Zum Hauptinhalt springen
Version: Next 🚧

Introduction to Cert-IX

Cert-IX is an AI-assisted cybersecurity platform that brings enterprise-grade security to individuals, small businesses, and mid-sized organizations — without requiring a dedicated security team or an enterprise budget.

Instead of stitching together a dozen point tools, Cert-IX gives you one platform to see what you have, find where you're exposed, prioritize what matters, prove your compliance, and act on clear guidance — with an AI assistant alongside you the whole way.

The problem Cert-IX solves

Modern security is hard for most organizations for three reasons:

  • It's fragmented. Asset inventory, scanning, vulnerability management, and compliance usually live in separate, expensive tools that don't talk to each other.
  • It's expensive and specialist-heavy. Enterprise-grade security has traditionally required headcount most smaller organizations can't justify.
  • It moves fast. New vulnerabilities, new attack techniques, and new regulations arrive constantly.

Cert-IX addresses all three: a single, unified platform, priced for smaller teams, with AI woven throughout to reduce the expertise required — and to keep pace with a changing threat landscape.

How the platform fits together

Cert-IX is built around a simple security lifecycle. Each capability feeds the next, so your security posture improves as a loop rather than a checklist:

Discover → Assess → Prioritize → Comply → Act
assets scans vulnerabilities frameworks guidance
(10 (risk-ranked) & audit (Bobby AI +
engines) recommendations)
  1. Discover every asset you own with Asset Management.
  2. Assess them with the Scan API's 10 security engines.
  3. Prioritize the findings with risk-based Vulnerability Management.
  4. Comply by mapping your posture to frameworks like NIST, ISO 27001, and SOC 2.
  5. Act on prioritized, plain-language guidance — with Bobby, your AI assistant.

Core capabilities

CapabilityWhat it doesLearn more
Security DashboardA single command center with a security score, threat overview, alerts, and one-click actions.Dashboard →
Asset ManagementContinuous inventory of your devices, cloud resources, software, and network — discovered externally or via on-network agents.Asset Management →
Vulnerability ScanningA unified Scan API fronting 10 professional engines (Nmap, OWASP ZAP, Trivy, Nuclei, and more).Scan API →
Vulnerability ManagementRisk-ranked findings from your scans, with severity breakdowns and remediation guidance.Vulnerability Management →
Compliance (Beta)Track frameworks, manage policies, and prepare for audits with evidence collection.Compliance →
Bobby AI AssistantAn AI companion that answers security questions, explains findings, and guides you across the platform.Bobby AI →
DepCheck MCPLet your AI coding agent check dependencies for known vulnerabilities before they enter your codebase.MCPs →

Security & privacy by design

Cert-IX is a security product, so the platform holds itself to the standard it helps you meet. Security and privacy are built into the architecture, not bolted on:

  • EU-based infrastructure. Cert-IX runs on EU-hosted infrastructure. Some sub-processors — for example, the AI assistant — operate in the United States under Standard Contractual Clauses; see the privacy notice for the current list and safeguards.
  • Post-quantum authentication. Sign-in and identity are protected with ML-KEM (FIPS 203) post-quantum key encapsulation, so your authentication stays confidential even against future quantum adversaries.
  • Strong authentication. Multi-factor authentication with TOTP and hardware security keys (WebAuthn / FIDO2), backed by short-lived, signed ES256 tokens.
  • Least-privilege access. Fine-grained role-based access control (RBAC) governs who can see and do what.
  • Privacy-first by default. The platform is designed around GDPR principles — data minimization, purpose limitation, and user rights.
Built for EU and French requirements

Cert-IX is designed EU-first, with the regulatory landscape faced by European organizations — GDPR, NIS2, DORA, and related frameworks — front of mind.

Built for automation

Everything you can do in the dashboard, you can automate:

  • Scan API — submit scans, retrieve results, and manage templates over a REST API secured with scoped API keys, IP allowlisting, and per-key rate limits. Wire it into your CI/CD pipelines and security automation. See the Scan API overview.
  • DepCheck MCP — let your AI coding agent check dependencies for known vulnerabilities before they enter your codebase, over the Model Context Protocol.

Plans

Cert-IX offers three tiers — Free, Starter, and Pro — so you can begin at no cost and scale as your needs grow. Compare features and limits on the Cert-IX pricing page.

Who is Cert-IX for?

  • Individuals & founders who want serious security without hiring for it.
  • Small & medium businesses that need visibility and risk reduction without a SOC.
  • Developers & DevSecOps teams who want scanning and dependency checks native to their pipelines and AI tools.
  • Compliance owners who need to track frameworks and produce audit evidence.

Where to go next

Not sure where to start? Ask Bobby.

Open the assistant from the documentation homepage or the bottom-right corner of the platform and ask anything — for example, "How do I run my first scan?"

War diese Seite hilfreich?