For founders & CTOs

Security coverage before your first security hire.

You're shipping product, and somewhere between the seed round and the first enterprise deal a prospect sends a questionnaire asking whether you perform external vulnerability scanning. Bastion watches the outside of everything you run — certificates, headers, DNS, exposed services — and produces the dated report that answers that question honestly.

No card required to start. Plans from $25/month; first scan in about a minute.

The problems that land on a founder's desk

The questionnaire you can't skip

"Do you perform external vulnerability scanning?" appears on nearly every vendor review. Answering it with a paragraph an assessor has to take on faith is how deals stall in procurement.

Infrastructure nobody owns yet

Preview deployments, a contractor's microsite, the staging box from last quarter — small teams accumulate surface fast, and without a security hire nobody is tasked with watching it.

The outage that was a calendar problem

An expired certificate takes your product down as effectively as any attack, and renewal automation fails quietly. Someone has to notice before customers do.

No time for a security project

Anything that needs an agent rolled out, a scanner tuned, or a dashboard babysat loses to the roadmap. Security tooling for a startup has to run itself.

What Bastion does about them

Set up in minutes, not sprints

No agent to install, no code to change. Verify your domain with a DNS TXT record and the first scan finishes in about a minute — then re-runs on a schedule without you.

Attach the PDF, close the question

Every scan exports as a dated PDF with scope, findings and severities on the first page. When the questionnaire asks about external scanning, you attach last week's report instead of writing an essay.

Findings your coding agent can fix

Most external findings are small config changes that live in a repo. One click turns a scan into a paste-ready prompt for Claude Code, Codex or opencode — evidence, suggested fix and a verification step per finding. How the hand-off works →

Alerts only when something moves

Critical changes — a port that opened, a certificate about to lapse — are sent the moment they're found. Everything else lands in one weekly digest short enough to actually read.

Common questions

Do I need a security background to use Bastion?

No. Every finding says what was observed, why it matters, and the specific change that fixes it — written to be actionable by whoever runs your infrastructure, or by the coding agent you hand it to. Severity ordering tells you what to do first.

Will Bastion help with SOC 2?

Yes, for the controls it covers: SOC 2's Common Criteria expect you to monitor infrastructure for vulnerabilities and configuration change (CC7.1). A year of scheduled scans, alerts and resolved findings is that control operating. It complements a penetration test rather than replacing one — more on audit evidence.

How much does this cost a small team?

Plans start at $25/month with a 7-day free trial and no card required. That's the whole product — scheduled scans, change alerts, PDF reports — not a teaser tier. See pricing.

Find out what your startup exposes.

Add your domain and have your first report before your next meeting starts.

Start your 7-day trial

No card required to start. Cancel any time.