TrustDyne scans firmware, mobile apps, desktop software, web apps, code and AWS accounts. When you patch a web finding, it runs the original test again against the live site before it calls the issue closed.
Enter your details and we'll scan your site for security gaps, then email you a PDF report, free.
Findings map to 27 frameworks, and reports cite the exact article or control. Some are laws. Others are standards or schemes you may choose to follow.
Laws and regulations
EU AI Act · EU Cyber Resilience Act · NIS2 · DORA · UK GDPR · UK PSTI Act · NIS Regulations 2018 · Telecommunications (Security) Act 2021 · Computer Misuse Act 1990 · PSD2 · HIPAA · EU MDR · UNECE R155 · FCA SYSC
Standards and schemes
ISO 27001 · ISO 42001 · NIST AI RMF · NIST SSDF · SOC 2 · PCI DSS · IEC 62443 · Cyber Essentials · OWASP ASVS · OWASP LLM Top 10 · MITRE CWE · NHS DTAC · FDA medical device cybersecurity
Scanning, exploit-aware prioritisation, device-to-cloud attack paths, re-tested fixes, local scanning, bring-your-own AI and compliance evidence, in under two minutes.
We ran every scanner against published, deliberately vulnerable test projects and scored the results against each project's own public vulnerability list. No customer data was used. Pick a surface to see the real findings, the weakness class, the compliance mapping and the before and after fix. Each result has a View source link.
23 of the documented vulnerabilities confirmed
Hardcoded AES encryption key
The key used to "encrypt" stored credentials is a literal string compiled into the app, recoverable by anyone who decompiles it.
Fix: Remove the hardcoded key. Derive encryption keys at runtime from the Android Keystore; never ship one in source.
Vulnerable
private static final String SECRET_KEY = "ThisIsASecretKey123";
Cipher cipher = Cipher.getInstance("AES");
cipher.init(Cipher.ENCRYPT_MODE, new SecretKeySpec(SECRET_KEY.getBytes(), "AES"));Fixed
KeyGenerator kg = KeyGenerator.getInstance(KeyProperties.KEY_ALGORITHM_AES, "AndroidKeyStore");
kg.init(new KeyGenParameterSpec.Builder("app_key",
KeyProperties.PURPOSE_ENCRYPT | KeyProperties.PURPOSE_DECRYPT)
.setBlockModes(KeyProperties.BLOCK_MODE_GCM)
.setEncryptionPaddings(KeyProperties.ENCRYPTION_PADDING_NONE)
.build());
SecretKey key = kg.generateKey(); // never leaves the KeystoreBackdoor credentials in source
A hardcoded username/password pair bypasses the normal login check entirely.
Fix: Delete the backdoor account and its check before release, and audit the build for other debug-only bypasses left in.
Vulnerable
if (username.equals("devadmin") && password.equals("superdebug123")) {
grantFullAccess(); // debug bypass left in release build
}Fixed
// Debug-only paths must never ship. Gate with a compile-time flag that is
// stripped from release builds, and delete the credential check entirely.
if (BuildConfig.DEBUG) {
// debug tooling, excluded from release builds by Gradle
}World-readable shared preferences
Session data is written with MODE_WORLD_READABLE, so any other app on the device can read it.
Fix: Use MODE_PRIVATE for SharedPreferences, or EncryptedSharedPreferences for anything sensitive.
Vulnerable
SharedPreferences prefs = getSharedPreferences("session", Context.MODE_WORLD_READABLE);
prefs.edit().putString("authToken", token).apply();Fixed
MasterKey masterKey = new MasterKey.Builder(context).setKeyScheme(MasterKey.KeyScheme.AES256_GCM).build();
SharedPreferences prefs = EncryptedSharedPreferences.create(context, "session", masterKey,
EncryptedSharedPreferences.PrefKeyEncryptionScheme.AES256_SIV,
EncryptedSharedPreferences.PrefValueEncryptionScheme.AES256_GCM);AI coding assistants write a growing share of production code. TrustDyne scans it the same way it scans code your team wrote by hand.
Import SARIF from GitHub Advanced Security, CodeQL, or Semgrep, or a Snyk export. Every ingested finding gets normalized, deduped, and mapped against the same 27 compliance frameworks as a native scan.
AI coding assistants sometimes reference packages that do not exist. We check every dependency in your SBOM against the real PyPI, npm, and crates.io registries and flag the ones that could be squatted by an attacker.
Findings map to specific articles and controls from 79 obligations across 27 frameworks. The lookup uses CWE identifiers and keywords, with no AI involved, and reports can cite only the records they are given.
Drop the GitHub Action or GitLab pipeline step in and every build gets scanned automatically. A structured pass or fail verdict, tied to the commit and branch, blocks a regression before it merges.
TrustDyne records an append-only, timestamped entry every time a framework's status changes, so a buyer or auditor sees "ISO 42001: compliant since 12 June" instead of a single snapshot.
Cloud accounts, live websites and customer security reviews need checking too. TrustDyne covers them from one account.
Connect your AWS accounts and TrustDyne continuously audits posture against CIS benchmarks and the same compliance frameworks as your code, so a misconfigured bucket and a vulnerable dependency show up in the same place.
Active testing includes network vulnerability scanning (OpenVAS), web-app testing (ZAP, Nuclei) and check-only exploit validation (Metasploit, non-destructive). It runs against a public domain you own, or against a private network of PCs and servers through a small outbound-only relay, so you change nothing on your inbound firewall.
