
C
30%
Application Security
Vulnerable software, headers and libraries.
Grade C
B
30%
Network Resilience
Open ports, certificates and exposed infrastructure.
Grade B
A
20%
Identity & Trust
Domains, email and DNS records.
Grade A
D
20%
Compromised Systems
Signs of compromise and threat feeds.
Grade D
Compliance

From Risk to
Compliance Posture


We surface vulnerabilities that impact LGPD/Privacy and ISO/IEC 27001 compliance.

Knowing you have an XSS isn’t enough. You need to know it violates Art. 46 of the LGPD — with technical evidence ready for your data protection officer.

Technical coverage detected externally by cidguard · does not replace a formal certification audit.

LGPD

Lei 13.709/2018

Action required4 of 5 controls assessed
Art. 46Processing Security
Action required
Art. 6 VIIPrevention
Attention
Art. 47Agent Accountability
Attention
Art. 49Security by Design
No findings
Art. 37Records of Processing
Not assessed
ISO 27001

ISO/IEC 27001:2022

Action required4 of 5 controls assessed
A.8.8Vulnerability Management
Action required
A.8.12Data Leakage Prevention
Attention
A.8.20Network Security
Attention
A.8.28Secure Coding
No findings
A.5.1Security Policies
Not assessed

Auditable report generated automatically

PDF with the per-control LGPD + ISO posture, the findings impacting each one, and a content fingerprint (SHA-256) for integrity verification — ready to support audits and conversations with clients, board and your data protection officer. Available on Pro and Enterprise plans.

Continuous monitoring

cidguard works
while you sleep.

Security is not an event, it’s a continuous process. While your team focuses on the product, cidguard monitors, detects and alerts.

Monitoring now
9:41
cidguardnow

Critical vulnerability detected

CVE-2024-3094 · wordpress/6.4 — immediate action recommended.

Proactive alerts available on Pro and Enterprise plans.

01
CVE Monitor

New CVEs cross-checked with your stack every day

cidguard cross-checks your detected stack against the OSV database daily. If a new CVE affects your environment, you’ll be notified.

02
Proactive Alerts

Automatic email when something critical appears

Critical and high findings arrive by email, consolidated per asset. Log in to the platform for description, severity and a suggested fix.

03
Monthly Report

Executive PDF delivered on the 1st of each month

Score, per-pillar evolution, top vulnerabilities and remediation status generated and sent automatically to your team. Ready to share with the board or auditors.

Pricing
Plans

Simple pricing,
no surprises

A single security incident can cost far more than a year of monitoring. Starter is R$ 890/month.

Starter
For teams that want initial visibility into their digital exposure.
R$ 890
per month · 25 assets
Get started
  • 25 monitored assets · 3 users
  • All scanners included
  • 30-day score history
  • Rescan delta (score + severity)
  • Visual dashboard + reports
  • Email support
Most popular
Professional
For teams that need traceability and daily proactive alerts.
R$ 3.190
per month · 50 assets
Get started
  • 50 monitored assets · 5 users
  • 90-day score history
  • Per-pillar (LGPD/ISO) and per-asset delta
  • CVE Monitor + proactive alerts
  • Compliance PDF report
  • Priority email support
Enterprise
For organizations with a complex attack surface and regulatory requirements.
R$ 6.190
per month · 150+ assets
Get started
  • 150+ assets · 25 users
  • 1-year score history
  • Full per-pillar and per-asset delta
  • Automatic monthly email report
  • Proactive onboarding with dedicated CSM
  • Dedicated CSM + quarterly QBR
FAQ

Frequently asked questions

Still have a question? We gathered the main ones here.

A pentest is a snapshot: it shows how you looked that day. But your surface changes every week, a new subdomain, an expiring certificate, an outdated library, a CVE released yesterday. cidguard swaps the snapshot for the movie: it scans your assets continuously, from the viewpoint of whoever tries to break in, and alerts you when something changes. You stop discovering problems in an audit and start fixing them first.

No. cidguard looks at your assets from the outside, exactly as an attacker sees them, with nothing to install, no VPN, no credentials in your network. You just confirm the domain is yours (a DNS TXT record) and the analysis begins. Zero friction with your IT team.

No, and we insist on being honest about it: manual pentests and formal audits play a role no tool automates. cidguard covers the gap between them, the continuous monitoring of what is exposed, and gets you to those moments far more prepared, with the homework done and the evidence in hand.

Every scan produces a 0 to 100 score with an A to D grade, broken down by pillar (application, network, identity, threats). It is not a magic number: it is auditable, you see exactly which findings make it up and how it evolves each cycle. It is the number the board understands and the engineer can defend.

We help you see where your technical vulnerabilities impact LGPD and ISO 27001 controls, with the evidence ready and an auditable PDF report (with an integrity fingerprint) to take to your data protection officer, your board or a client. It is the bridge between "we have an XSS" and "this affects Article 46 of the LGPD". It is not a compliance seal, it is the technical foundation that backs the conversation.

That is where continuous shines. Every day cidguard cross-checks the stack it detected on your assets against public CVE databases. If a new vulnerability starts affecting you, you find out. On the Pro and Enterprise plans, with a proactive email alert the same day, prioritized by real impact.

Yes, and for a security company that is non-negotiable. Each customer is isolated (multi-tenant), access is protected by strong authentication with MFA, everything travels encrypted, and downloading sensitive reports requires a verified domain. We treat your exposure data with the same care we ask you to have with yours.

It starts at R$ 890/month (Starter plan), with no setup fee and no lock-in. It is month to month, you adjust or cancel whenever you want. Compared to the cost of a single incident, it is cheap insurance. You sign up yourself in minutes, right on the site.

Start today

Discover what hackers
already know about you

Your risk score in minutes. Real visibility into what’s exposed right now.