Ask Secure Assess a question. Answers come from this site's docs only. I will cite a page. I will not invent a product claim.
We scan and advise. We never attack.
Defensive PCI 11.3 scans. Not an official ASV attestation. Not a pentest.
Secure Assess is multi-tenant SaaS for PCI 11.3 readiness and vulnerability assessment. Scheduled scans, AI-triaged findings, PCI mapping, and a PDF report. ASV-readiness is a PASS or FAIL check — not an official attestation.
Sign up in the app and get set up there. That is the whole path. We scan systems you authorize. We report and advise. We never attack.

Scan the scope you authorize. Leave it as you found it.
Six things the product does. Each one is a report or a schedule — never a change made on your network.
Defensive external assessment
Scan the internet-facing surface you authorize. We identify what is exposed and what it means. We do not attack it.
Credentialed assessment
When you provide credentials, we assess from the inside of the systems you named. Still defensive. Still advice, not a change to the host.
PCI mapping
Findings are mapped to PCI DSS 11.3 vulnerability assessment. That is the requirement we cover. We do not perform PCI 11.4 penetration testing.
Scheduled scans
Run on a schedule you set. Same scope, same report shape, so a quarter-to-quarter picture is comparable.
AI-triaged findings
The model ranks and explains findings so you know what to look at first. A human still decides. We do not apply fixes.
PDF reports
A written report you can hand to an assessor, a merchant, or an internal owner. Findings, advice, and the readiness result.
Sign up in the app. That is the whole path.
Add a target you own, verify ownership, create a scope, run a defensive scan, review findings. This site does not take payment.

What a finding looks like
Ranked, mapped, and written so an owner can act — without us acting for them.
# report excerpt — advice, not a change
finding TLS 1.0 accepted on :443
scope external · 203.0.113.10
pci 11.3.1 vulnerability identified
triage high · expired protocol on a card-data path
advice Disable TLS 1.0; require TLS 1.2+.
readiness FAIL # not an official ASV attestationThe report names the finding, the PCI 11.3 mapping, and the advice. Applying the change is yours. What the product does →
What this is not
A readiness product that over-claims becomes a liability. These limits are part of the product, not fine print.
ASV-readiness is PASS or FAIL
A readiness check against the shape of an ASV scan. It is not an official ASV attestation and it is not a certificate you can present as one.
We never attack
No exploitation, no payloads, no offensive exercise. If a finding implies a path, we describe it as a finding — not as something we ran.
We report and advise
The product does not patch, remediates nothing on your behalf, and does not change the environment it scanned.
Start in the app.
Free, Starter at $99/month, Professional at $399/month, Enterprise custom. Sign up in the app. This site does not take payment. Enterprise talks to sales.
Free
PCI readiness and vulnerability assessment. Scan systems you authorize. Advice only.
- 1 active scope
- 16 hosts per scope
- 2 scans per month
- Cadences: adhoc, monthly
- No AI triage
- No PDF reports
- No API access
- 1 seat, community support
Starter
Adds weekly cadence, AI triage, PDF reports, and API access.
- 3 active scopes
- 64 hosts per scope
- 20 scans per month
- Cadences: adhoc, weekly, monthly
- AI triage
- PDF reports
- API access
- 3 seats, email support
Professional
Daily cadence, more scopes and seats. Same defensive VA, not a pentest.
- 15 active scopes
- 256 hosts per scope
- 200 scans per month
- Cadences: daily, weekly, monthly, adhoc
- AI triage
- PDF reports
- API access
- 15 seats, priority support
Enterprise
Custom pricing. Contact sales.
- 1000 active scopes
- 65536 hosts per scope
- 100000 scans per month
- Cadences: daily, weekly, monthly, adhoc
- AI triage
- PDF reports
- API access
- 1000 seats, dedicated support
Start a scan on systems you authorize
We scan and advise. We never attack.