MASADASecurity Systems/məˈsɑː.də/
AI-powered Cyber Risk Management for companies and individuals

Cyber risk, anti-fraud and digital exposure in one intelligent platform

MASADA Security identifies digital exposure, breaches, suspicious links, vulnerabilities, third-party risk and compliance gaps in a clear, AI-guided experience.

Nothing is charged during the first 7 days. Cancel anytime, right in the platform.

AI Security Interface

Digital Exposure Diagnostic

AI Intelligence

AI generating your risk interface

Analyzing signals, modules and context to build the visualization.

7 days free

Start with 7 days free on the full plan

Pick Starter or Pro and use the full platform for 7 days: exposure signals, breaches, domain risks and AI-prioritized fixes — before the first charge.

7-day trial

Digital Exposure Diagnostic in your trial

Every feature of the chosen plan
No charge during the first 7 days
Pay by PIX or credit card
Cancel anytime from the platform
Free trial on your first signup only

After 7 days the subscription continues on the chosen plan. Without payment, module access is suspended — your data stays stored.

Why now

Cyber Risk Management for faster, safer decisions

MASADA combines diagnostics, monitoring, AI, anti-fraud and compliance in a progressive journey: first see, then monitor, prioritize and respond.

See exposure before the incident

Domains, credentials, OSINT, third parties and public signals feed into one executive risk view.

Prioritize with AI and context

Dashboard AI turns technical findings into summaries, recommendations and clear next steps.

Evolve into continuous operation

Starter monitors the basics, Pro organizes continuous management, and Enterprise connects governance and integrations.

Threat Panorama

Real news shows where risk starts

Public cases, official reports and exploitation catalogs help turn headlines into actionable signals: exposure, credentials, third parties, fraud and exploited vulnerabilities.

12 real sourcesOriginal summaryAI-mapped signals
Ransomware

HHS OCR

Mar 2024

Change Healthcare showed how ransomware becomes an operational crisis

HHS opened an investigation into the Change Healthcare attack after widespread disruption across the healthcare ecosystem. The case reinforces that ransomware is an operational, privacy and continuity risk.

Public impact

healthcare services disrupted

Monitored signal

MFA, remote access and response

Network ScannerSource: HHS OCR
Assess ransomware readiness
Cloud breach

AT&T / SEC

Jul 2024

AT&T exposed call metadata in a third-party cloud environment

AT&T's disclosure described improper download of call and text records from a third-party cloud platform. It's a strong example of SaaS, access and vendor-chain risk.

Public impact

nearly all mobile customers affected

Monitored signal

third parties, logs and credentials

Breach MonitorSource: AT&T / SEC
Map exposure and third parties
Fraud and phishing

FBI IC3

2024 Report

FBI IC3 recorded $16.6B in reported losses

The IC3 annual report shows phishing/spoofing among the most reported crimes and record losses from digital scams. The executive takeaway needs to connect fraud, identity and monitoring.

Public impact

859,532 complaints in 2024

Monitored signal

phishing, BEC and extortion

Anti-fraud BRSource: FBI IC3
Learn about Anti-fraud
Active exploitation

CISA KEV

Updated

CISA KEV keeps prioritizing CVEs exploited in the field

The Known Exploited Vulnerabilities catalog is a public reference for separating theoretical vulnerability from observed exploitation — exactly the kind of signal that cuts noise in the scanner.

Public impact

patching based on real risk

Monitored signal

exploited CVEs and deadlines

Vulnerability ScannerSource: CISA KEV
Learn about the scanner
7 days free

Try MASADA Pro free for 7 days

Start the trial and use the full Pro plan for 7 days: continuous monitoring, executive reports, alerts and advanced features. The first charge is only due on day 8.

Every Pro feature and limit
Daily AI assessment on the Dashboard
Workspace Sec and Code Security
Email and webhook/Slack alerts
No charge during the first 7 days
Cancel anytime, right in the platform

Active scans require domain verification to protect third parties and prevent abuse.

Core capabilities

19 integrated modules. One platform.

Every module solves a real security problem — from continuous monitoring to consultative enterprise operations.

AI

Masada AI

Security assistant with Claude and Gemini. Mandatory PII masking, LGPD consent, and real-time streaming.

