See exposure before the incident
Domains, credentials, OSINT, third parties and public signals feed into one executive risk view.
MASADA Security identifies digital exposure, breaches, suspicious links, vulnerabilities, third-party risk and compliance gaps in a clear, AI-guided experience.
Nothing is charged during the first 7 days. Cancel anytime, right in the platform.
AI Security Interface
Digital Exposure Diagnostic
AI generating your risk interface
Analyzing signals, modules and context to build the visualization.
7 days free
Pick Starter or Pro and use the full platform for 7 days: exposure signals, breaches, domain risks and AI-prioritized fixes — before the first charge.
7-day trial
After 7 days the subscription continues on the chosen plan. Without payment, module access is suspended — your data stays stored.
Why now
MASADA combines diagnostics, monitoring, AI, anti-fraud and compliance in a progressive journey: first see, then monitor, prioritize and respond.
Domains, credentials, OSINT, third parties and public signals feed into one executive risk view.
Dashboard AI turns technical findings into summaries, recommendations and clear next steps.
Starter monitors the basics, Pro organizes continuous management, and Enterprise connects governance and integrations.
Threat Panorama
Public cases, official reports and exploitation catalogs help turn headlines into actionable signals: exposure, credentials, third parties, fraud and exploited vulnerabilities.
HHS OCR
Mar 2024
HHS opened an investigation into the Change Healthcare attack after widespread disruption across the healthcare ecosystem. The case reinforces that ransomware is an operational, privacy and continuity risk.
Public impact
healthcare services disrupted
Monitored signal
MFA, remote access and response
AT&T / SEC
Jul 2024
AT&T's disclosure described improper download of call and text records from a third-party cloud platform. It's a strong example of SaaS, access and vendor-chain risk.
Public impact
nearly all mobile customers affected
Monitored signal
third parties, logs and credentials
FBI IC3
2024 Report
The IC3 annual report shows phishing/spoofing among the most reported crimes and record losses from digital scams. The executive takeaway needs to connect fraud, identity and monitoring.
Public impact
859,532 complaints in 2024
Monitored signal
phishing, BEC and extortion
CISA KEV
Updated
The Known Exploited Vulnerabilities catalog is a public reference for separating theoretical vulnerability from observed exploitation — exactly the kind of signal that cuts noise in the scanner.
Public impact
patching based on real risk
Monitored signal
exploited CVEs and deadlines
Start the trial and use the full Pro plan for 7 days: continuous monitoring, executive reports, alerts and advanced features. The first charge is only due on day 8.
Active scans require domain verification to protect third parties and prevent abuse.
Core capabilities
Every module solves a real security problem — from continuous monitoring to consultative enterprise operations.
AI
Security assistant with Claude and Gemini. Mandatory PII masking, LGPD consent, and real-time streaming.
AI
AI-generated daily assessment, automatic risk prioritization and one-click Autopilot mitigation — a fresh layout every morning.
Risk Management
Risk execution hub: turns signals and findings into trackable cases, with SLAs, automatic triage and an advisory AI copilot.
Intelligence
CISA KEV, EPSS and CERT.br integrated — actionable global and Brazilian threat intelligence with no API key required.
Intelligence
Look up IP, malware hash and suspicious URL reputation with geolocation, multi-source fallback and unified history.
Monitoring
Immediate alert when emails, IDs, or domains appear in global data breaches via HaveIBeenPwned API.
Anti-fraud
CPF/CNPJ background checks, federal sanctions lookup (CEIS/CNEP) and community risk scoring. Includes Phishing Analyzer: forward a suspicious email to isthisphishing@masadasecurity.net and get an AI verdict in seconds.
Cloud Security
Agentless Cloud Email Security & Drive CASB/DLP. Detects inbound phishing, outbound DLP violations and CASB anomalies using dual-LLM analysis (Claude + Gemini) with mandatory PII masking in real time.
Assets
Automatic discovery, ownership verification and centralized management of every digital asset in one inventory.
Diagnosis
Multi-engine recon across IPs, domains and hosts: exposed surface, CVEs, TLS/SSL, technology fingerprinting and DNS tools — a 360° view of the target.
Diagnosis
Active scanner with Nuclei v3.3 (8,000+ templates). Auto cross-reference with CISA KEV and EPSS. Mandatory target ownership verification.
Diagnosis
Detects exposed secrets and credentials in Git repository history before they become an incident.
Pentest
Pentest report management with R2 evidence upload, AI analysis, and automatic finding cross-reference.
Awareness
Custom phishing simulations, continuous awareness training and per-employee human risk metrics.
Identity
Maps access, scores identity risk and syncs your directory (Google Workspace/M365). SSO via OIDC and SAML 2.0, SCIM 2.0 provisioning and granular RBAC with 28 permissions.
Compliance
Structured checklist by category with R2 evidence upload. Automatic compliance score per category.
Automation
Automatic scheduling of scans and monitors via cron expressions. Unified execution history in real time.