Individually modest misconfigurations chain into a real compromise path. TrustDyne links your failing cloud checks into a directed attack-path graph, from public exposure to weak identity controls to blast radius, so you see how findings combine instead of a flat list.
A public page shows your live compliance posture and dated compliance history, so a customer's security review starts with a link you control instead of a questionnaire.
You can check what TrustDyne tells you. It re-tests web fixes, signs its reports, and can keep your source code on your own machine.
For web findings, TrustDyne sends the original proof-of-concept request again to your patched site. The finding closes only when that request stops working.
Local mode runs a model on your own hardware, offline, so source code stays in your environment.
When the same credential turns up in more than one asset, for example a firmware image and several mobile builds, it is reported once as a linked finding.
Enterprise buyers and insurers can verify that a report is the one TrustDyne issued. Every audit report is signed with an asymmetric AWS KMS key over its hash, so any change after signing shows up.
If your product includes a companion mobile app, a Windows or macOS desktop client or an embedded device, upload the build and get the same report: component list, known CVEs, fix guidance and framework mapping.
Uploaded builds are deleted from storage when analysis finishes. Reports stay in your account.
TrustDyne extracts the component list from firmware images, reads Android manifests and flags hardcoded credentials and weak hardening (NX, PIE).
CVEs are mapped to specific articles and controls in frameworks such as EU CRA and UK PSTI Act, with remediation guidance.
Paste a public GitHub URL and TrustDyne runs the same SAST, secrets, and dependency-CVE pipeline your own code gets, before a third-party or open-source dependency ever touches your machine. You need no installation, no fork and no help from the repo owner.
Paste a URL and pick a branch. It works on any repo you can see on github.com, whether or not you or its owner ever installed a TrustDyne integration.
Extraction and static analysis only. Install scripts, build steps, and the repo's own code never run, so a malicious target can't compromise the scan that's checking it.
Full SBOM, prioritised CVEs, AI-generated remediation, and compliance mapping, exportable as a PDF. Every scanned repo is saved as its own asset with full history.
Each AI feature is configured on its own. Every fix is also checked by a pattern test, a syntax check and a generated regression test, and every report citation is checked against what was retrieved, whichever model produced it.
Your own Bedrock account, Azure OpenAI, or a self-hosted vLLM/Ollama deployment can sit behind remediation, reports, chat, or any other engine, set independently per engine, self-served from Account Settings rather than a support ticket.
If your organization has already approved a specific AI deployment, your code and data can go there instead of to us. That adds no new AI vendor to a security review, for any engine you move.
If your configured model is unreachable, the feature reports an error. It does not switch to our model.
Every plan is public, right here on this page. No sales call required to see a number.
Free
£0
See what TrustDyne finds, at no cost
Starter
£99/mo
£990/yr, two months free. For your first security review
Growth · most chosen
£299/mo
£2,990/yr, two months free. The full platform
Enterprise
Custom
For regulated and multi-entity businesses
One-off expert-led security assessment
£1,200 one-off
About 1.5 days of hands-on testing by a TrustDyne security engineer on one website or web app, with the paperwork your buyer asks for.
Hands-on work a subscription doesn't include
Key journeys tested by hand
Up to 5: login, password reset, role changes, payments, uploads, admin actions
Access control with real accounts
Two accounts per role for up to 2 roles, plus up to 20 API endpoints
Login and session review
MFA, brute-force lockout, session expiry, logout and reset links
Findings confirmed by a person
False positives removed, every issue ranked by business risk
Plus our full automated scan, run for you: 13,000+ vulnerability checks, injection and XSS testing, exposed secrets and files, open Supabase/Firebase databases, TLS, headers, email spoofing and phishing lookalikes.
Starts only after you verify you own the site and sign a consent record (Computer Misuse Act 1990). An expert-led assessment, not a CREST-accredited penetration test.
A subscription gives you the tools. The assessment gives you a person's time and the paperwork a buyer asks for.
Prefer to talk it through first? Email hello@trustdyne.com →
The short version of what TrustDyne is and what you get. Full detail is in the .
Firmware images, Android and iOS apps, Windows and macOS binaries, web applications, code repositories and AWS accounts. Cloud coverage is AWS only. Azure and Google Cloud are not supported yet.
For web findings, TrustDyne keeps the original proof-of-concept request and runs it again against your patched site. The result is either closed (the request no longer works) or still open. It is a re-run of the same test. It does not prove that no other route to the same flaw exists.
Yes, in local mode. A model runs on your hardware, scans the code there, and nothing is sent to TrustDyne. The cloud scanners need you to upload a build, and uploaded files are deleted from storage when analysis finishes. Enterprise accounts can also point each AI feature at their own Bedrock, Azure OpenAI or self-hosted endpoint.
Each finding is matched to records in a corpus of 79 obligations across 27 frameworks, using CWE identifiers and keywords. No AI is involved in the lookup. When a report is written, the AI is handed only the matched records and may cite only those.
A report with a software bill of materials, prioritised vulnerabilities, suggested fixes and compliance mapping. Reports are signed with an AWS KMS key, so a customer or insurer can check that a report has not changed since TrustDyne issued it.
The Free plan is £0 with 5 scans a month. Starter is £99 a month and Growth is £299 a month. Enterprise is priced per agreement. A one-off Expert-Led Security Assessment, where a person tests your web app and signs off a report for your customer, is £1,200.