See exposure before the incident
Domains, credentials, OSINT, third parties and public signals feed into one executive risk view.
MASADA Security identifies digital exposure, breaches, suspicious links, vulnerabilities, third-party risk and compliance gaps in a clear, AI-guided experience.
No commitment. The free diagnostic uses limited, safe queries to assess your initial exposure.
AI Security Interface
Digital Exposure Diagnostic
AI generating your risk interface
Analyzing signals, modules and context to build the visualization.
Free plan
MASADA's Free plan was built to help you or your organization quickly understand whether there are signs of exposure, breaches, basic domain risks and early opportunities to improve security.
Coming soon
Free doesn't replace continuous monitoring. For personal protection, choose Personal. For alerts, reports, recurring scans and continuous management, choose Starter or Pro.
Why now
MASADA combines diagnostics, monitoring, AI, anti-fraud and compliance in a progressive journey: first see, then monitor, prioritize and respond.
Domains, credentials, OSINT, third parties and public signals feed into one executive risk view.
Dashboard AI turns technical findings into summaries, recommendations and clear next steps.
Starter monitors the basics, Pro organizes continuous management, and Enterprise connects governance and integrations.
Threat Panorama
Public cases, official reports and exploitation catalogs help turn headlines into actionable signals: exposure, credentials, third parties, fraud and exploited vulnerabilities.
HHS OCR
Mar 2024
HHS opened an investigation into the Change Healthcare attack after widespread disruption across the healthcare ecosystem. The case reinforces that ransomware is an operational, privacy and continuity risk.
Public impact
healthcare services disrupted
Monitored signal
MFA, remote access and response
AT&T / SEC
Jul 2024
AT&T's disclosure described improper download of call and text records from a third-party cloud platform. It's a strong example of SaaS, access and vendor-chain risk.
Public impact
nearly all mobile customers affected
Monitored signal
third parties, logs and credentials
FBI IC3
2024 Report
The IC3 annual report shows phishing/spoofing among the most reported crimes and record losses from digital scams. The executive takeaway needs to connect fraud, identity and monitoring.
Public impact
859,532 complaints in 2024
Monitored signal
phishing, BEC and extortion
CISA KEV
Updated
The Known Exploited Vulnerabilities catalog is a public reference for separating theoretical vulnerability from observed exploitation — exactly the kind of signal that cuts noise in the scanner.
Public impact
patching based on real risk
Monitored signal
exploited CVEs and deadlines
After the free diagnostic, activate the Pro trial to experience continuous monitoring, executive reports, alerts and advanced features for 7 days.
Active scans require domain verification to protect third parties and prevent abuse.
Core capabilities
Every module solves a real security problem — from free diagnostics to consultative enterprise operations.
AI
Security assistant with Claude and Gemini. Mandatory PII masking, LGPD consent, and real-time streaming.
AI
AI-generated daily assessment, automatic risk prioritization and one-click Autopilot mitigation — a fresh layout every morning.
Risk Management
Risk execution hub: turns signals and findings into trackable cases, with SLAs, automatic triage and an advisory AI copilot.
Intelligence
CISA KEV, EPSS and CERT.br integrated — actionable global and Brazilian threat intelligence with no API key required.
Intelligence
Look up IP, malware hash and suspicious URL reputation with geolocation, multi-source fallback and unified history.
Monitoring
Immediate alert when emails, IDs, or domains appear in global data breaches via HaveIBeenPwned API.
Anti-fraud
CPF/CNPJ background checks, federal sanctions lookup (CEIS/CNEP) and community risk scoring. Includes Phishing Analyzer: forward a suspicious email to isthisphishing@masadasecurity.net and get an AI verdict in seconds.
Cloud Security
Agentless Cloud Email Security & Drive CASB/DLP. Detects inbound phishing, outbound DLP violations and CASB anomalies using dual-LLM analysis (Claude + Gemini) with mandatory PII masking in real time.
Assets
Automatic discovery, ownership verification and centralized management of every digital asset in one inventory.
Diagnosis
Multi-engine recon across IPs, domains and hosts: exposed surface, CVEs, TLS/SSL, technology fingerprinting and DNS tools — a 360° view of the target.