AI

Dashboard

AI-generated daily assessment, automatic risk prioritization and one-click Autopilot mitigation — a fresh layout every morning.

Risk Management

Risk Operations

Risk execution hub: turns signals and findings into trackable cases, with SLAs, automatic triage and an advisory AI copilot.

Intelligence

Threat Intelligence

CISA KEV, EPSS and CERT.br integrated — actionable global and Brazilian threat intelligence with no API key required.

Intelligence

Threat Lookup

Look up IP, malware hash and suspicious URL reputation with geolocation, multi-source fallback and unified history.

Monitoring

Breach Monitor

Immediate alert when emails, IDs, or domains appear in global data breaches via HaveIBeenPwned API.

Anti-fraud

Anti-fraud BR

CPF/CNPJ background checks, federal sanctions lookup (CEIS/CNEP) and community risk scoring. Includes Phishing Analyzer: forward a suspicious email to isthisphishing@masadasecurity.net and get an AI verdict in seconds.

Cloud Security

Workspace Sec

Agentless Cloud Email Security & Drive CASB/DLP. Detects inbound phishing, outbound DLP violations and CASB anomalies using dual-LLM analysis (Claude + Gemini) with mandatory PII masking in real time.

Assets

Asset Inventory

Automatic discovery, ownership verification and centralized management of every digital asset in one inventory.

Diagnosis

Network Scanner

Multi-engine recon across IPs, domains and hosts: exposed surface, CVEs, TLS/SSL, technology fingerprinting and DNS tools — a 360° view of the target.

Diagnosis

Vulnerability Scanner

Active scanner with Nuclei v3.3 (8,000+ templates). Auto cross-reference with CISA KEV and EPSS. Mandatory target ownership verification.

Diagnosis

Code Security

Detects exposed secrets and credentials in Git repository history before they become an incident.

Pentest

Pentest Control

Pentest report management with R2 evidence upload, AI analysis, and automatic finding cross-reference.

Awareness

Phishing Training

Custom phishing simulations, continuous awareness training and per-employee human risk metrics.

Identity

IAM

Maps access, scores identity risk and syncs your directory (Google Workspace/M365). SSO via OIDC and SAML 2.0, SCIM 2.0 provisioning and granular RBAC with 28 permissions.

Compliance

LGPD Compliance

Structured checklist by category with R2 evidence upload. Automatic compliance score per category.

Automation

Automations

Automatic scheduling of scans and monitors via cron expressions. Unified execution history in real time.

Alerts

Alerts Center

Real-time threat notifications via email, Slack, webhook and more — 7 configurable delivery channels.

Enterprise

Enterprise Integrations

Exports alerts to SIEM (Splunk, Sentinel, Datadog), creates tickets in ITSM (Jira, ServiceNow) and fetches credentials from PAM (CyberArk, HashiCorp Vault) via mTLS.

Pricing

Choose the best starting point

Start with 7 days free, move up to continuous monitoring or advanced management, and scale to Enterprise when you need governance, integrations and premium support.

Basic monitoring

Starter

R$ 297/mo

For companies that need to track essential risks without complexity.

  • Up to 3 users
  • 2 verified domains
  • Vulnerability Scanner: 15 scans/month
  • Breach Monitor and Threat Lookup: 50 queries/month each
  • Full LGPD module with evidence

+ 4 features in the comparison

Annual plan: R$ 2,970/year (2 months free).

Try Starter for 7 days
Most popular

Growing operation

Business

R$ 697/mo

For SMBs with an IT team that need daily AI, more volume and API integration.

  • Up to 10 users
  • 8 verified domains
  • Everything in Starter, with up to 6x higher limits
  • Daily AI assessment on the Dashboard
  • Deep vulnerability scans: 60/month

+ 4 features in the comparison

Annual plan: R$ 6,970/year (2 months free).

Try Business for 7 days

Continuous management

Pro

R$ 1,297/mo

For companies that need to monitor, prioritize and reduce digital risk continuously.

  • Up to 25 users
  • 20 verified domains
  • Everything in Business, with higher limits
  • Workspace Sec: email protection and DLP
  • Code Security: 10 repositories

+ 7 features in the comparison

Annual plan: R$ 12,970/year (2 months free).

