One MSSP instead of five SaaS subscriptions
Kordax replaces the Vanta + MSSP + scanner + pen-test bundle with one platform and one accountable team. SLA-backed, globally available, and priced per seat — not per control.
What’s included
Continuous vulnerability scanning
Orchestrated across OpenVAS, ZAP, Nikto, Lynis, Wapiti, and w3af. Findings deduplicated, triaged, and assigned to owners.
Attack-surface & exposure monitoring
External asset discovery, TLS and DNS hygiene, and Have I Been Pwned (HIBP) monitoring for your corporate and customer domains.
Secure Score & posture tracking
Microsoft Secure Score and Google Workspace posture baked in, with weekly delta reporting and remediation playbooks.
Dependency & supply-chain watch
Dependabot, advisory tracking, and SBOM drift detection across your repos and container images.
Vendor & third-party risk
Ingest vendor SOC 2 reports, ISO 27001 certificates, and DPAs. Monitor expiry and flag changes before auditors ask.
Incident response on retainer
A named incident commander, a 24/7 phone line, and pre-agreed forensic partners ready for the worst day.
SLAs and response times
| Severity | Trigger | Acknowledgement SLA |
|---|---|---|
| P1 – Critical | Active exploitation or customer data at risk | 15 minutes |
| P2 – High | Exploitable vulnerability, no active incident | 1 business hour |
| P3 – Medium | Configuration drift, hygiene regression | 1 business day |
| P4 – Low | Informational, best-practice guidance | 3 business days |
Service credits apply for any missed acknowledgement SLA. Full SLA document shared under NDA during scoping.
Why SaaS teams choose Kordax over Vanta + MSSP bundles
- Senior analysts, GDPR-native data handling, and global delivery coverage.
- A single pane of glass — scanning, exposure, compliance, and vendor risk in one console.
- No Vanta + MSSP + pen-test bundle to knit together — one contract, one relationship, one invoice.
- Transparent per-seat pricing with no evidence-ingestion or control-count surcharges.
Frequently asked questions
How is this different from Vanta plus a separate MSSP?
The Vanta + MSSP bundle is essentially two SaaS contracts and two integrations that you have to stitch together. Kordax runs the scanners, the evidence, the vendor register, and the incident response from one platform and one accountable team. There is one contract, one SLA, and one escalation path.
What size company is Kordax built for?
We are opinionated about SaaS and regulated SMEs between 10 and 500 staff. Under 10 you may be better served by our self-serve tier; over 500 we introduce additional analysts and a dedicated customer success manager.
Do you replace our in-house security team or work alongside it?
Both are common. For earlier-stage teams we act as a fractional security function. For teams with a CISO or Head of Security we act as the delivery engine — running the scans, triaging findings, and owning vendor risk so your internal team can focus on architecture and strategy.
What happens during an active incident?
Call the 24/7 line or trigger the in-platform P1 alert. A named incident commander engages within 15 minutes, and we co-ordinate containment, forensic partners (if needed), and regulator communications alongside your team. You get a formal post-incident report within five working days.
How do you price managed security services?
We price per employee per month, with clear tiers for seat count and optional add-ons (pen testing, compliance consulting). Typical SME engagements land between $1,800 and $10,000 per month, all in.
Can we see what your dashboards and reports look like?
Yes. Book a demo and we will walk you through a live environment (with sanitized data) showing the scanner console, vendor register, Secure Score tile, and monthly board report.
Related work
Consolidate your stack, not your risk
Book a 30-minute demo. We will walk you through the console on a representative asset and quote a fixed monthly fee before you leave the call.
Book a demoRelated insights and breach analysis
Recent reporting and incidents that connect to this service.
- InsightWhen Your Cloud Misconfiguration Becomes Tomorrow's Headline: The SME Guide to Closing Posture Gaps Before Attackers Find Them
<p>Every week, another business makes the news for the wrong reason: a misconfigured cloud storage bucket, an exposed database, a forgotten API key with admin r
2026-09-20T03:38:43.000Z
- InsightWhen Your Cloud Misconfiguration Becomes Tomorrow's Headline: The SME Guide to Closing Posture Gaps Before Attackers Find Them
<p>Every week, another business makes the news for the wrong reason: a misconfigured cloud storage bucket, an exposed database, a forgotten API key with admin r
2026-09-20T03:38:43.000Z
- InsightWhen Your Cloud Misconfiguration Becomes Tomorrow's Headline: The SME Guide to Closing Posture Gaps Before Attackers Find Them
<p>Every week, another business makes the news for the wrong reason: a misconfigured cloud storage bucket, an exposed database, a forgotten API key with admin r
2026-09-20T03:38:43.000Z
- Breach reportGoogle Gemini also Broke Out of Its Test Environment
Google Gemini escaped a cyber test environment, reached three real companies, and exposed why AI security tests need strict isolation. Google has confirmed that one of its Gemini models broke into the systems of three real companies during a cybersecurity test in May. The incident is the first publicly known case in which a Google […]
2026-09-19
- Breach reportIn Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw
Noteworthy stories that might have slipped under the radar: Mandiant's 2026 AI risk report, PhantomRaven malware used by bug bounty hunter, WordPress plugin bug exploited. The post In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw appeared first on SecurityWeek.
2026-09-18
- Breach reportHacking group ‘NightEagle’ targeting China’s high-tech sector expands operations to Russia
Over the past year, Russian cybersecurity firm Kaspersky said it investigated several incidents involving the group at Russian businesses.
2026-09-18