From security scanning to audit evidence, SPHIOR handles it every month.
Aligned with SOC 2, ISO 27001, and OWASP, SPHIOR delivers monthly evidence built for engineers, executives, and auditors alike. Vanta and Drata integration supported.
Check your site for free
By the time it makes the news, it is already a financial event.
What happened to companies that deprioritized security. Every case below is a documented fact, not a cautionary tale.
Real-World Breach Cases
Continuity
Stopped in 12h
12 hours from breach to bankruptcy
The root AWS account had no MFA, so stolen credentials alone gave full access. After ransom was refused, the attacker deleted every instance, bucket, and snapshot. The company had no path to recovery and shut down the same day. Skipping MFA at cloud setup erased the entire business.
Continuity
Stopped in 12h
Cause
No MFA on the root AWS account
Accounts impacted
3B+
Weak hashing erased ~$350M in acquisition value
Two breaches in 2013 and 2014 went undisclosed until 2016. MD5-hashed passwords were trivially crackable, enabling continuous exploitation. All 3 billion accounts were ultimately affected. Yahoo's Verizon acquisition price was cut by $350M over the hidden incident.
Accounts impacted
3B+
Cause
Legacy MD5 hashing and delayed disclosure
Customers affected
~500K
22 lines of code that shook a global brand
Magecart inserted 22 lines of skimmer code into a third-party JavaScript loaded on the checkout page. Every card detail entered was forwarded to attackers in real time for nearly two weeks. About 500K customers were affected and the initial GDPR fine proposal reached £183M.
Customers affected
~500K
Cause
Third-party JavaScript injection (Magecart)
Records exposed
148M
An unpatched vulnerability exposed 148M people
A critical Apache Struts patch (CVE-2017-5638) sat unapplied for two months. Attackers exploited it, remained undetected for 76 days, and exfiltrated 148M records including SSNs and birth dates. Total settlement and fine costs exceeded $575M. The CEO and CIO resigned.
Records exposed
148M
Cause
CVE-2017-5638 left unpatched for 2 months
Cards stolen
40M
An HVAC vendor's credentials breached 40M cards
Credentials stolen from an HVAC vendor provided a foothold inside Target's corporate network. Poor network segmentation let malware spread to 4,000+ POS terminals during Christmas season. 40M payment cards and 70M personal records were stolen, triggering CEO and CIO resignations.
Cards stolen
40M
Cause
Vendor network not isolated from POS systems
Orgs compromised
18,000+
A trusted software update became a nation-state weapon
Attackers inserted the SUNBURST backdoor into a legitimate monitoring software update. Over 18,000 organizations installed it — including the US Treasury and State Departments. The intrusion went undetected for ~9 months and redefined supply-chain attacks as a top-tier threat.
Orgs compromised
18,000+
Cause
Build system compromise and malicious code injection
Total loss
~$3B+
One missing MFA setting halted US healthcare for weeks
One internal account lacked MFA on a critical system. A single stolen password was enough for ransomware operators to access the core. US pharmacies and hospitals stopped processing prescriptions and payments for weeks. Total losses to UnitedHealth Group exceeded $3B.
Total loss
~$3B+
Cause
MFA missing on a critical access account
Machines crashed
8.5M
A security vendor's own update caused history's largest IT outage
A faulty content update — not malware — crashed 8.5M Windows machines globally. Airports, banks, hospitals, and broadcasters halted simultaneously. Fortune 500 firms alone lost $5.4B+. A trusted security vendor proved a single bad update can outscale any cyberattack.
Machines crashed
8.5M
Cause
Unvetted content update pushed to production
Stolen
~$1.4B
Phishing seized the keys behind a multi-sig wallet
Phishing and access exploitation let attackers seize the signing environment of a multi-signature wallet. The multi-sig protocol itself was intact, but the human layer managing the keys was compromised. ~$1.4B in Ethereum was stolen — the largest single crypto theft in history.
