Introduction to Cert-IX
Cert-IX is an AI-assisted cybersecurity platform that brings enterprise-grade security to individuals, small businesses, and mid-sized organizations — without requiring a dedicated security team or an enterprise budget.
Instead of stitching together a dozen point tools, Cert-IX gives you one platform to see what you have, find where you're exposed, prioritize what matters, prove your compliance, and act on clear guidance — with an AI assistant alongside you the whole way.
The problem Cert-IX solves
Modern security is hard for most organizations for three reasons:
- It's fragmented. Asset inventory, scanning, vulnerability management, and compliance usually live in separate, expensive tools that don't talk to each other.
- It's expensive and specialist-heavy. Enterprise-grade security has traditionally required headcount most smaller organizations can't justify.
- It moves fast. New vulnerabilities, new attack techniques, and new regulations arrive constantly.
Cert-IX addresses all three: a single, unified platform, priced for smaller teams, with AI woven throughout to reduce the expertise required — and to keep pace with a changing threat landscape.
How the platform fits together
Cert-IX is built around a simple security lifecycle. Each capability feeds the next, so your security posture improves as a loop rather than a checklist:
Discover → Assess → Prioritize → Comply → Act
assets scans vulnerabilities frameworks guidance
(10 (risk-ranked) & audit (Bobby AI +
engines) recommendations)
- Discover every asset you own with Asset Management.
- Assess them with the Scan API's 10 security engines.
- Prioritize the findings with risk-based Vulnerability Management.
- Comply by mapping your posture to frameworks like NIST, ISO 27001, and SOC 2.
- Act on prioritized, plain-language guidance — with Bobby, your AI assistant.
Core capabilities
| Capability | What it does | Learn more |
|---|---|---|
| Security Dashboard | A single command center with a security score, threat overview, alerts, and one-click actions. | Dashboard → |
| Asset Management | Continuous inventory of your devices, cloud resources, software, and network — discovered externally or via on-network agents. | Asset Management → |
| Vulnerability Scanning | A unified Scan API fronting 10 professional engines (Nmap, OWASP ZAP, Trivy, Nuclei, and more). | Scan API → |
| Vulnerability Management | Risk-ranked findings from your scans, with severity breakdowns and remediation guidance. | Vulnerability Management → |
| Compliance (Beta) | Track frameworks, manage policies, and prepare for audits with evidence collection. | Compliance → |
| Bobby AI Assistant | An AI companion that answers security questions, explains findings, and guides you across the platform. | Bobby AI → |
| DepCheck MCP | Let your AI coding agent check dependencies for known vulnerabilities before they enter your codebase. | MCPs → |
Security & privacy by design
Cert-IX is a security product, so the platform holds itself to the standard it helps you meet. Security and privacy are built into the architecture, not bolted on:
- EU-based infrastructure. Cert-IX runs on EU-hosted infrastructure. Some sub-processors — for example, the AI assistant — operate in the United States under Standard Contractual Clauses; see the privacy notice for the current list and safeguards.
- Post-quantum authentication. Sign-in and identity are protected with ML-KEM (FIPS 203) post-quantum key encapsulation, so your authentication stays confidential even against future quantum adversaries.
- Strong authentication. Multi-factor authentication with TOTP and hardware security keys (WebAuthn / FIDO2), backed by short-lived, signed ES256 tokens.
- Least-privilege access. Fine-grained role-based access control (RBAC) governs who can see and do what.
- Privacy-first by default. The platform is designed around GDPR principles — data minimization, purpose limitation, and user rights.
Cert-IX is designed EU-first, with the regulatory landscape faced by European organizations — GDPR, NIS2, DORA, and related frameworks — front of mind.
Built for automation
Everything you can do in the dashboard, you can automate:
- Scan API — submit scans, retrieve results, and manage templates over a REST API secured with scoped API keys, IP allowlisting, and per-key rate limits. Wire it into your CI/CD pipelines and security automation. See the Scan API overview.
- DepCheck MCP — let your AI coding agent check dependencies for known vulnerabilities before they enter your codebase, over the Model Context Protocol.
Plans
Cert-IX offers three tiers — Free, Starter, and Pro — so you can begin at no cost and scale as your needs grow. Compare features and limits on the Cert-IX pricing page.
Who is Cert-IX for?
- Individuals & founders who want serious security without hiring for it.
- Small & medium businesses that need visibility and risk reduction without a SOC.
- Developers & DevSecOps teams who want scanning and dependency checks native to their pipelines and AI tools.
- Compliance owners who need to track frameworks and produce audit evidence.
Where to go next
- Quick Start Guide — sign in and run your first scan in minutes.
- Dashboard Overview — understand your security score and alerts.
- Scan API Overview — the 10 engines and how to automate scanning.
- Bobby AI Assistant — ask questions in plain language, any time.
Open the assistant from the documentation homepage or the bottom-right corner of the platform and ask anything — for example, "How do I run my first scan?"
Questa pagina ti è stata utile?