Skip to content
Early access · 50 design-partner spots

See your security the way an attacker does.

LuminaProtect maps your external attack surface — everything your company and your vendors expose to the internet — then turns it into one clear, evidence-backed security score with a prioritized list of what to fix.

  • Passive & outside-in
  • No agents, nothing to install
  • Evidence, not opinions

CISO-grade coverage for a fraction of the $20K+/yr enterprise tools charge — built for the companies that don't have a CISO.

Founders, SMBs & vCISOs are joining our first design-partner cohort — built by security engineers, not marketers.

A unified platform that delivers a continuously updated, auditable, CISO-grade view of your security.

Passive scanning engines
8Passive scanning engines
Risk pillars, one score
5Risk pillars, one score
Critical external risk areas
9Critical external risk areas
Agents to install
0Agents to install
The gap

Most companies carry security without a security department

SMBs, solo founders, and the vCISOs who protect them are stuck between tools that are too expensive, too noisy, or impossible to explain.

Enterprise tools, enterprise prices

Real external monitoring has meant $20K+/year and a security team to run it — out of reach for the businesses that need it most.

Scanners that drown you in noise

Tools that blindly flood your network return thousands of “maybe” findings. Nobody has time to triage a wall of false positives.

A grade you can't defend

Black-box security ratings give you a letter with no proof. You can't show a customer, auditor, or insurer why it says what it says.

And the pressure keeps rising

31%
of breaches now start with a software vulnerability — the top way attackers break inVerizon 2026 DBIR
4.8M
unfilled cybersecurity roles worldwide — most SMBs have no one watching their perimeterISC2 Workforce Study
24/7
your internet-facing surface keeps changing — point-in-time checks go stale the moment they finishWhy continuous, outside-in monitoring matters
How it works

A precise pipeline — broader coverage, without the flood

No blind network flooding, no thousands of raw findings. A proprietary, production-safe engine reads your live surface with a light touch — more coverage and more accurate results, in minutes. Speed comes from correlation, never from skipping checks.

  1. 01

    Map

    Discover your footprint like an attacker

    Point it at a domain. LuminaProtect passively maps your entire internet-facing surface — your own assets and your vendors' — with no agents and nothing to install.

  2. 02

    Correlate

    Confirm real risk, then de-duplicate it

    Targeted, version-aware checks confirm what's real. Then we correlate signals across sources — where rule-based scanners fire the same issue 2–3 times, we resolve it into one confirmed finding — and gate on confidence, so only real risk counts.

  3. 03

    Score & fix

    One score, ranked plain-English fixes

    You get a single versioned score plus a prioritized to-do list — each item backed by captured evidence. Re-run any time and watch a fix turn the score green.

Every finding ships with its evidence

  1. 1Surface & exposure mapComplete
  2. 2Version confirmationHigh confidence
  3. 3Prioritized risk driversRanked
  4. 4Report-ready proofAuditable
Coverage

Five risk pillars. Eight engines. One score.

Eight specialized engines work together to deliver broad, continuous visibility across the critical areas of external cyber risk — then roll up into a single grade.

Vulnerabilities

CVE / KEV / EPSS scoring, end-of-life detection, and risky software versions you actually run.

Example finding · Known-exploited component, confirmed by the version you're running.

Attack surface

Exposed ports and services, forgotten admin panels, DNS hygiene, and TLS / certificate health.

Example finding · A risky admin service is exposed on a public endpoint.

Email identity

SPF, DKIM, DMARC, MTA-STS, DANE, and MX TLS — your resistance to spoofing and impersonation.

Example finding · Your domain can be spoofed — DMARC enforcement is missing.

Trust & reputation

Threat-intel feeds, breach history, and abuse signals tied to your domains and infrastructure.

Example finding · Your domain surfaced on an abuse / breach feed.

Supply chain

Vulnerable client-side libraries and third-party scripts running on the pages your users trust.

Example finding · A vulnerable third-party script is loading on your site.

Your assets + your vendors

Scan and secure both your own internet-facing assets and the third-party vendors you depend on — first-party and supply-chain risk, scored side by side in one place.

Why LuminaProtect

Broader coverage, near-zero noise, real-time insight

A proprietary correlation engine turns broad, low-noise signal into one defensible score — more coverage and more accuracy than rule-based scanners, with far fewer false positives, and never at the cost of hammering your systems.

Correlation nobody else does

Rule-based scanners flag the same issue two or three times. We correlate signals across engines into one confirmed, de-duplicated finding — and gate on confidence, so only high-confidence results move your grade and false positives get cut.

Broad coverage, without the flood

8 specialized engines deliver continuous visibility across 9 critical areas of external risk — through a proprietary active-passive engine that runs a handful of targeted live checks. Higher accuracy, production-safe, results in minutes.

Evidence, not opinions

Every finding ties to a real captured observation — a versioned, auditable score with plain-English drivers you can defend to customers, auditors, and insurers.

Always reflects today

Every scan reads the live surface and reflects today. Re-run any time and watch a fix turn the score green.

Your assets + your vendors

One workspace that grows with you: your own surface → your vendors → code, cloud, and graph. Land and expand.

CISO-grade at SMB economics

CISO-grade security intelligence at SMB-friendly pricing — not the $20K+/year enterprise cost.