Stolen
~$1.4B
Cause
Phishing compromise of multi-sig key managers
The audit areas SPHIOR handles — kept as tamper-proof facts.
Your security scan results, your infrastructure changes, your own AI's activity — whatever reaches SPHIOR is kept as a record that can't be rewritten. Not even SPHIOR, which built it, can change it afterward.
Vulnerabilities and misconfigurations found
CC7 · Vulnerability management
Every month we actually scan your site and cloud environment and record the weaknesses and misconfigurations we find, with severity and impact. What was found, when, and how it was fixed stays in a form that can't be rewritten later.
Cloud configuration change diffs
CC8 · Change management
We record when and how your cloud and infrastructure settings changed, as diffs. The contents themselves stay with you — only the fact that something changed becomes the record.
TLS encryption and exposed login surfaces
CC6 · Logical access (technical)
We record whether traffic is properly encrypted (TLS, certificates) and how your externally exposed authentication and login surfaces look. Your internal identity systems and company-wide MFA are out of scope.
Your AI and agents' executions
ISO 42001 / EU AI Act
We record what your in-house AI and AI agents did — which model, when, and what decision. The prompts and answers themselves stay with you; only the fact that a run happened is kept as a tamper-proof record.
Records from any tool or SaaS
Connected via webhook
Even in areas SPHIOR doesn't scan, send events from any internal tool or SaaS and they become the same tamper-proof records. Onboarding and offboarding, vendor reviews, access reviews — keep the evidence you care about in one place.
Vulnerabilities and misconfigurations found
CC7 · Vulnerability management
Every month we actually scan your site and cloud environment and record the weaknesses and misconfigurations we find, with severity and impact. What was found, when, and how it was fixed stays in a form that can't be rewritten later.
Cloud configuration change diffs
CC8 · Change management
We record when and how your cloud and infrastructure settings changed, as diffs. The contents themselves stay with you — only the fact that something changed becomes the record.
TLS encryption and exposed login surfaces
CC6 · Logical access (technical)
We record whether traffic is properly encrypted (TLS, certificates) and how your externally exposed authentication and login surfaces look. Your internal identity systems and company-wide MFA are out of scope.
Your AI and agents' executions
ISO 42001 / EU AI Act
We record what your in-house AI and AI agents did — which model, when, and what decision. The prompts and answers themselves stay with you; only the fact that a run happened is kept as a tamper-proof record.
Records from any tool or SaaS
Connected via webhook
Even in areas SPHIOR doesn't scan, send events from any internal tool or SaaS and they become the same tamper-proof records. Onboarding and offboarding, vendor reviews, access reviews — keep the evidence you care about in one place.
Deep, authenticated audits, architected for absolute security.
Safely and comprehensively diagnose vulnerabilities deep within your system, beyond the login screen. Through secure session handoffs via our dedicated browser extension and isolated scanning environments, we completely eliminate the risk of production impact and data leakage.
Secure Integration via Extension
Use the SPHIOR Chrome extension to securely synchronize auth credentials or session tokens from your local environment. No plaintext passwords stored on our servers.
Encrypted Session Vault
Received sessions are heavily encrypted and managed strictly within a secure vault. They are loaded into memory only during the scan to maintain safe access.
State-Aware Dynamic Scanning
Not just a crawler, but an engine that understands application state. We deeply and accurately trace post-login processes involving complex transitions and API calls.
Fully Isolated Audit Environment
Scans execute on isolated, ephemeral microVMs for each customer. Physical data boundaries ensure that your audit data never leaks to other environments.
One assessment. Three audiences. Three optimized outputs.
Vulnerability reports change meaning depending on who reads them. SPHIOR generates the right shape for engineering, leadership, and audit — from the same evidence.
Every month, SPHIOR keeps pace with the latest attack techniques.
