We find the spark
before it becomes a fire.
Attack-surface monitoring, penetration testing, and AI/LLM security testing for startups and SMEs.
Continuous, automated attack-surface and AI-system monitoring for teams that can't afford an enterprise security budget — and can't afford a breach either.
Industry context compiled from Mordor Intelligence, Promptfoo and OWASP research, as referenced in the Cindrasec 2026 market analysis.
How exposed are you, actually?
Free attack-surface risk calculator.
Four questions, a rough exposure score, and a plain recommendation — calculated in your browser, nothing sent anywhere.
This is a directional estimate, not an audit — it's here to help you triage, not to replace a scan.
Four ways in — one engine underneath.
Attack-surface scanning, continuous monitoring, and AI/LLM security assessment services.
Every offering runs on the same SecretNode scanning engine, so pricing stays low and delivery stays fast.
Snapshot
A one-time look at everything of yours that's reachable from the public internet — exposed secrets, forgotten subdomains, misconfigurations.
- External attack-surface + exposed-secrets scan
- Verification-first report (every finding confirmed)
- 15-min walkthrough call + free re-check
Watch
Your Snapshot, kept current. We watch your surface continuously and tell you the moment something new appears.
- Continuous monitoring, done-for-you
- Monthly diff report (what changed & why)
- Real-time alert on every new finding
AI/LLM Security
For teams shipping a chatbot, agent, MCP server, or LLM feature. We try to break it the way a real attacker would — before they do.
- Prompt-injection & jailbreak testing
- Data-leak & system-prompt exposure
- Agent / tool-abuse testing (test accounts only)
- MCP & tool-surface review — tool poisoning, indirect injection, consent flows
Productized Gig
A single, tightly-scoped check with a fixed price and fast turnaround — the lowest-commitment way to start.
- One specific target, one clear deliverable
- Fixed price agreed up front
- Ideal for Fiverr / Upwork-style buyers
Ranges depend on one thing only: how many domains and assets are in scope. We confirm the exact figure and give you a fixed quote before you pay anything. No hourly billing, no surprise scope.
Nothing without your signature
Every scan runs only under a signed Rules of Engagement. No drive-by testing, ever.
Passive-first — safe by design
We look, we don't break. Your systems are never modified or taken offline.
Your data, deleted on request
Self-hosted, encrypted, auto-purged in 30 days — or sooner if you ask. No trackers.
First Snapshot is free
Founding-cohort clients pay nothing for the first scan. See the value before you spend.
From intake to a verified report — nothing skipped.
Our security assessment process, step by step.
Two checkpoints are never automated away: authorization, and the final severity call on anything critical.
Intake
Quick scope form — domains, targets, goals.
Authorize
Signed RoE + Authorization Letter. Non-negotiable gate.
Scan
SecretNode passive scan, strictly within authorized scope.
Verify & Report
AI-drafted report plus a human severity review.
Delivery Call
A 15–20 min walkthrough of every finding.
Free Re-check
Two weeks later, then an easy path into Watch.
Three rules that never bend.
Authorized, ethical penetration testing — how we handle scope, data, and disclosure.
Authorization before anything
No scan ever starts without a signed Rules of Engagement and Authorization Letter naming the exact scope and time window. There is no drive-by scanning — not for demos, not for pilots, not ever.
Your data stays minimal and mortal
Scan data lives on self-hosted infrastructure, encrypted at rest, kept only as long as the engagement needs it — and deleted on request. No third-party analytics, no trackers, no cookies on this site either.
Findings go to you — and only you
The same responsible-disclosure discipline behind the Google VRP track record applies to every engagement: verified before reported, severity calibrated honestly, and never disclosed to anyone but you.
The moat isn't the tool. It's how it's run.
Why teams choose Cindrasec for attack-surface and AI/LLM security.
Anyone can copy a scanner. These five things compound instead.
Verification-First
Every finding is confirmed before you see it — you get signal, not a wall of false positives.
Recurring, Not One-off
Monthly diff reports keep you covered between big reviews — security as a habit, not a yearly panic.
Local Trust, Global Reach
Bilingual delivery — বাংলা support paired with international-grade reporting.
Niche Authority
Focused only on attack surface and AI/LLM security — not a generalist agency.
Built for Speed
Automation-first pipeline delivers in days where agencies take weeks.
Findings that were actually accepted — not hypotheticals.
Verified vulnerability research and a Google VRP disclosure track record.
Cindrasec is new as a business, but the researcher behind it isn't new to disclosure. A sample of confirmed, redacted findings from the Google Vulnerability Reward Program:
Cross-tenant load balancer misconfiguration
A Google-acquired product's subdomains shared a load balancer in a way that allowed cross-tenant routing exposure. Confirmed and assigned P2 severity by a Google engineer.
Dangling nameserver delegation
A subdomain on Google-acquired infrastructure delegated to a nameserver provider whose account had lapsed — a takeover path later confirmed and classified critical.
CORS misconfiguration — a lesson kept, not hidden
A CORS header-reflection issue was reported and closed as working-as-intended. It's on this list on purpose: header reflection alone isn't enough, and every report Cindrasec sends holds itself to that same higher bar.
The three above stay redacted until their disclosure timelines clear. Two other findings are published in full — the authentication bypass reported to Google VRP, including why it resolved to credit rather than cash, and a measured 4.6× gap in prompt-injection resistance with full reproduction steps — also on GitHub, translated into 9 languages. See also a sample client-facing report format (PDF).
Your first Snapshot is free — here's the deal.
