Attack Surface Monitoring · AI Security

We find the spark
before it becomes a fire.

Attack-surface monitoring, penetration testing, and AI/LLM security testing for startups and SMEs.

Continuous, automated attack-surface and AI-system monitoring for teams that can't afford an enterprise security budget — and can't afford a breach either.

Google VRP–credited researcher Self-hosted, verification-first engine Bilingual — বাংলা + English Bangladesh + Global
$2.26B
AI red-teaming market, 2026
Aug 2
EU AI Act enforcement begins, 2026
~14%
orgs with in-house AI-security talent
#1
OWASP LLM risk — prompt injection

Industry context compiled from Mordor Intelligence, Promptfoo and OWASP research, as referenced in the Cindrasec 2026 market analysis.

Free Tool

How exposed are you, actually?

Free attack-surface risk calculator.

Four questions, a rough exposure score, and a plain recommendation — calculated in your browser, nothing sent anywhere.

What does your team run publicly?
Does anything use an LLM or AI chatbot?
When was your last external security check?
Team size handling security today?
Estimated exposure
/ 100

This is a directional estimate, not an audit — it's here to help you triage, not to replace a scan.

Services

Four ways in — one engine underneath.

Attack-surface scanning, continuous monitoring, and AI/LLM security assessment services.

Every offering runs on the same SecretNode scanning engine, so pricing stays low and delivery stays fast.

First one free — founding cohort

Snapshot

A one-time look at everything of yours that's reachable from the public internet — exposed secrets, forgotten subdomains, misconfigurations.

  • External attack-surface + exposed-secrets scan
  • Verification-first report (every finding confirmed)
  • 15-min walkthrough call + free re-check
৳15,000–25,000one-time · report in 3–5 working days
Start with a Snapshot →

AI/LLM Security

For teams shipping a chatbot, agent, MCP server, or LLM feature. We try to break it the way a real attacker would — before they do.

  • Prompt-injection & jailbreak testing
  • Data-leak & system-prompt exposure
  • Agent / tool-abuse testing (test accounts only)
  • MCP & tool-surface review — tool poisoning, indirect injection, consent flows
৳40,000–1,50,000per engagement · 2–5 days
Book an assessment →

Productized Gig

A single, tightly-scoped check with a fixed price and fast turnaround — the lowest-commitment way to start.

  • One specific target, one clear deliverable
  • Fixed price agreed up front
  • Ideal for Fiverr / Upwork-style buyers
৳7,000–15,000fixed scope · 2–4 hrs delivery
See gig scope →

Ranges depend on one thing only: how many domains and assets are in scope. We confirm the exact figure and give you a fixed quote before you pay anything. No hourly billing, no surprise scope.

Nothing without your signature

Every scan runs only under a signed Rules of Engagement. No drive-by testing, ever.

Passive-first — safe by design

We look, we don't break. Your systems are never modified or taken offline.

Your data, deleted on request

Self-hosted, encrypted, auto-purged in 30 days — or sooner if you ask. No trackers.

First Snapshot is free

Founding-cohort clients pay nothing for the first scan. See the value before you spend.

Process

From intake to a verified report — nothing skipped.

Our security assessment process, step by step.

Two checkpoints are never automated away: authorization, and the final severity call on anything critical.

01

Intake

Quick scope form — domains, targets, goals.

02

Authorize

Signed RoE + Authorization Letter. Non-negotiable gate.

03

Scan

SecretNode passive scan, strictly within authorized scope.

04

Verify & Report

AI-drafted report plus a human severity review.

05

Delivery Call

A 15–20 min walkthrough of every finding.

06

Free Re-check

Two weeks later, then an easy path into Watch.

How We Work

Three rules that never bend.

Authorized, ethical penetration testing — how we handle scope, data, and disclosure.

RULE 01

Authorization before anything

No scan ever starts without a signed Rules of Engagement and Authorization Letter naming the exact scope and time window. There is no drive-by scanning — not for demos, not for pilots, not ever.

RULE 02

Your data stays minimal and mortal

Scan data lives on self-hosted infrastructure, encrypted at rest, kept only as long as the engagement needs it — and deleted on request. No third-party analytics, no trackers, no cookies on this site either.