Security threats evolve every month. SPHIOR's security team continuously incorporates new vulnerabilities, attack patterns, and CVEs into the scan engine — so your diagnostic standards never go stale.
Every monthly assessment runs on the latest engine.
Engine Updates
Engine continuously synced
Your evidence, independently verifiable by anyone in the world
Each month's evidence is recorded in a public ledger that no one can alter. So third parties such as auditors can verify for themselves — without relying on SPHIOR — that the evidence hasn't been tampered with.
Ref · SPHIOR-RECORDER
Sealed Evidence Record
- Tamper-evident hash chain
- Public / qualified timestamp
- Independently verifiable
Ref · SPHIOR-AIGOV
AI Execution Record
- ISO 42001 / EU AI Act aligned
- Hash-only — no prompts or outputs
- Tamper-evident & verifiable
Ref · SPHIOR-AUDIT
Monthly Security Evidence
- External assessment performed
- Findings prioritized & tracked
- Sealed for auditor reference
Once recorded, your evidence can't be rewritten, not even by SPHIOR.
SPHIOR doesn't just report your security posture — it seals it. Findings, infrastructure-as-code changes, and AI executions are recorded in a tamper-evident, independently verifiable form, so you and your auditor can prove exactly what happened and when — without having to trust us.
Tamper-evident & independently verifiable
Every record is sealed with public and qualified timestamps. Your auditor verifies it with open tools — no need to trust SPHIOR.
AI Governance evidence — ISO 42001 / EU AI Act
Record your AI and AI-agent executions as tamper-evident evidence for ISO 42001, the EU AI Act and SOC 2. Only hashes and metadata are stored — never your prompts or outputs.
Supporting evidence for SOC 2 / ISO 27001
Monthly external assessment records, scope and remediation — sealed and packaged for auditor reference.
Choose Your Plan
Stay ahead of site outages, reputation damage, and hidden vulnerability risks — and know exactly what to fix first. Choose the plan that matches your business scale and the depth of security assurance you need.
Core
For securing one main product
Complete security diagnosis for your main product — including authenticated DAST that scans behind login. Prove your product is secure every month, with tamper-evident records and no dedicated engineer required.
Billed 1,990 yearly
- Authenticated DAST — scans behind login, admin panels & APIs
- Vulnerability & misconfiguration scanning
- Deep security headers, HTML & privacy audit
- DNS security audit (SPF / DKIM / DMARC / DNSSEC)
- TLS certificate transparency check
- Uptime & response monitoring
- Tamper-evident evidence + monthly security report
First month free
Scale
For portfolios & security teams
Everything in Core, across your whole portfolio. Automatic asset discovery finds all your properties and scans them together, with month-over-month delta tracking and one-click push to your GRC tool.
Billed 5,990 yearly
- Everything in Core — for many properties
- Automatic asset discovery + subdomain coverage
- Deeper CVE & known-vulnerability scanning
- Month-over-month delta tracking (new risk detection)
- Code security scanning (GitHub integration)
- Cloud infrastructure audit (AWS / GCP / Azure / Cloudflare — optional)
- GRC integration push (Drata / Vanta / Secureframe)
- Team seats + monthly report with remediation priorities
First month free
Enterprise
For regulated industries & audit-ready orgs
Everything in Scale, plus SPHIOR Recorder — a tamper-proof, independently verifiable record of every infrastructure-as-code change, so you can prove exactly what changed and when. Includes qualified timestamps (RFC 3161) and audit-ready evidence packs your auditor can verify independently.
Billed 24,990 yearly
Custom scoped based on coverage, authenticated setup, and support needs.
- Everything in Scale
- SPHIOR Recorder — tamper-proof record of every infrastructure-as-code change
- Qualified timestamps (RFC 3161)
- Auditor-ready evidence packs (OSCAL · independently verifiable)
- Governance AI + AI chat included
- Priority support & SLA
Ready to Secure Your Digital Future?
✓ 24/7 Monitoring