Free attack-surface security assessment for founding-cohort clients.
We're onboarding a small number of pilot clients at no cost to build honest, redacted case studies. You get a real scan and a real report; we get proof. Every client works directly with the researcher behind the scan — not a support queue. Slots are limited by design, not marketing.
Google VRP–credited, with a calibrated, responsible-disclosure track record. Builds and runs the SecretNode scanning engine end to end.
Clear, fixed-scope pricing. No hourly billing.
Attack-surface and AI/LLM security assessment pricing.
Toggle ৳ / $ above. The range depends only on scope size — you always get a fixed quote before paying.
| Tier | What's included | Delivery | Price |
|---|---|---|---|
| Snapshot | External surface + exposed-secrets scan, verified report, walkthrough call, free re-check | 3–5 working days | ৳15k–25k$250–600 |
| Watch | Continuous monitoring, monthly diff report, real-time alerts — fully done-for-you | Monthly · cancel anytime | ৳5k–12k/mo$150–500/mo |
| AI/LLM Security | Prompt-injection, jailbreak, data-leak, agent-abuse & MCP tool-surface testing on your LLM systems | 2–5 days | ৳40k–1.5L$2,000–8,000 |
| Productized Gig | One tightly-scoped check, one clear deliverable, fixed price agreed up front | 2–4 hrs | ৳7k–15k$150–500 |
- A single snapshot in time, then nothing
- Weeks of turnaround
- Out of reach for most SMEs
- Automation makes the first pass near-free
- Report in days, alerts in real time
- Priced for founders, not enterprises
How billing works
bKash or bank transfer, invoiced in Taka. A 50% advance starts the work; the balance is due on delivery.
Payoneer or Wise, billed in USD as an export of service. Same 50% advance, 50% on delivery.
No payment link on this site by design — you get a proper invoice after a quick scope call and a signed RoE.
Before you reach out.
Frequently asked questions about scope, legality, pricing, and data handling.
Is scanning my systems even legal?
Yes — every engagement starts with a signed Rules of Engagement and Authorization Letter covering scope, time window, and data handling. Scans are passive-first and never touch anything outside the agreed scope. No signed authorization, no scan — that's a hard rule, not a formality.
Will testing break or slow down my site?
No. Testing is passive-first and rate-limited — we observe what's publicly reachable rather than attacking it. We never exploit, never overload, and never modify or delete your data. Your systems keep running exactly as they were.
How much does it cost, and why the range?
A Snapshot is ৳15k–25k ($250–600); Watch is ৳5k–12k/mo ($150–500); AI/LLM assessments are ৳40k–1.5L ($2,000–8,000). The range depends only on how many domains and assets are in scope — we confirm the exact figure and give a fixed quote before you pay. And the first Snapshot is free for founding-cohort clients.
How do I pay?
Local clients: bKash or bank transfer in Taka. Global clients: Payoneer or Wise in USD. It's 50% advance to start and 50% on delivery, invoiced after a quick scope call — there's no payment button on this site by design.
We're small — are we even a target?
Attackers don't hand-pick you; they scan the whole internet for anything left open — an exposed key, a forgotten subdomain, a stale admin panel. Small teams get breached exactly because they assume no one's looking. A Snapshot tells you what's actually exposed, cheaply, before it becomes an incident.
What if the scan finds nothing?
A clean scan is still a report: you get a coverage summary, a confidence statement, and a clear picture of what was and wasn't in scope — never just "we found nothing."
How is client data handled?
Data minimization by default: stored on self-hosted infrastructure, encrypted at rest, redacted where possible, and auto-purged 30 days after delivery — or sooner on request. Findings go only to the person you name.
Can international clients work with Cindrasec?
Yes — global engagements are billed in USD via Payoneer or Wise, delivered in English, and treated as an export of service.
Don't wait for the fire alarm.
Tell us what to look at — a free Snapshot is the fastest way to see what's actually exposed.
What this site collects, and what we do with it
Short version: nothing, unless you send the form. A security studio that quietly tracked its visitors would be worth exactly nothing to you.
Just visiting
No cookies, no analytics, no tracking pixels, no fingerprinting, and nothing written to browser storage. Fonts are served from this domain, so no font CDN sees your visit either. The exposure estimator scores entirely inside your browser — your answers are never transmitted, to us or to anyone. The only file cached on your device is the page itself, so it works offline.
If you send the contact form
We receive your name and email, plus the service you picked and — only if you fill them in — your domain and message. It reaches us through Web3Forms, a form-relay service, and lands as an email at contact@cindrasec.com. We use it to reply to you and nothing else. It is never sold, never added to a marketing list, and never shared with anyone outside Cindrasec.
If you become a client
Scan data is kept to the minimum the work needs: stored on self-hosted infrastructure, encrypted at rest, redacted where possible, and auto-purged 30 days after delivery — or sooner if you ask. Findings go only to the person you name in the Rules of Engagement. Scope, testing window and data handling are all written into that document before anything is scanned.
Who else touches your data
Two services, both named: Web3Forms delivers the contact form, and GitHub Pages hosts this site and therefore sees the usual web-server request logs. That is the complete list. This page makes exactly one cross-origin request in its entire lifetime, and only when you press Send.
Asking us to show or delete what we hold
Email contact@cindrasec.com and ask. We will tell you what we hold about you, correct it, or delete it — within 30 days, and usually the same week. You do not need to give a reason, and you can withdraw an authorization to test in writing at any moment, at which point testing stops immediately.
Last updated 31 July 2026. Questions about any of this go to contact@cindrasec.com.