RULE 03

Findings go to you — and only you

The same responsible-disclosure discipline behind the Google VRP track record applies to every engagement: verified before reported, severity calibrated honestly, and never disclosed to anyone but you.

Why Cindrasec

The moat isn't the tool. It's how it's run.

Why teams choose Cindrasec for attack-surface and AI/LLM security.

Anyone can copy a scanner. These five things compound instead.

Verification-First

Every finding is confirmed before you see it — you get signal, not a wall of false positives.

Recurring, Not One-off

Monthly diff reports keep you covered between big reviews — security as a habit, not a yearly panic.

Local Trust, Global Reach

Bilingual delivery — বাংলা support paired with international-grade reporting.

Niche Authority

Focused only on attack surface and AI/LLM security — not a generalist agency.

Built for Speed

Automation-first pipeline delivers in days where agencies take weeks.

Track Record

Findings that were actually accepted — not hypotheticals.

Verified vulnerability research and a Google VRP disclosure track record.

Cindrasec is new as a business, but the researcher behind it isn't new to disclosure. A sample of confirmed, redacted findings from the Google Vulnerability Reward Program:

Confirmed · P2

Cross-tenant load balancer misconfiguration

A Google-acquired product's subdomains shared a load balancer in a way that allowed cross-tenant routing exposure. Confirmed and assigned P2 severity by a Google engineer.

Google VRP · acquisition-scope target
Critical · NS delegation

Dangling nameserver delegation

A subdomain on Google-acquired infrastructure delegated to a nameserver provider whose account had lapsed — a takeover path later confirmed and classified critical.

Custom NS-takeover scanner · Google-acquired target
Closed · WAI / P4

CORS misconfiguration — a lesson kept, not hidden

A CORS header-reflection issue was reported and closed as working-as-intended. It's on this list on purpose: header reflection alone isn't enough, and every report Cindrasec sends holds itself to that same higher bar.

Included for calibration, not just wins

The three above stay redacted until their disclosure timelines clear. Two other findings are published in full — the authentication bypass reported to Google VRP, including why it resolved to credit rather than cash, and a measured 4.6× gap in prompt-injection resistance with full reproduction steps — also on GitHub, translated into 9 languages. See also a sample client-facing report format (PDF).

Founding Cohort

Your first Snapshot is free — here's the deal.

Free attack-surface security assessment for founding-cohort clients.

We're onboarding a small number of pilot clients at no cost to build honest, redacted case studies. You get a real scan and a real report; we get proof. Every client works directly with the researcher behind the scan — not a support queue. Slots are limited by design, not marketing.

Signed RoE on every engagement Real report, yours to keep Case study only with your consent
Md. Azmol Haque Rony
Founder & Principal Security Researcher

Google VRP–credited, with a calibrated, responsible-disclosure track record. Builds and runs the SecretNode scanning engine end to end.

Pricing

Clear, fixed-scope pricing. No hourly billing.

Attack-surface and AI/LLM security assessment pricing.

Toggle ৳ / $ above. The range depends only on scope size — you always get a fixed quote before paying.

★ Founding cohort: your first Snapshot is free

A real scan and a real report at no cost, under a signed RoE — while pilot slots last. The prices below apply after that.

Claim a free Snapshot →
TierWhat's includedDeliveryPrice
Snapshot External surface + exposed-secrets scan, verified report, walkthrough call, free re-check 3–5 working days ৳15k–25k
Watch Continuous monitoring, monthly diff report, real-time alerts — fully done-for-you Monthly · cancel anytime ৳5k–12k/mo
AI/LLM Security Prompt-injection, jailbreak, data-leak, agent-abuse & MCP tool-surface testing on your LLM systems 2–5 days ৳40k–1.5L
Productized Gig One tightly-scoped check, one clear deliverable, fixed price agreed up front 2–4 hrs ৳7k–15k
Traditional one-time pentest
৳5,00,000+
  • A single snapshot in time, then nothing
  • Weeks of turnaround
  • Out of reach for most SMEs
Cindrasec
A fraction of that — continuous
  • Automation makes the first pass near-free
  • Report in days, alerts in real time
  • Priced for founders, not enterprises

How billing works

Local (Bangladesh)

bKash or bank transfer, invoiced in Taka. A 50% advance starts the work; the balance is due on delivery.

