Services
Understand veyrisk
PricingDemo consoleContact
EN
Sign inBuy now
■ What is veyrisk?

See what can be reached from outside.

veyrisk is an exposure management platform. It shows a company which of its systems can be reached from the internet, where it may be vulnerable and what should be fixed first.

■ In brief

Every company has an attack surface

Website, mail server, VPN access, online shop, customer portal, cloud accounts, user accounts in Microsoft 365: everything that can be reached from the internet is part of the attack surface. It grows with every new service. Test systems stay online, certificates expire, updates get postponed, and after a few years nobody knows exactly what is reachable.

veyrisk maps this attack surface automatically, checks it regularly and summarises the results so that it is clear what to do, even without a dedicated security team.

■ Process

How veyrisk works

01

Discover

You enter your domain. veyrisk looks for related subdomains in public certificate logs and in DNS and builds an inventory from them. Cloud accounts and Microsoft 365 are connected with read-only permissions.

02

Check

Passive checks run daily and behave like a normal visitor. Active checks such as port scans and vulnerability scans only run once you have proven via a DNS record that the domain belongs to you.

03

Assess

Every finding gets a priority from 0 to 100. It takes into account the severity, whether the vulnerability is actively exploited and how important the affected system is. What really matters comes first.

04

Fix and prove

Every finding comes with a concrete recommendation. The next scan shows whether the gap is closed. Reports for IT, management and auditors are created at the push of a button.

■ Why

Why a company needs this

  • Attackers scan the internet automatically and around the clock for known vulnerabilities. They often don't choose their targets, they take what they find.
  • The biggest risks are often in systems nobody thinks about any more: old test environments, forgotten subdomains, an open remote maintenance access.
  • Updates alone are not enough. Many findings are misconfigurations, such as a publicly reachable admin interface or missing email protection.
  • Customers, insurers and auditors increasingly ask for evidence. ISO 27001 and NIS2 require a structured vulnerability management.
■ Limits

What veyrisk is not

veyrisk does not replace a manual penetration test, where experts deliberately try to break into systems. The platform checks continuously and broadly, a pentest selectively and in depth. The two complement each other. You can request a penetration test by the experts of neonotu GmbH directly from us.

veyrisk is also not antivirus software or real-time attack detection. The platform changes nothing on your systems and only actively checks what demonstrably belongs to you.

■ Operator

Who is behind veyrisk

veyrisk is developed and operated by neonotu GmbH in Munich. The platform runs on its own servers in Germany. Sign-in is only possible with two-factor authentication, and data processing is covered by a contract.

■ FAQ

Frequently asked questions

Does veyrisk need access to our servers?

No. veyrisk checks from the outside, the way an attacker sees your systems. For cloud accounts and Microsoft 365, read-only access is enough.

Is veyrisk allowed to simply scan our systems?

Passive checks only concern publicly available information. Active checks only run once you have proven via a DNS record that the domain belongs to you. For systems a provider runs for you, you should inform them in advance.

How much effort is the setup?

You enter your domain and set a DNS record as proof of ownership. After that, the first scan runs automatically. If you like, you can also book an onboarding session with our team.

Does veyrisk replace a penetration test?

No. veyrisk provides continuous, broad checks. A penetration test goes into depth at a point in time. For ISO 27001 and NIS2, the combination of both is common.

■ Free first scan

What does your attack surface look like?

We scan your external attack surface for free and walk you through the results in 30 minutes.