DevShield: your attack surface as a live state, not a PDF.
DevShield is the security module of the Engineering Intelligence Platform. It continuously records what is reachable and discoverable about your company from the outside, reports changes, and brings findings from monitoring and penetration testing into one place โ with history, status and ownership instead of PDF archaeology.

Where it honestly stands
Early Access here means: usable, not finished.
DevShield is being built right now, so we say plainly what runs today and what is still coming. Discovery, breach matching and reporting are in use, in part analyst-assisted rather than fully automated. The self-service interface is growing step by step. For you that means you get the result from day one โ you just cannot yet press every button yourself.
- Available today
- External attack surface discovery, breach matching, manual review, monthly report, platform access for your team
- In progress
- Self-service scans on demand, alerting to Slack and Teams, per-finding status tracking
- Planned
- Linking with pentest findings, API access, trend analysis over time, on-premise variant
The typical case
Nobody did anything wrong. The door is open anyway.
A team spins up a staging environment for a customer pilot in March. The pilot ends in May; the environment stays. In July the certificate expires, in September the address turns up in a scan list, in November a known vulnerability in the service running there becomes public. Until the next penetration test in February nobody looks โ because nobody knows the environment still exists. DevShield is built to break exactly this chain on day one: newly discovered, assessed, reported.
What the module does
Discover, compare, report
Not another dashboard nobody opens โ a small number of solid notifications when something changes.
Asset discovery
Domains, subdomains, IP ranges, reachable services and cloud resources attributed to your company โ including what has not been on anyone's list for years.
Change detection
Every run is compared with the previous one. What gets reported is what is new or has degraded โ not the unchanged inventory.
Leak and credential matching
Credentials on your domains appearing in known breaches, with the source and the date they surfaced.
Risk assessment with context
A human assesses before you see anything. False positives and third-party systems are filtered out; the rest gets a severity and a recommendation.
Findings in one place
Monitoring findings and pentest findings share one model: severity, status, owner, verification. One place instead of four PDFs.
Reports on demand
Monthly report for leadership, technical list for your team, dated evidence for audits under NIS2, ISO 27001 or the CRA.
In operation
How the module works day to day
Define the scope
Domains, brands and cloud accounts that belong to you. Set up once, extendable at any time.
Run and compare
Weekly or monthly depending on the plan. Each result is automatically held against the previous state.
Analyst review
Assessment of the deltas, removal of false positives, added context and recommendation.
Notification and report
Critical items immediately, the rest bundled into the report. Few notifications with a high hit rate instead of constant noise.
Handover into the cycle
Anything needing depth goes into a penetration test. The result comes back as a finding in the same module.
Getting started
See first, decide after
Two ways into the module โ one costs nothing, one costs โฌ199. Both end with a result, not a sales call.
Attack surface check
The free first look at one domain โ no contract, no system access.
- One domain
- Automated discovery plus manual review
- Two-page PDF report
- Result within a few working days
Basic check
A deeper first check with platform access โ you see the results where they will later be maintained.
- Multiple domains and cloud resources
- Matching against known breach data
- Platform access for your team
- Trigger scans yourself within the check
- Result history and status tracking
- Credited against the first monthly plan
Ongoing monitoring
Continuous coverage with notification on change โ Basic monthly, Pro weekly.
- Basic: one domain, monthly run and report
- Pro (โฌ599): up to five domains, weekly
- Alerts on new exposure
- Continuous breach matching
- Pro: 2 hours of analyst time per month
- Included in the Security Cycle retainer
The basic check is credited against ongoing monitoring: book a monthly plan within 30 days and we offset the โฌ199 against your first month.
Inside the platform
Security is not a side show of the engineering platform
DevShield is the security pillar of the Engineering Intelligence Platform โ working with the other modules rather than sitting next to them.
A shared finding model for monitoring and penetration testing
Connections to GitHub, GitLab and Azure DevOps to reconcile against your repositories
Notifications to Slack and Microsoft Teams
Jira integration so findings land where your team already works
Evidence export for audits under NIS2, ISO 27001, TISAX and the CRA
One login, one permission model, one billing model across all modules
Further integrations on request. What your team uses daily is where the notification should arrive โ not in yet another inbox.
Security & data
A security module has to lead on data protection
The same standards as the rest of the platform โ and they matter more for a tool that knows your weaknesses.
Hosting exclusively in the EU
Operated in Frankfurt, Gravelines and Paris. Nothing leaves the EU.
Encrypted at rest
All data is encrypted at rest; credentials and secrets are additionally encrypted and non-recoverable.
No active intervention
Monitoring observes from the outside and does not attack. Active testing happens only within a commissioned penetration test.
Access on a need-to-know basis
Role-based permissions per module and project. Anyone who does not need to see findings does not see them.
Traceable history
Every change to a finding is logged โ including evidence of when something was remediated and verified.
On-premise on request
For environments requiring full data sovereignty we offer operation inside your own infrastructure.
Early Access
Start with the free check
One domain, a few working days, one report on what is visible from outside today. Then you decide whether it becomes ongoing monitoring.