Introduction to Cert-IX
Cert-IX is an AI-assisted cybersecurity platform that brings enterprise-grade security to individuals, small businesses, and mid-sized organizations β without requiring a dedicated security team or an enterprise budget.
Instead of stitching together a dozen point tools, Cert-IX gives you one platform to see what you have, find where you're exposed, prioritize what matters, prove your compliance, and act on clear guidance β with an AI assistant alongside you the whole way.
The problem Cert-IX solvesβ
Modern security is hard for most organizations for three reasons:
- It's fragmented. Asset inventory, scanning, vulnerability management, and compliance usually live in separate, expensive tools that don't talk to each other.
- It's expensive and specialist-heavy. Enterprise-grade security has traditionally required headcount most smaller organizations can't justify.
- It moves fast. New vulnerabilities, new attack techniques, and new regulations arrive constantly.
Cert-IX addresses all three: a single, unified platform, priced for smaller teams, with AI woven throughout to reduce the expertise required β and to keep pace with a changing threat landscape.
How the platform fits togetherβ
Cert-IX is built around a simple security lifecycle. Each capability feeds the next, so your security posture improves as a loop rather than a checklist:
Discover β Assess β Prioritize β Comply β Act
assets scans vulnerabilities frameworks guidance
(10 (risk-ranked) & audit (Bobby AI +
engines) recommendations)
- Discover every asset you own with Asset Management.
- Assess them with the Scan API's 10 security engines.
- Prioritize the findings with risk-based Vulnerability Management.
- Comply by mapping your posture to frameworks like NIST, ISO 27001, and SOC 2.
- Act on prioritized, plain-language guidance β with Bobby, your AI assistant.
Core capabilitiesβ
| Capability | What it does | Learn more |
|---|---|---|
| Security Dashboard | A single command center with a security score, threat overview, alerts, and one-click actions. | Dashboard β |
| Asset Management | Continuous inventory of your devices, cloud resources, software, and network β discovered externally or via on-network agents. | Asset Management β |
| Vulnerability Scanning | A unified Scan API fronting 10 professional engines (Nmap, OWASP ZAP, Trivy, Nuclei, and more). | Scan API β |
| Vulnerability Management | Risk-ranked findings from your scans, with severity breakdowns and remediation guidance. | Vulnerability Management β |
| Compliance (Beta) | Track frameworks, manage policies, and prepare for audits with evidence collection. | Compliance β |
| Bobby AI Assistant | An AI companion that answers security questions, explains findings, and guides you across the platform. | Bobby AI β |
| DepCheck MCP | Let your AI coding agent check dependencies for known vulnerabilities before they enter your codebase. | MCPs β |
Security & privacy by designβ
Cert-IX is a security product, so the platform holds itself to the standard it helps you meet. Security and privacy are built into the architecture, not bolted on:
- EU-based infrastructure. Cert-IX runs on EU-hosted infrastructure. Some sub-processors β for example, the AI assistant β operate in the United States under Standard Contractual Clauses; see the privacy notice for the current list and safeguards.
- Post-quantum authentication. Sign-in and identity are protected with ML-KEM (FIPS 203) post-quantum key encapsulation, so your authentication stays confidential even against future quantum adversaries.
- Strong authentication. Multi-factor authentication with TOTP and hardware security keys (WebAuthn / FIDO2), backed by short-lived, signed ES256 tokens.
- Least-privilege access. Fine-grained role-based access control (RBAC) governs who can see and do what.
- Privacy-first by default. The platform is designed around GDPR principles β data minimization, purpose limitation, and user rights.
Cert-IX is designed EU-first, with the regulatory landscape faced by European organizations β GDPR, NIS2, DORA, and related frameworks β front of mind.
Built for automationβ
Everything you can do in the dashboard, you can automate:
- Scan API β submit scans, retrieve results, and manage templates over a REST API secured with scoped API keys, IP allowlisting, and per-key rate limits. Wire it into your CI/CD pipelines and security automation. See the Scan API overview.
- DepCheck MCP β let your AI coding agent check dependencies for known vulnerabilities before they enter your codebase, over the Model Context Protocol.
Plansβ
Cert-IX offers three tiers β Free, Starter, and Pro β so you can begin at no cost and scale as your needs grow. Compare features and limits on the Cert-IX pricing page.
Who is Cert-IX for?β
- Individuals & founders who want serious security without hiring for it.
- Small & medium businesses that need visibility and risk reduction without a SOC.
- Developers & DevSecOps teams who want scanning and dependency checks native to their pipelines and AI tools.
- Compliance owners who need to track frameworks and produce audit evidence.
Where to go nextβ
- Quick Start Guide β sign in and run your first scan in minutes.
- Dashboard Overview β understand your security score and alerts.
- Scan API Overview β the 10 engines and how to automate scanning.
- Bobby AI Assistant β ask questions in plain language, any time.
Open the assistant from the documentation homepage or the bottom-right corner of the platform and ask anything β for example, "How do I run my first scan?"
Was this page helpful?