Try Pro for 7 days

Governance and integrations

Enterprise

Contact us

For organizations that need governance, integrations, retention, premium support and advanced operations.

  • Unlimited users and domains
  • Everything in Pro, with tailored limits
  • SCIM and granular RBAC
  • Forensic Journal (WORM)
  • Masada AI: 30,000 credits/week

+ 3 features in the comparison

The comparison below covers limits, modules and advanced features without cluttering the pricing cards.

Comparison

Compare features by maturity stage

The table shows where Starter, Pro and Enterprise start making sense.

FeatureStarterBusinessProEnterprise
Users31025unlimited
Verified domains2820unlimited
Inventory assets1060150unlimited
Vulnerability Scanner15 scans/month60 scans/month150 scans/monthunlimited
Scan profilesquick and standard+ deep+ customall
Network Scanner / OSINT50 queries/month250 queries/month600 queries/monthunlimited
On-demand scans and continuous IP monitoringnonoyesyes
Breach Monitor50 queries/month · 1 target300 queries/month · 8 targets1,000 queries/month · 20 targetsunlimited
Threat Lookup50 queries/month250 queries/month500 queries/month5,000 queries/month
Anti-fraud (CNPJ and sanctions)25 queries/month150 queries/month300 queries/monthunlimited
LGPDfull · 1 GB of evidencefull · 5 GBfull · 10 GBunlimited
Phishing Training1 campaign/month · 15 targets3 campaigns/month · 100 targets5 campaigns/month · 250 targetsunlimited
Pentest Control2 AI analyses/month · 1 GB15 AI analyses/month · 5 GB50 AI analyses/month · 10 GB500 analyses/month · 20 GB
Risk Operations100 open cases500 open cases2,000 open casesunlimited
Automations1 active5 active15 activeunlimited
Masada AI800 credits/week3,000 credits/week7,500 credits/week30,000 credits/week
Daily AI assessment on the Dashboardnoyesyesyes
Phishing Analyzerno200 emails/month500 emails/monthunlimited
REST API (OAuth 2.0 M2M)noyesyesyes
Workspace Sec (email and DLP)nono1 domain · 2,000 emails/monthunlimited
Code Securitynono10 repositories · 30 scans/month50 repositories
IAM and SSOnono100 identities · 1 SSO providerunlimited
SIEM/PAM/ITSM integrationsnonoyesyes
SCIM and forensic Journal (WORM)nononoyes
Alerts (email, Slack, Teams, Telegram, webhook)yesyesyesyes
Alert history60 days6 months1 yearunlimited
Supportemailemailprioritypremium with SLA

Responsible use

Security in how the platform is used, too

Queries and scans are governed by quotas, permissions and domain validation. Active features and sensitive integrations unlock based on plan and verification level.

Passive OSINT that never touches your systems
Active scans require a verified domain
Quotas to prevent abuse
Sensitive actions require permissions
Enterprise features go through commercial validation

Frequently asked questions

Does the 7-day trial charge anything?

No. The first charge is only due after 7 days; you pay by PIX or card on the first invoice and can cancel before that from the platform. The free trial applies to your first signup only (one per CPF/CNPJ and email); on a new subscription, access is released once payment is confirmed.

Does the Pro trial charge automatically here?

The Pro trial follows the checkout flow configured for the environment. Before finishing, you'll see the plan, billing cycle and applicable terms.

Can active scans be run against any domain?

No. Active scans require domain verification to protect third parties and reduce the risk of abuse.

Contact us

A smart form to get you to the right answer faster

Tell us what you need and MASADA forwards the context to cyber@masadasecurity.net with a structured briefing for diagnostics, Starter, Pro trial, Enterprise, AI or privacy.

Structured briefing

Official contact

Clear priority

Briefing quality0/6

The more context, the better the first response. For legal, privacy or DPO matters, the official channel is also cyber@masadasecurity.net.

Next step

Start by seeing your exposure. Then evolve into continuous management.

Try MASADA for 7 days to spot risk signals and experience monitoring, prioritization and executive reports — no charge before day 8.