Skip to content

Offensive security, on autopilot.

Chadow runs authorized engagements end to end — recon, scanning, exploitation and a written report — against targets you own. Findings land in one workspace with the evidence attached and the steps to reproduce them.

Authorized targets only. Scope is confirmed before anything runs.

See it run

Watch a live app test

Pick a surface. Cortex drives the target like a user, watches what it says on the wire and reads what it leaves behind — and reasons about what it sees. This is the shape of a real run.

shop-android-4.2.1.apk

Simulated walkthrough

Activity

  1. Bashadb install shop-android-4.2.1.apk

Findings

Example findings, not a real engagement.

Nothing yet.

Findings shown are illustrative. On your own target, each one arrives with the evidence attached and the steps to reproduce it.

What it does

An offensive-security team in a box

Five modules in one workspace: two that run engagements, two that keep watching, and one you can ask.

Cortex

Application scanning

Points real offensive tooling at one application and writes up what it finds, with the evidence attached. It takes more than a URL:

  • Web app URL
  • Android / iOS build
  • Source ZIP
  • API spec — OpenAPI, Postman, HAR
  • Cloud account — AWS, GCP, Azure
  • Linux host over SSH

Apex

Offensive simulation

Plans and runs a full engagement against an authorized target — recon, exploitation, chaining what works — and writes up what it found, with the evidence in the report.

Talon

Credential exposure

Watches breach and credential-dump data for the domains and addresses a workspace has verified, and flags the matches.

Beacon

CVE intelligence

A local, filterable mirror of the public CVE feed — searchable against the software you actually run, without leaving the workspace.

Cognition

Security assistant

A chat assistant with this workspace’s scans and findings in context — for triage, follow-up questions and drafting the write-up.

Cortex and Apex spend real compute against real infrastructure. They run only against targets a workspace has added and confirmed it is authorized to test, and a run takes as long as the work takes.

How it works

From target to report in three steps

  1. Add a target

    Name the domain, app or asset you are authorized to test and confirm its scope. Nothing is deployed and no agent is installed.

  2. Chadow runs the engagement

    Watch either one work — Cortex shows its reasoning and every action it takes; Apex shows its plan, its agents, the pages it captures and the commands it runs.

  3. Read the findings

    Findings land in the workspace ranked by severity, each with its evidence and the steps to reproduce it, and a report you can hand to whoever fixes it.

Pricing

Plans that scale with your attack surface

What Chadow costs depends on how much surface you point it at.

  • Starter

    $299/mo

    Save 17% billed yearly

    Essential features for individuals.

    Up to 3 seats

    • Chadow Cortex — up to 20 Scans
    • Chadow Talon — Data Leak Monitoring
    • Chadow Cognition — Image Upload
    • Chadow Cognition — Thinking Mode
    • Data Leak Visibility
    • Chadow Pulse — Domain Health Monitoring
    • Chadow Beacon — 5 Alert Rules
    • Dynamic Mobile Testing (BYOD)
    • 24/7 Email Support
    Subscribe
  • Pro

    Most popular

    $999/mo

    Save 17% billed yearly

    Advanced features for professionals.

    Up to 6 seats

    • Everything in Starter, plus:
    • Chadow Apex — AI Powered Autonomous Web Penetration Testing (1 Scan)
    • Chadow Cortex — up to 50 Scans
    • Chadow Beacon — 10 Alert Rules
    • Cortex Cloud Security Posture
    • Deep Exploitation
    • AI Risk Dashboard & Attacker Scenarios
    • 24/7 Email Support
    Subscribe
  • Business

    $1,999/mo

    Save 17% billed yearly

    For teams and growing businesses.

    Up to 15 seats

    • Everything in Pro, plus:
    • Chadow Apex — up to 4 Monthly Scans
    • Chadow Cortex — up to 100 Scans
    • Concurrent Cortex Scans — up to 10
    • Chadow Beacon — 40 Alert Rules
    • 24/7 Email Support
    Subscribe
  • Enterprise

    Custom

    Priced to your scope

    Full access for organizations.

    Up to 100 seats

    • Everything in Business, plus:
    • Chadow Cortex — Unlimited Scans
    • Chadow Apex — up to 25 Monthly Scans
    • Cortex Authenticated Network Audit
    • API Access
    • DAST Integration
    Talk to us

Want to look around first? Create an account — or sign in if you already have one.

Add-ons

These are extras on an existing subscription, not the price of Chadow. Each is bought one at a time, stacks on top of a base plan, and stays valid until that subscription ends.

  • Extra Apex Scan (1)$100one-time
  • Extra Seats (5)$19.99one-time
  • Extra Token Budget (100K)$4.99one-time
  • Extra Cortex Scan$19.99one-time
  • Extra Projects (5)$7.99one-time

Talk to us

Book a demo

Thirty minutes with an engineer, run against something you own.

Thirty minutes, not a sales cycle

One call. We launch a scan against a target you nominate and stay on the line while it runs.

Scope is agreed in writing first

Nothing is touched until you have confirmed, in writing, what we may test. Authorized targets only — that is the whole basis this works on.

You keep whatever it finds

The findings and the written report are yours at the end of the call, whether or not you go further.

We confirm your email and phone with a one-time code so a booking reaches a real person. Both are used for this booking and to reach you about it — two messages in total, and no marketing list.

Book a demo

Thirty minutes, against a target you own. We agree scope before anything runs.

  1. 1Email
  2. 2Phone
  3. 3Details

See what an attacker would find first.

Point Chadow at something you own and let it do the recon, the scanning, the exploitation and the write-up. You decide what gets fixed.