
Latchkey
​​​
Autonomous penetration testing that reports only what an attacker could actually exploit.
​
Real offensive tradecraft running as a service, without a red team on payroll. No scanner noise. No thousand line reports of theoretical findings. Just the handful of things that would get you breached, each one proven by exploitation.
​
​
Scanners bury you in findings that do not matter
Traditional vulnerability assessment flags everything it can see and inflates the severity of most of it. Unreachable services, unauthenticated banners, false positives your team spends weeks triaging. You end up staring at a spreadsheet of five hundred items while the two paths that actually lead to domain admin sit quietly in the middle of it.
​
A CVSS score is not an attack. A flagged version string is not a breach. You do not need a longer list. You need to know what an adversary would do with what you have.
​
It runs the attack, not the checklist​
Latchkey chains offensive techniques the way an operator would. Network discovery, service enumeration, credential attacks, exploitation, and post exploitation, orchestrated end to end and unattended. Nobody babysits a console. Nobody stitches tools together.
​
We build Latchkey out of the work we do on live red team engagements. When we find something that works in the field, it goes into the product.
​
That is where the technique library comes from and that is what separates it from a scanner with a marketing budget.
​
If it cannot be exploited, it does not get reported
Every finding is validated by exploiting it, not inferred from a version number. You get a short, ranked list of proven attack paths. Each one comes with the evidence, the real world impact, and the fix.
​
No theoretical maybes. No padding to make the report look thorough. If an attacker could not use it, it does not make the report.
​
How it works
Authorize your scope. You define the assets you own or have written permission to test.​
​
It attacks like an adversary. Discovery, enumeration, exploitation, and pivoting run in sequence without supervision. Every action is logged to your account.
​
You get proven paths. A ranked report of what an attacker can actually reach, with proof of exploitation and clear remediation for each path.​
​
One price​
Twenty dollars a month. Test as often as you want across your authorized scope. No per scan fees, no seat math, no surprise overages. Run it after every deploy, run it nightly, run it before the board meeting.​
​
​
Who it is for​
-
Teams without a full time offensive capability who still need to know their real exposure.​
-
Engineers who refuse to wait for the annual pentest to find out an attacker already had a way in.​
-
Security leaders stuck between a quarterly scan that finds nothing useful and an annual engagement that finds everything eleven months too late.
​
Where Latchkey stops​
Latchkey finds the technical paths an adversary would take through your infrastructure. It does not walk into your lobby, it does not call your help desk, and it does not tell you what a determined human does with a work order and a high visibility vest.
​
Automated testing tells you what is reachable. It cannot tell you what happens when someone decides to try. When you need that answer, Penetration Testing or Active Threat Emulation Testing are where the people come in.
​
Built for authorized testing​
​Exploitation is real, which means it can cause state change on live systems. Run it against production the way you would run any authorized test, with a window and a rollback plan if the environment is fragile.
​
We build offensive tooling for defenders. Responsible use is part of the product, not an afterthought.
​
Stop reading reports nobody acts on​
See the attacks that matter, proven and ranked, in plain language.
​
​
Common questions
-
Is this a vulnerability scanner? No. A scanner lists what might be wrong. Latchkey proves what an attacker can actually do.
-
How is this different from the enterprise validation platforms? Two things. Price, because those platforms are six figure purchases that move through procurement for a quarter before anyone runs a test. And provenance, because we still run human red team engagements and everything we learn in the field feeds the product.
-
Do I need offensive security skills to use it? No. It runs on its own and reports in language you can act on without a red team to interpret it.
-
What do I have to authorize? Only assets you own or have written permission to test. You confirm authorization before each run and scope enforcement is built in.
-
How often can I run it? As often as you want within your authorized scope.
-
Will it break something? Exploitation is real, so it can cause state change. Treat a run the way you would treat any other authorized test against production.
-
What do I get at the end? A ranked list of proven attack paths, each one with exploitation evidence, business impact, and remediation guidance.
-
Does this replace a red team engagement? No. Latchkey covers the technical attack surface. It does not cover people, buildings, or the pretext that gets someone through a door. Those stay with our assessment team.