
SQUR provides autonomous, AI-driven web and API security testing for European SMEs, delivering verified pentest findings with working exploits and compliance-ready reports. The platform combines a free 60-second attack surface scan with on-demand or continuous pentesting that achieves human-parity accuracy while reducing noise by 90%.
Funding
Funding not disclosed
Founders
Product
Problem
Traditional penetration testing is slow, expensive, and dependent on scarce human expertise, forcing companies to choose between development velocity and security compliance. Annual or one-off tests leave organizations exposed to newly discovered vulnerabilities for months, while conventional scanners generate high volumes of false positives that overwhelm security teams.
Solution
SQUR delivers autonomous pentesting that combines AI-driven attack simulation with verified exploit proof for every finding, eliminating false positives and providing auditors with evidence they can accept. The platform maps external attack surfaces in 60 seconds without sending attacks, then performs authorized, full-scope pentests of web applications and APIs within 24 hours. Each finding includes a working exploit, remediation guidance, and a compliance-ready report supporting NIS2, DORA, ISO 27001, SOC 2, and GDPR requirements. The continuous Professional plan runs a full pentest monthly, re-tests open findings, and refreshes a living security certificate after each clean run.
Target Audience
Primary customers are European SMEs, security leaders, engineering teams, and MSSPs needing cost-effective, continuous security validation with audit-ready evidence for compliance frameworks.
Features
- Autonomous pentest engine that independently achieves human-parity quality, measured against top human pentesters
- Verified exploit proof for every finding, with zero false positives and ~90% noise reduction compared to traditional scanners
- Free 60-second attack surface scan that maps external exposure including assets, open ports, and misconfiguration indicators without sending attacks
- 24-hour full pentest coverage for web apps and APIs, including authenticated areas with multiple user roles and custom scope configuration
- Continuous monthly pentesting with automatic re-testing of open findings, marking them as Fixed, Regressed, or New
- Living compliance certificate that refreshes after each clean run, supporting NIS2, DORA, ISO 27001, SOC 2, BSI, and GDPR frameworks
- GitHub and CI/CD integration for enterprise customers, enabling security testing within development workflows
- Bulk credit system valid for 12 months, allowing flexible pentest scheduling across multiple applications