A security portfolio, built and entering early access
More than twenty modules with AI doing the heavy lifting of recon, triage and prioritisation — from bug bounty to SOC/MDR, threat intelligence, OSINT, OT/ICS and compliance. The portfolio is built; it enters invite-only early access, module by module. We show the real state of each one, with no empty promises: built is not the same as open to the public.
Built · early access
21- Bug Bounty / VDP
JustCyber Bounty
A bug bounty and VDP platform and social network: companies publish programmes, hunters hunt and get paid, with AI triage.
- Security copilot
Norte
A public cybersecurity chat: it answers questions, guides first steps and connects the person to the right service or module, backed by the team.
- Security rating
CyberScore
An external security grade for a domain (A–F), non-intrusive: it assesses exposure, email, TLS and headers. Top of funnel, no sign-up.
- Passive scan + extension
JustCyber Scan
Passive surface scanning on authorised domains, with a browser extension for quick checks. No intrusive traffic by default.
- Vulnerability prioritisation
VulnScan AI
It consolidates scan findings, deduplicates and prioritises by real risk with AI — separating the noise from what needs fixing now.
- OSINT / Investigation
CyberIntel
It researches everything public about a company, person or asset and delivers a structured dossier, with sources and an evidence trail.
- Deep / Dark Web Intel
ShadowSignal
Digital-exposure monitoring: it watches forums, the dark web, Telegram and paste sites for leaks and brand mentions. It only observes; it never buys illicit data.
- Threat Intelligence
ThreatRadar LATAM
It ingests CVEs, CERT advisories and IOCs, correlates them with your technology profile and summarises with AI. Coverage with configurable regional focus.
- Alert triage (SOC)
TriageAI
A triage engine that classifies and enriches security alerts (L1/L2) with AI, handing the analyst only what genuinely needs a human decision.
- Managed detection & response
SOC for SMB (MDR)
Managed detection and response sized for SMBs: event ingestion, detection rules and response with AI triage up front.
- Simulated phishing
PhishGuard AI
Simulated phishing campaigns with AI-generated emails, tailored by role and context, with a report of who clicked and microlearning.
- DevSecOps / SAST
SecureCode AI
AI-assisted code security review: it flags issues by CWE/OWASP, ranks severity and suggests the fix. Sending code to the model is opt-in per repository (fail-closed).
- Compliance automation
ComplianceBot AI
Compliance automation (ISO 27001, SOC 2, PCI, LGPD): it generates policies, collects evidence and tracks maturity in a single score.
- LGPD for buildings
CondoLGPD
LGPD compliance tailored to residential buildings: data mapping, policies, notices and a compliance trail for managers and administrators.
- Regulatory compliance (ANS)
RN964 Cockpit
A compliance cockpit for Brazil's ANS RN 964 rule for health operators: controls, evidence and tracking of regulatory adherence.
- CCTV/IoT monitoring
CondoShield
Discovery and monitoring of a building's IoT/CCTV devices — cameras, DVR/NVR, access control: it detects default credentials, vulnerable firmware and internet exposure.
- OT / ICS visibility
OT Sentinel
OT/ICS visibility and detection for the long tail (cooperatives, small hydro plants, substations): asset inventory, passive parsing of Modbus/DNP3/IEC 61850 and anomaly alerts, without interfering with the process.
- OT / ICS simulation
OT/ICS Cyber Range
An OT/ICS simulation environment to exercise attack and defence in industrial scenarios — without touching the real production environment.
- Labs and challenges (CTF)
Cyber Arena
An arena of hands-on security challenges and labs — real scenarios to exercise and measure technical skill, tied to the Academy.
- Security talent
Talent Marketplace
A showcase connecting cybersecurity professionals to real demand, with profiles validated by the Academy track and the Arena.
- Newsroom
JustCyber News
A cybersecurity newsroom that reports, edits and publishes to a blog — the platform's content and distribution layer.
On the roadmap
04- Dark web (active investigation)
DarkSignal
Active dark-web investigation beyond ShadowSignal's passive monitoring — assisted collection and deeper correlation. Planned.
- Authorised intrusive scanning
Active Scan
Authorised active scanning (Nuclei/nmap/ZAP) beyond JustCyber Scan's passive surface, with an execution worker. On the roadmap.
- Agentic pentest
PentestFlow (PTaaS)
Pentest as a service with AI agents orchestrating recon and exploitation under human supervision. On the roadmap.
- Co-managed SOC / fusion
SOCaaS Fusion Center
Variants of the managed SOC — co-managed and fusion-center models for larger operations, beyond today's SOC for SMB. On the roadmap.
Built does not mean available to the public: each module enters pilot/early access as the platform matures toward go-live.
Want to test a module before launch?
Several products are in progress. If your case fits, let's talk about a pilot and early access.