Global

Payoneer or Wise, billed in USD as an export of service. Same 50% advance, 50% on delivery.

Always

No payment link on this site by design — you get a proper invoice after a quick scope call and a signed RoE.

Watch subscriptions are month-to-month with no lock-in. The founding-cohort Snapshot is genuinely free — no card, no obligation to continue.
FAQ

Before you reach out.

Frequently asked questions about scope, legality, pricing, and data handling.

Is scanning my systems even legal?

Yes — every engagement starts with a signed Rules of Engagement and Authorization Letter covering scope, time window, and data handling. Scans are passive-first and never touch anything outside the agreed scope. No signed authorization, no scan — that's a hard rule, not a formality.

Will testing break or slow down my site?

No. Testing is passive-first and rate-limited — we observe what's publicly reachable rather than attacking it. We never exploit, never overload, and never modify or delete your data. Your systems keep running exactly as they were.

How much does it cost, and why the range?

A Snapshot is ৳15k–25k ($250–600); Watch is ৳5k–12k/mo ($150–500); AI/LLM assessments are ৳40k–1.5L ($2,000–8,000). The range depends only on how many domains and assets are in scope — we confirm the exact figure and give a fixed quote before you pay. And the first Snapshot is free for founding-cohort clients.

How do I pay?

Local clients: bKash or bank transfer in Taka. Global clients: Payoneer or Wise in USD. It's 50% advance to start and 50% on delivery, invoiced after a quick scope call — there's no payment button on this site by design.

We're small — are we even a target?

Attackers don't hand-pick you; they scan the whole internet for anything left open — an exposed key, a forgotten subdomain, a stale admin panel. Small teams get breached exactly because they assume no one's looking. A Snapshot tells you what's actually exposed, cheaply, before it becomes an incident.

What if the scan finds nothing?

A clean scan is still a report: you get a coverage summary, a confidence statement, and a clear picture of what was and wasn't in scope — never just "we found nothing."

How is client data handled?

Data minimization by default: stored on self-hosted infrastructure, encrypted at rest, redacted where possible, and auto-purged 30 days after delivery — or sooner on request. Findings go only to the person you name.

Can international clients work with Cindrasec?

Yes — global engagements are billed in USD via Payoneer or Wise, delivered in English, and treated as an export of service.

Get Started

Don't wait for the fire alarm.

Tell us what to look at — a free Snapshot is the fastest way to see what's actually exposed.

Sent straight to our inbox — we usually reply within a day. No live scan ever starts without a signed Rules of Engagement.

Privacy

What this site collects, and what we do with it

Short version: nothing, unless you send the form. A security studio that quietly tracked its visitors would be worth exactly nothing to you.

Just visiting

No cookies, no analytics, no tracking pixels, no fingerprinting, and nothing written to browser storage. Fonts are served from this domain, so no font CDN sees your visit either. The exposure estimator scores entirely inside your browser — your answers are never transmitted, to us or to anyone. The only file cached on your device is the page itself, so it works offline.

If you send the contact form

We receive your name and email, plus the service you picked and — only if you fill them in — your domain and message. It reaches us through Web3Forms, a form-relay service, and lands as an email at contact@cindrasec.com. We use it to reply to you and nothing else. It is never sold, never added to a marketing list, and never shared with anyone outside Cindrasec.

If you become a client

Scan data is kept to the minimum the work needs: stored on self-hosted infrastructure, encrypted at rest, redacted where possible, and auto-purged 30 days after delivery — or sooner if you ask. Findings go only to the person you name in the Rules of Engagement. Scope, testing window and data handling are all written into that document before anything is scanned.

Who else touches your data

Two services, both named: Web3Forms delivers the contact form, and GitHub Pages hosts this site and therefore sees the usual web-server request logs. That is the complete list. This page makes exactly one cross-origin request in its entire lifetime, and only when you press Send.

Asking us to show or delete what we hold

Email contact@cindrasec.com and ask. We will tell you what we hold about you, correct it, or delete it — within 30 days, and usually the same week. You do not need to give a reason, and you can withdraw an authorization to test in writing at any moment, at which point testing stops immediately.

Last updated 31 July 2026. Questions about any of this go to contact@cindrasec.com.