Security scanning that re-tests
the fixes it suggests.

TrustDyne scans firmware, mobile apps, desktop software, web apps, code and AWS accounts. When you patch a web finding, it runs the original test again against the live site before it calls the issue closed.

Request a free assessment

Get your security report

Enter your details and we'll scan your site for security gaps, then email you a PDF report, free.

We'll email you a confirmation link first. We will only send you the report.

Findings map to 27 frameworks, and reports cite the exact article or control. Some are laws. Others are standards or schemes you may choose to follow.

Laws and regulations

EU AI Act · EU Cyber Resilience Act · NIS2 · DORA · UK GDPR · UK PSTI Act · NIS Regulations 2018 · Telecommunications (Security) Act 2021 · Computer Misuse Act 1990 · PSD2 · HIPAA · EU MDR · UNECE R155 · FCA SYSC

Standards and schemes

ISO 27001 · ISO 42001 · NIST AI RMF · NIST SSDF · SOC 2 · PCI DSS · IEC 62443 · Cyber Essentials · OWASP ASVS · OWASP LLM Top 10 · MITRE CWE · NHS DTAC · FDA medical device cybersecurity

See TrustDyne in action

Scanning, exploit-aware prioritisation, device-to-cloud attack paths, re-tested fixes, local scanning, bring-your-own AI and compliance evidence, in under two minutes.

Checked against known vulnerable apps

We ran every scanner against published, deliberately vulnerable test projects and scored the results against each project's own public vulnerability list. No customer data was used. Pick a surface to see the real findings, the weakness class, the compliance mapping and the before and after fix. Each result has a View source link.

4 published vulnerable-by-design apps, 59 of 63 statically-detectable documented issues confirmed

InsecureBankv2

View source

23 of the documented vulnerabilities confirmed

criticalCWE-321CVSS 7.5

Hardcoded AES encryption key

The key used to "encrypt" stored credentials is a literal string compiled into the app, recoverable by anyone who decompiles it.

Fix: Remove the hardcoded key. Derive encryption keys at runtime from the Android Keystore; never ship one in source.

UK GDPR Art 32PCI DSS 3.6.1Cyber Essentials

Vulnerable

private static final String SECRET_KEY = "ThisIsASecretKey123";

Cipher cipher = Cipher.getInstance("AES");
cipher.init(Cipher.ENCRYPT_MODE, new SecretKeySpec(SECRET_KEY.getBytes(), "AES"));

Fixed

KeyGenerator kg = KeyGenerator.getInstance(KeyProperties.KEY_ALGORITHM_AES, "AndroidKeyStore");
kg.init(new KeyGenParameterSpec.Builder("app_key",
    KeyProperties.PURPOSE_ENCRYPT | KeyProperties.PURPOSE_DECRYPT)
    .setBlockModes(KeyProperties.BLOCK_MODE_GCM)
    .setEncryptionPaddings(KeyProperties.ENCRYPTION_PADDING_NONE)
    .build());
SecretKey key = kg.generateKey(); // never leaves the Keystore
criticalCWE-798CVSS 9.8

Backdoor credentials in source

A hardcoded username/password pair bypasses the normal login check entirely.

Fix: Delete the backdoor account and its check before release, and audit the build for other debug-only bypasses left in.

UK GDPR Art 32OWASP MASVS-AUTH

Vulnerable

if (username.equals("devadmin") && password.equals("superdebug123")) {
    grantFullAccess(); // debug bypass left in release build
}

Fixed

// Debug-only paths must never ship. Gate with a compile-time flag that is
// stripped from release builds, and delete the credential check entirely.
if (BuildConfig.DEBUG) {
    // debug tooling, excluded from release builds by Gradle
}
highCWE-276CVSS 5.5

World-readable shared preferences

Session data is written with MODE_WORLD_READABLE, so any other app on the device can read it.

Fix: Use MODE_PRIVATE for SharedPreferences, or EncryptedSharedPreferences for anything sensitive.

UK GDPR Art 32

Vulnerable

SharedPreferences prefs = getSharedPreferences("session", Context.MODE_WORLD_READABLE);
prefs.edit().putString("authToken", token).apply();

Fixed

MasterKey masterKey = new MasterKey.Builder(context).setKeyScheme(MasterKey.KeyScheme.AES256_GCM).build();
SharedPreferences prefs = EncryptedSharedPreferences.create(context, "session", masterKey,
    EncryptedSharedPreferences.PrefKeyEncryptionScheme.AES256_SIV,
    EncryptedSharedPreferences.PrefValueEncryptionScheme.AES256_GCM);

Scanning for code your AI tools write

AI coding assistants write a growing share of production code. TrustDyne scans it the same way it scans code your team wrote by hand.

