Passa al contenuto principale
Versione: Next 🚧

Introduction to Cert-IX

Cert-IX is an AI-assisted cybersecurity platform that brings enterprise-grade security to individuals, small businesses, and mid-sized organizations — without requiring a dedicated security team or an enterprise budget.

Instead of stitching together a dozen point tools, Cert-IX gives you one platform to see what you have, find where you're exposed, prioritize what matters, prove your compliance, and act on clear guidance — with an AI assistant alongside you the whole way.

The problem Cert-IX solves​

Modern security is hard for most organizations for three reasons:

  • It's fragmented. Asset inventory, scanning, vulnerability management, and compliance usually live in separate, expensive tools that don't talk to each other.
  • It's expensive and specialist-heavy. Enterprise-grade security has traditionally required headcount most smaller organizations can't justify.
  • It moves fast. New vulnerabilities, new attack techniques, and new regulations arrive constantly.

Cert-IX addresses all three: a single, unified platform, priced for smaller teams, with AI woven throughout to reduce the expertise required — and to keep pace with a changing threat landscape.

How the platform fits together​

Cert-IX is built around a simple security lifecycle. Each capability feeds the next, so your security posture improves as a loop rather than a checklist:

Discover → Assess → Prioritize → Comply → Act
assets scans vulnerabilities frameworks guidance
(10 (risk-ranked) & audit (Bobby AI +
engines) recommendations)
  1. Discover every asset you own with Asset Management.
  2. Assess them with the Scan API's 10 security engines.
  3. Prioritize the findings with risk-based Vulnerability Management.
  4. Comply by mapping your posture to frameworks like NIST, ISO 27001, and SOC 2.
  5. Act on prioritized, plain-language guidance — with Bobby, your AI assistant.

Core capabilities​

CapabilityWhat it doesLearn more
Security DashboardA single command center with a security score, threat overview, alerts, and one-click actions.Dashboard →
Asset ManagementContinuous inventory of your devices, cloud resources, software, and network — discovered externally or via on-network agents.Asset Management →
Vulnerability ScanningA unified Scan API fronting 10 professional engines (Nmap, OWASP ZAP, Trivy, Nuclei, and more).Scan API →
Vulnerability ManagementRisk-ranked findings from your scans, with severity breakdowns and remediation guidance.Vulnerability Management →
Compliance (Beta)Track frameworks, manage policies, and prepare for audits with evidence collection.Compliance →
Bobby AI AssistantAn AI companion that answers security questions, explains findings, and guides you across the platform.Bobby AI →
DepCheck MCPLet your AI coding agent check dependencies for known vulnerabilities before they enter your codebase.MCPs →
SecCheck MCPGive your AI agent 857 curated security and compliance playbooks — offensive, defensive, and GRC — so security work follows a written procedure.SecCheck →
Bits MCPLet your AI client recommend a Cert-IX host agent, give you a verifiable download and draft its configuration for you to review — no account or API key, and it deploys nothing.Bits →

Security & privacy by design​

Cert-IX is a security product, so the platform holds itself to the standard it helps you meet. Security and privacy are built into the architecture, not bolted on:

  • EU-based infrastructure. Cert-IX runs on EU-hosted infrastructure. Some sub-processors — for example, the AI assistant — operate in the United States under Standard Contractual Clauses; see the privacy notice for the current list and safeguards.
  • Post-quantum authentication. Sign-in and identity are protected with ML-KEM (FIPS 203) post-quantum key encapsulation, so your authentication stays confidential even against future quantum adversaries.
  • Strong authentication. Multi-factor authentication with TOTP and hardware security keys (WebAuthn / FIDO2), backed by short-lived, signed ES256 tokens.
  • Least-privilege access. Fine-grained role-based access control (RBAC) governs who can see and do what.
  • Privacy-first by default. The platform is designed around GDPR principles — data minimization, purpose limitation, and user rights.
Built for EU and French requirements

Cert-IX is designed EU-first, with the regulatory landscape faced by European organizations — GDPR, NIS2, DORA, and related frameworks — front of mind.

Built for automation​

Everything you can do in the dashboard, you can automate:

  • Scan API — submit scans, retrieve results, and manage templates over a REST API secured with scoped API keys, IP allowlisting, and per-key rate limits. Wire it into your CI/CD pipelines and security automation. See the Scan API overview.
  • DepCheck MCP — let your AI coding agent check dependencies for known vulnerabilities before they enter your codebase, over the Model Context Protocol.
  • SecCheck MCP — give the same agent 857 curated security and compliance playbooks, so it follows a written procedure instead of improvising. See the SecCheck overview.
  • Bits MCP — let it recommend a Cert-IX host agent, hand you a download you can verify (version, size, SHA-256) and draft a configuration for you to review, with no key needed. See the Bits overview.

Plans​

Cert-IX offers three tiers — Free, Starter, and Pro — so you can begin at no cost and scale as your needs grow. Compare features and limits on the Cert-IX pricing page.

Who is Cert-IX for?​

  • Individuals & founders who want serious security without hiring for it.
  • Small & medium businesses that need visibility and risk reduction without a SOC.
  • Developers & DevSecOps teams who want scanning and dependency checks native to their pipelines and AI tools.
  • Compliance owners who need to track frameworks and produce audit evidence.

Where to go next​

Not sure where to start? Ask Bobby.

Open the assistant from the documentation homepage or the bottom-right corner of the platform and ask anything — for example, "How do I run my first scan?"

Questa pagina ti è stata utile?