Diagnosis
Active scanner with Nuclei v3.3 (8,000+ templates). Auto cross-reference with CISA KEV and EPSS. Mandatory target ownership verification.
Diagnosis
Detects exposed secrets and credentials in Git repository history before they become an incident.
Pentest
Pentest report management with R2 evidence upload, AI analysis, and automatic finding cross-reference.
Awareness
Custom phishing simulations, continuous awareness training and per-employee human risk metrics.
Identity
Maps access, scores identity risk and syncs your directory (Google Workspace/M365). SSO via OIDC and SAML 2.0, SCIM 2.0 provisioning and granular RBAC with 28 permissions.
Compliance
Structured checklist by category with R2 evidence upload. Automatic compliance score per category.
Automation
Automatic scheduling of scans and monitors via cron expressions. Unified execution history in real time.
Alerts
Real-time threat notifications via email, Slack, webhook and more — 7 configurable delivery channels.
Enterprise
Exports alerts to SIEM (Splunk, Sentinel, Datadog), creates tickets in ITSM (Jira, ServiceNow) and fetches credentials from PAM (CyberArk, HashiCorp Vault) via mTLS.
Pricing
Start free, move up to personal protection or continuous management, and scale to Enterprise when you need governance, integrations and premium support.
Initial diagnostic
Coming soon
To get to know MASADA and spot early risk signals.
+ 5 features in the comparison
Limited use. No active scans, integrations or executive reports.
Start for freeFor individuals
Coming soon
To check companies, suspicious links, breaches and fraud signals day to day.
+ 3 features in the comparison
Start on PersonalBasic monitoring
Coming soon
For companies that need to track essential risks without complexity.
+ 4 features in the comparison
Start on StarterContinuous management
Coming soon
For companies that need to monitor, prioritize and reduce digital risk continuously.
+ 9 features in the comparison
Try Pro for 7 daysGovernance and integrations
Contact us
For organizations that need governance, integrations, retention, premium support and advanced operations.
+ 8 features in the comparison
Comparison
The table makes it clear where Free ends and where Personal, Starter, Pro and Enterprise start making sense.
| Feature | Free | Personal | Starter | Pro | Enterprise |
|---|---|---|---|---|---|
| Users | 1 | 1 | up to 3 | up to 10 | custom |
| Domains | 1 | personal use | up to 2 | up to 10 | custom |
| Threat Lookup | 3/month | personal | limited | extended | custom |
| Breach Monitor | 3/month | personal emails | yes | extended | custom |
| Anti-fraud | 2/month | personal | basic | extended | custom |
| OSINT | 1 passive/month | no | basic | advanced | advanced |
| Vulnerability Scanner | no | no | limited/add-on | yes | high volume |
| Dashboard AI | monthly summary | personal | limited | yes | advanced |
| PDF reports | no | no | simple | executive | custom |
| External alerts | no | email/Slack/webhook | all | ||
| API/OAuth M2M | no | no | no | limited | yes |
| SSO/SCIM | no | no | no | no | yes |
| Workspace Sec | no | no | no | add-on | yes |
| Journal WORM | no | no | no | no | yes |
| Support | basic | priority | premium/SLA |
Responsible use
Queries and scans are governed by quotas, permissions and domain validation. Active features and sensitive integrations unlock based on plan and verification level.
No. Free is a limited initial diagnostic to understand exposure signals. Monitoring, alerts and recurring reports come with the Starter and Pro plans.
The Pro trial follows the checkout flow configured for the environment. Before finishing, you'll see the plan, billing cycle and applicable terms.
No. Active scans require domain verification to protect third parties and reduce the risk of abuse.
Contact us
Tell us what you need and MASADA forwards the context to cyber@masadasecurity.net with a structured briefing for diagnostics, Personal, Pro trial, Enterprise, AI or privacy.
Structured briefing
Official contact
Clear priority
The more context, the better the first response. For legal, privacy or DPO matters, the official channel is also cyber@masadasecurity.net.
Next step
Use the free diagnostic to spot initial risk signals and try MASADA Pro for 7 days to experience monitoring, prioritization and executive reports.