The difference

Point tools show you problems. We show you priorities.

Most external-security tools hand you data and leave the hard part — deciding what's real and what to do — to you. LuminaProtect closes that gap.

Point scanners

Long lists of raw technical issues

The gap · Results fragment across tools and need an expert to triage.

With LuminaProtect · Correlated into a short, evidence-backed list of what actually matters — de-duplicated and confidence-gated.

Security ratings

A board-level letter grade

The gap · The number is opaque — hard to defend, harder to improve.

With LuminaProtect · A versioned score with plain-English drivers and the captured evidence behind every point.

Questionnaires

A point-in-time compliance answer

The gap · They go stale fast and rely on manual, unverified proof.

With LuminaProtect · Fresh outside-in evidence standing behind every answer — re-run any time to prove it's still true.

Broad coverage, correlated into one defensible scoreyou know what to fix first, and can prove it.

See what an attacker sees — before they do.

Claim a free outside-in posture review while founding-cohort spots last.

Get my free posture review
Who it's for

Two kinds of teams. Equal footing.

Whether you run security in-house or manage it for a portfolio of clients, LuminaProtect is built around how you actually work.

For in-house teams

SMBs & solo founders

Carry real, enterprise-grade security without hiring a team. See exactly what you expose, what it means, and what to fix first — then prove your posture to customers and insurers.

  • No security team or CISO required
  • Fix-first, plain-English priorities
  • Near-zero noise — only confirmed risk
  • A defensible score to share with buyers & insurers
Purpose-built for advisors

vCISOs & MSSPs

Multi-tenant and white-label from day one — designed for advisors who protect a portfolio. No more juggling a separate login per client, and every report ships under your own brand.

  • Multi-tenant: manage every client from one login
  • White-label, fully brandable PDF reports
  • Portfolio-wide visibility & prioritization
  • Land-and-expand across your whole book of clients

One platform that grows with you

Start with your own assets, add your vendors, then expand into code, cloud, and graph — same workspace, land and expand.

FAQ

Answers before you ask

The essentials on how LuminaProtect works, what it touches, and who it's built for.

Do I need to install anything?

No. LuminaProtect is fully passive and outside-in — there are no agents, no code changes, and nothing to install. You point it at a domain and it maps your internet-facing footprint the way an attacker would.

Is it safe to run against production?

Yes. Instead of blindly flooding your network, our active-passive engine performs a handful of targeted, version-aware checks. It's production-safe, higher-accuracy, and returns results in minutes.

Do you need permission to scan my organization?

For your own domains, there's no special setup or authorization to arrange — LuminaProtect only observes what's already publicly visible on the internet, the same surface an attacker or search engine can see. It never logs in, touches internal systems, or runs intrusive tests. Vendors are assessed from those same publicly observable signals, so you can measure third-party risk without access to their environment.

What data do you collect and store?

Only publicly observable, internet-facing signals — no credentials, no internal access, and nothing installed on your systems. We securely retain the evidence behind each finding so your score stays auditable and defensible, and so you can see how your posture changes over time.

How is the security score calculated?

From five risk pillars scored by eight specialized engines. The methodology is versioned and auditable, every finding is backed by captured evidence, and only high-confidence results move the grade — so the score is one you can defend to customers, auditors, and insurers.

How is it different from a security rating?

Ratings hand you an opaque letter grade you can't dig into or easily improve. LuminaProtect gives you a versioned score with plain-English drivers and the captured evidence behind every point — correlated and de-duplicated, so you see priorities instead of a black-box number.

Can I monitor my third-party vendors too?

Yes. LuminaProtect scores both your own internet-facing assets and your vendors, so first-party and supply-chain risk live in one place. You start with your own surface and expand to vendors, code, and cloud as you grow.

Is it white-label for advisors?

Yes. LuminaProtect is multi-tenant and white-label ready, built for vCISOs and small MSSPs who protect a portfolio of clients under their own brand.

Does it replace a CISO?

No — it makes existing security effort go further. LuminaProtect gives teams without a dedicated security function (and the vCISOs who serve them) the attacker's-eye visibility and prioritized, evidence-backed actions a CISO would push for. It informs decisions; it doesn't replace judgment.

What stage is the product at?

Pre-launch and MVP-complete — a working, multi-tenant, heavily tested platform. We're now opening early access to a small group of design partners.

What does it cost, and how do I get started?

We're in pre-launch and opening early access to a small founding cohort of design partners, who help shape the roadmap and get hands-on pricing as we finalize plans. To start, request a free outside-in posture review — we'll map your public surface and walk you through what we find, with nothing to install.

Early access · Limited cohort

Get a fresh, attacker's-eye view of your security.

We're hand-selecting 50 design partners — SMBs, founders, vCISOs, and MSSPs — to evaluate LuminaProtect before public launch, and to help shape it.

  • A free outside-in posture review of your own domain
  • Early access to the platform and a direct line to the founding team
  • A real say in scoring, reports, findings, and onboarding

Spots are limited. Founders, SMBs & vCISOs are already claiming their cohort seats.

No credit cardNo spamUnsubscribe anytime

Company email required — it keeps our first cohort focused on serious evaluators.

Every request is reviewed by a human before we invite evaluators. We use your details only to contact you about early access — no spam, no reselling.