Security assessments · delivered worldwide

Security testingbuilt for shipping teams.Clear scope. Defensible evidence.

Fixed-scope discovery, web and API pentesting, AppSec and continuous validation. Argus handles repeatable work; experienced reviewers validate material findings and evidence.

Asynchronous by default
Fixed pricing, no surprises
You own the report and the evidence
~/kotav/platform
# security assessment · compliance · monitoring
argus scan --target=api.acme.com --skill=web_full
↳ findings: 3 high, 1 critical
↳ evidence: reviewed · SARIF generated
─────────────────────
argus compliance --framework=NIS2
↳ milestone: 5/12 complete
↳ audit_dossier: READY
─────────────────────
argus watch --interval=24h
↳ delta: +0 new · 2 closed
↳ posture: IMPROVING
// what we do

Four focused ways to
produce security evidence.

Start with a structured diagnostic, test a defined application, add checks to selected repositories or keep product evidence current as threats and software change. Every boundary is explicit before work begins.

most popular first step
01 / pentest

Website and application pentesting

Four fixed scopes, from a simple public website through authenticated applications, APIs, roles and business logic.

  • From €490
  • Fixed authorised scope
  • Expert-validated findings
  • One 30-day retest
compare scopes
from €5,000 · 10 days

Discovery Sprint

A structured, asynchronous diagnostic that maps one product, its security posture and its regulatory exposure — in 10 working days after a complete intake.

  • Secure guided intake
  • Architecture and data-flow map
  • Prioritised security and compliance risks
  • Expert-validated 90-day roadmap
Start here →
02 / argus sentinel

Argus Sentinel

Scheduled Argus assessments for one product, with human review reserved for material findings and two focused manual testing windows each year.

  • From €30,000/year
  • Monthly automated validation
  • Two focused manual windows
  • No on-call obligation
see the boundaries
secure what is shipped

Argus AppSec

Fast automated checks stay distinct from verified findings. Repository access authorises code analysis only; dynamic testing always requires a separate approved scope.

  • Selected-repository onboarding
  • Immutable commit fingerprint
  • Semgrep and dependency results
  • SARIF and repository status checks
  • Specialist review queue
Start scoping

Who this is for

Built for companies that need real security evidence — not checkbox compliance.

SaaS and software houses

Pre-sales security questionnaires, ISO 27001, customer audits

Fintech and payments

DORA ICT risk, PCI DSS scope reduction, penetration test evidence

E-commerce and marketplaces

GDPR compliance, NIS2 readiness, API security

MSPs and IT vendors

Vendor security reviews, white-label pentest reports, NIS2 Annex I

Logistics and industry

NIS2 critical infrastructure, OT/IT boundary assessment

Regulated-sector suppliers

Banking, healthcare and public procurement supply chain requirements

Not a fit for: generic IT support, very early-stage startups without revenue, or companies that want checkbox compliance without real remediation.

How we are different

Automation where it scales. Expert judgment where it matters.

Structured intake and Argus remove repeatable work. Experienced reviewers validate material findings, evidence and remediation guidance before delivery.

Traditional consultancyGeneric scannerKotav Labs
ScopeDefined through callsSelf-configuredStructured and fixed upfront
Client effortWorkshops and meetingsTool setupSecure asynchronous intake
TestingPrimarily manualAutomated onlyArgus-assisted + expert validation
Findings qualityDeep, consultant-ledOften unvalidatedEvidence-backed and reviewed
DeliveryProject-dependentImmediate outputFixed delivery window
RetestOften an add-onRescanOne defined retest included
OwnershipReport deliverablePlatform-dependentReport, SARIF and evidence are yours
// how it works

Defined engagement or recurring validation.
Same operating discipline.

One-shot engagement

from €490
  1. 01Complete the scope and access checklist.
  2. 02Sign Rules of Engagement before testing.
  3. 03Argus-assisted testing with expert validation.
  4. 04Receive the report, evidence, SARIF and one defined retest.

Argus Sentinel

from €30,000/year
  1. 01One primary product under a 12-month scope.
  2. 02Monthly Argus validation and quarterly risk review.
  3. 03Two focused manual testing windows per year.
  4. 04Portal response within two business days; no incident response.
// integrates with

Slots into your existing security stack.

GitHub / GitLab
SARIF upload to Code Scanning
Slack / Teams
Real-time finding alerts
Jira / Linear
Auto-ticket from findings
Cloudflare / Akamai
WAF whitelist for scan windows
Datadog / Splunk
SIEM event ingestion
AWS / GCP / Azure
BYO-LLM via Bedrock / Vertex
Okta / Azure AD
SSO for portal access
PGP Email / SFTP
Encrypted report delivery
Delivery proof

Evidence that stays useful.

Each engagement produces portable evidence, traceable findings and clear remediation guidance. Argus handles repeatable checks; reviewers protect signal quality.

SIGNED
signed authorisation
Rules of Engagement before testing
EXPERT
expert-reviewed findings
Material evidence checked before delivery
PDF + SARIF
portable outputs
PDF, SARIF and reproducible evidence where applicable
1×
included retest
One defined validation of reported fixes
HIGHBroken tenant isolation · CWE-639 · cross-account invoice access
targethttps://app.acme-saas.test/api/invoices/{invoiceId}
evidenceA tenant A session returned tenant B invoice metadata after only the object identifier was changed.
reproGET /api/invoices/tenant-b-id with a tenant A session → 200 OK
impactCross-customer exposure of billing records without elevated privileges.
fixEnforce tenant ownership in the data query and add an object-authorisation regression test.
validationexpert reviewed · evidence retained
// next step

Start with a complete scope.
Then start testing.

Tell us what you need to assess. We confirm the required intake, the smallest suitable engagement and the next available delivery window.

Plano de Recuperação e Resiliência, República Portuguesa e Financiado pela União Europeia — NextGenerationEU