Import findings from other tools

Import SARIF from GitHub Advanced Security, CodeQL, or Semgrep, or a Snyk export. Every ingested finding gets normalized, deduped, and mapped against the same 27 compliance frameworks as a native scan.

Hallucinated package check

AI coding assistants sometimes reference packages that do not exist. We check every dependency in your SBOM against the real PyPI, npm, and crates.io registries and flag the ones that could be squatted by an attacker.

Compliance mapping you can audit

Findings map to specific articles and controls from 79 obligations across 27 frameworks. The lookup uses CWE identifiers and keywords, with no AI involved, and reports can cite only the records they are given.

Pull request and CI gate

Drop the GitHub Action or GitLab pipeline step in and every build gets scanned automatically. A structured pass or fail verdict, tied to the commit and branch, blocks a regression before it merges.

Dated compliance history

TrustDyne records an append-only, timestamped entry every time a framework's status changes, so a buyer or auditor sees "ISO 42001: compliant since 12 June" instead of a single snapshot.

More than code scanning

Cloud accounts, live websites and customer security reviews need checking too. TrustDyne covers them from one account.

Cloud security

Connect your AWS accounts and TrustDyne continuously audits posture against CIS benchmarks and the same compliance frameworks as your code, so a misconfigured bucket and a vulnerable dependency show up in the same place.

Active testing, with consent

Active testing includes network vulnerability scanning (OpenVAS), web-app testing (ZAP, Nuclei) and check-only exploit validation (Metasploit, non-destructive). It runs against a public domain you own, or against a private network of PCs and servers through a small outbound-only relay, so you change nothing on your inbound firewall.

Attack path graph

Individually modest misconfigurations chain into a real compromise path. TrustDyne links your failing cloud checks into a directed attack-path graph, from public exposure to weak identity controls to blast radius, so you see how findings combine instead of a flat list.

Trust Center

A public page shows your live compliance posture and dated compliance history, so a customer's security review starts with a link you control instead of a questionnaire.

Results you can check yourself

You can check what TrustDyne tells you. It re-tests web fixes, signs its reports, and can keep your source code on your own machine.

Re-tested fixes

For web findings, TrustDyne sends the original proof-of-concept request again to your patched site. The finding closes only when that request stops working.

Local mode

Local mode runs a model on your own hardware, offline, so source code stays in your environment.

One credential, several places

When the same credential turns up in more than one asset, for example a firmware image and several mobile builds, it is reported once as a linked finding.

Signed reports

Enterprise buyers and insurers can verify that a report is the one TrustDyne issued. Every audit report is signed with an asymmetric AWS KMS key over its hash, so any change after signing shows up.

Firmware, mobile and desktop builds

If your product includes a companion mobile app, a Windows or macOS desktop client or an embedded device, upload the build and get the same report: component list, known CVEs, fix guidance and framework mapping.

Files deleted after analysis

Uploaded builds are deleted from storage when analysis finishes. Reports stay in your account.

Built for binaries

TrustDyne extracts the component list from firmware images, reads Android manifests and flags hardcoded credentials and weak hardening (NX, PIE).

Mapped to the rules

CVEs are mapped to specific articles and controls in frameworks such as EU CRA and UK PSTI Act, with remediation guidance.

Check a repository before you pull it

Paste a public GitHub URL and TrustDyne runs the same SAST, secrets, and dependency-CVE pipeline your own code gets, before a third-party or open-source dependency ever touches your machine. You need no installation, no fork and no help from the repo owner.

Any public repository

Paste a URL and pick a branch. It works on any repo you can see on github.com, whether or not you or its owner ever installed a TrustDyne integration.

We never run the code

Extraction and static analysis only. Install scripts, build steps, and the repo's own code never run, so a malicious target can't compromise the scan that's checking it.

Same report as your own code

Full SBOM, prioritised CVEs, AI-generated remediation, and compliance mapping, exportable as a PDF. Every scanned repo is saved as its own asset with full history.

Use our AI, or bring your own, for every engine

Each AI feature is configured on its own. Every fix is also checked by a pattern test, a syntax check and a generated regression test, and every report citation is checked against what was retrieved, whichever model produced it.

11 AI features, set one by one

Your own Bedrock account, Azure OpenAI, or a self-hosted vLLM/Ollama deployment can sit behind remediation, reports, chat, or any other engine, set independently per engine, self-served from Account Settings rather than a support ticket.

Use a model you have already approved

If your organization has already approved a specific AI deployment, your code and data can go there instead of to us. That adds no new AI vendor to a security review, for any engine you move.

No silent fallback

If your configured model is unreachable, the feature reports an error. It does not switch to our model.

Start free. Upgrade when you're ready.

Every plan is public, right here on this page. No sales call required to see a number.

