What SERAPH does and why it exists
SERAPH runs autonomous cyber due diligence on an acquisition target's public attack surface.
The honest starting point for SERAPH is not a comparison against other scanners. It is a comparison against what almost every lower-middle-market acquirer actually does today, which is nothing.
Cyber diligence before a letter of intent is rare below a certain deal size, because a Big 4 cyber diligence engagement typically runs in the region of $50,000 and takes about six weeks. On a $12M acquisition that is not a defensible line item, and it does not fit inside an LOI timeline. So the work gets skipped, and the acquirer discovers the target's security posture after closing.
SERAPH runs a nine-wing autonomous scan against the target's public attack surface and returns a findings report in roughly ninety seconds, at $299/mo. That is a cost compression of roughly 170x against the traditional engagement, and it moves the analysis from post-close to pre-LOI.
What SERAPH is not: it is not a penetration test, it is not a substitute for a full security audit before a large transaction, and it does not access anything that is not publicly reachable. It is a pre-LOI screening instrument. Use it to decide whether deeper work is warranted.
Was this helpful?