Alerts
Real-time threat notifications via email, Slack, webhook and more — 7 configurable delivery channels.
Enterprise
Exports alerts to SIEM (Splunk, Sentinel, Datadog), creates tickets in ITSM (Jira, ServiceNow) and fetches credentials from PAM (CyberArk, HashiCorp Vault) via mTLS.
Pricing
Start with 7 days free, move up to continuous monitoring or advanced management, and scale to Enterprise when you need governance, integrations and premium support.
Basic monitoring
R$ 297/mo
For companies that need to track essential risks without complexity.
+ 4 features in the comparison
Annual plan: R$ 2,970/year (2 months free).
Try Starter for 7 daysGrowing operation
R$ 697/mo
For SMBs with an IT team that need daily AI, more volume and API integration.
+ 4 features in the comparison
Annual plan: R$ 6,970/year (2 months free).
Try Business for 7 daysContinuous management
R$ 1,297/mo
For companies that need to monitor, prioritize and reduce digital risk continuously.
+ 7 features in the comparison
Annual plan: R$ 12,970/year (2 months free).
Try Pro for 7 daysGovernance and integrations
Contact us
For organizations that need governance, integrations, retention, premium support and advanced operations.
+ 3 features in the comparison
Comparison
The table shows where Starter, Pro and Enterprise start making sense.
| Feature | Starter | Business | Pro | Enterprise |
|---|---|---|---|---|
| Users | 3 | 10 | 25 | unlimited |
| Verified domains | 2 | 8 | 20 | unlimited |
| Inventory assets | 10 | 60 | 150 | unlimited |
| Vulnerability Scanner | 15 scans/month | 60 scans/month | 150 scans/month | unlimited |
| Scan profiles | quick and standard | + deep | + custom | all |
| Network Scanner / OSINT | 50 queries/month | 250 queries/month | 600 queries/month | unlimited |
| On-demand scans and continuous IP monitoring | no | no | yes | yes |
| Breach Monitor | 50 queries/month · 1 target | 300 queries/month · 8 targets | 1,000 queries/month · 20 targets | unlimited |
| Threat Lookup | 50 queries/month | 250 queries/month | 500 queries/month | 5,000 queries/month |
| Anti-fraud (CNPJ and sanctions) | 25 queries/month | 150 queries/month | 300 queries/month | unlimited |
| LGPD | full · 1 GB of evidence | full · 5 GB | full · 10 GB | unlimited |
| Phishing Training | 1 campaign/month · 15 targets | 3 campaigns/month · 100 targets | 5 campaigns/month · 250 targets | unlimited |
| Pentest Control | 2 AI analyses/month · 1 GB | 15 AI analyses/month · 5 GB | 50 AI analyses/month · 10 GB | 500 analyses/month · 20 GB |
| Risk Operations | 100 open cases | 500 open cases | 2,000 open cases | unlimited |
| Automations | 1 active | 5 active | 15 active | unlimited |
| Masada AI | 800 credits/week | 3,000 credits/week | 7,500 credits/week | 30,000 credits/week |
| Daily AI assessment on the Dashboard | no | yes | yes | yes |
| Phishing Analyzer | no | 200 emails/month | 500 emails/month | unlimited |
| REST API (OAuth 2.0 M2M) | no | yes | yes | yes |
| Workspace Sec (email and DLP) | no | no | 1 domain · 2,000 emails/month | unlimited |
| Code Security | no | no | 10 repositories · 30 scans/month | 50 repositories |
| IAM and SSO | no | no | 100 identities · 1 SSO provider | unlimited |
| SIEM/PAM/ITSM integrations | no | no | yes | yes |
| SCIM and forensic Journal (WORM) | no | no | no | yes |
| Alerts (email, Slack, Teams, Telegram, webhook) | yes | yes | yes | yes |
| Alert history | 60 days | 6 months | 1 year | unlimited |
| Support | priority | premium with SLA |
Responsible use
Queries and scans are governed by quotas, permissions and domain validation. Active features and sensitive integrations unlock based on plan and verification level.
No. The first charge is only due after 7 days; you pay by PIX or card on the first invoice and can cancel before that from the platform. The free trial applies to your first signup only (one per CPF/CNPJ and email); on a new subscription, access is released once payment is confirmed.
The Pro trial follows the checkout flow configured for the environment. Before finishing, you'll see the plan, billing cycle and applicable terms.
No. Active scans require domain verification to protect third parties and reduce the risk of abuse.
Contact us
Tell us what you need and MASADA forwards the context to cyber@masadasecurity.net with a structured briefing for diagnostics, Starter, Pro trial, Enterprise, AI or privacy.
Structured briefing
Official contact
Clear priority
The more context, the better the first response. For legal, privacy or DPO matters, the official channel is also cyber@masadasecurity.net.
Next step
Try MASADA for 7 days to spot risk signals and experience monitoring, prioritization and executive reports — no charge before day 8.