Free

£0

See what TrustDyne finds, at no cost

  • ✓5 scans/month across firmware, mobile, desktop, web or code
  • ✓Full SBOM generation, incl. hallucinated-package detection
  • ✓Compliance pass/fail status, 2 frameworks
  • ✓Executive summary: cloud security score & cost savings estimate

Starter

£99/mo

£990/yr, two months free. For your first security review

  • ✓Full findings detail with remediation guidance
  • ✓1 product line, weekly automated scans
  • ✓Full Cloud Security (1 account) & Cost Optimizer reports
  • ✓Hosted VDP page with AI-powered triage
  • ✓Up to 3 compliance frameworks

Growth · most chosen

£299/mo

£2,990/yr, two months free. The full platform

  • ✓All asset types, continuous scanning, unlimited frameworks
  • ✓AI remediation with a written fix for each finding
  • ✓Up to 3 cloud accounts + AI risk analysis, full Cost Optimizer AI
  • ✓Full Trust Center: evidence library, questionnaire automation
  • ✓VDP with full AI triage & escalation

Enterprise

Custom

For regulated and multi-entity businesses

  • ✓Everything in Growth, unlimited scale
  • ✓Multi-account AWS portfolio, per-tenant encryption
  • ✓Bring your own AI model for any of 11 engines, or run a local model offline on your own hardware
  • ✓Custom compliance framework authoring
  • ✓Dedicated customer success manager and onboarding

One-off expert-led security assessment

£1,200 one-off

About 1.5 days of hands-on testing by a TrustDyne security engineer on one website or web app, with the paperwork your buyer asks for.

  • ✓Expert-written report with step-by-step fixes
  • ✓Signed attestation letter for your customers
  • ✓One security questionnaire completed (up to 50 questions)
  • ✓60-minute readout and 30 days of fix support
  • ✓Free re-test within 30 days

Hands-on work a subscription doesn't include

✓

Key journeys tested by hand

Up to 5: login, password reset, role changes, payments, uploads, admin actions

✓

Access control with real accounts

Two accounts per role for up to 2 roles, plus up to 20 API endpoints

✓

Login and session review

MFA, brute-force lockout, session expiry, logout and reset links

✓

Findings confirmed by a person

False positives removed, every issue ranked by business risk

Plus our full automated scan, run for you: 13,000+ vulnerability checks, injection and XSS testing, exposed secrets and files, open Supabase/Firebase databases, TLS, headers, email spoofing and phishing lookalikes.

Starts only after you verify you own the site and sign a consent record (Computer Misuse Act 1990). An expert-led assessment, not a CREST-accredited penetration test.

A subscription gives you the tools. The assessment gives you a person's time and the paperwork a buyer asks for.

Automated vulnerability scanning
Plan: Included, you run it
Assessment: Run for you at full depth, authenticated
False positives removed
Plan: No
Assessment: Every critical and high finding confirmed by hand
Business-logic testing of key journeys
Plan: No
Assessment: Up to 5 journeys, by hand
Access control with real accounts
Plan: Automated heuristic
Assessment: Two accounts per role, by hand
Customer security questionnaire
Plan: AI drafts on Growth, you complete
Assessment: Completed for you (up to 50 questions)
Attestation letter for buyers
Plan: No
Assessment: Yes, signed
Expert readout and fix support
Plan: No
Assessment: 60-minute call plus 30 days of email support

Prefer to talk it through first? Email hello@trustdyne.com →

Questions before your first scan

The short version of what TrustDyne is and what you get. Full detail is in the .

Firmware images, Android and iOS apps, Windows and macOS binaries, web applications, code repositories and AWS accounts. Cloud coverage is AWS only. Azure and Google Cloud are not supported yet.

For web findings, TrustDyne keeps the original proof-of-concept request and runs it again against your patched site. The result is either closed (the request no longer works) or still open. It is a re-run of the same test. It does not prove that no other route to the same flaw exists.

Yes, in local mode. A model runs on your hardware, scans the code there, and nothing is sent to TrustDyne. The cloud scanners need you to upload a build, and uploaded files are deleted from storage when analysis finishes. Enterprise accounts can also point each AI feature at their own Bedrock, Azure OpenAI or self-hosted endpoint.

Each finding is matched to records in a corpus of 79 obligations across 27 frameworks, using CWE identifiers and keywords. No AI is involved in the lookup. When a report is written, the AI is handed only the matched records and may cite only those.

A report with a software bill of materials, prioritised vulnerabilities, suggested fixes and compliance mapping. Reports are signed with an AWS KMS key, so a customer or insurer can check that a report has not changed since TrustDyne issued it.

The Free plan is £0 with 5 scans a month. Starter is £99 a month and Growth is £299 a month. Enterprise is priced per agreement. A one-off Expert-Led Security Assessment, where a person tests your web app and signs off a report for your customer, is £1,200.