Help Center

Frequently Asked Questions

Everything you need to know about Cynoculist services and our three proprietary products: DASTA-AI, the intelligent GRC platform, and Aether autonomous SOC.

About Cynoculist

About Cynoculist

Who we are, who we serve, and how we deliver security differently.

What makes Cynoculist different from other cybersecurity providers?
Cynoculist is a boutique cybersecurity partner specializing in AI-driven security for small to mid-sized organizations. We build and operate three proprietary products (DASTA-AI, our intelligent GRC platform, and Aether) which we also use to deliver client services. That means our advice is grounded in products we own and operate, not third-party tooling.
What types of businesses does Cynoculist serve?
We primarily serve small and mid-sized businesses (SMBs) that need enterprise-grade security without the overhead of an in-house security team, and enterprises deploying AI systems who need AI risk assessment, AI governance frameworks, and NIST AI RMF compliance. Sectors include Finance, Healthcare, E-commerce, and SaaS/AI companies.
Where is Cynoculist based and do you work remotely?
We're headquartered in New York, NY and deliver all cybersecurity services remotely to businesses across the United States.
Do you offer 24/7 security monitoring?
Yes. Our Aether autonomous SOC platform provides 24/7 real-time alert triage, enrichment, and escalation across cloud and SIEM environments. For managed service clients, this is backed by expert-led incident response support.
How does AI enhance your security services?
AI is built into each of our proprietary products: DASTA-AI uses AI for vulnerability analysis, executive risk translation, and privacy-safe finding summaries; the GRC platform uses AI to translate regulations into trackable controls, derive compliance status, and generate board-ready reports; and Aether uses AI agents to triage, enrich, and escalate security alerts in under 15 seconds.
Proprietary Product

DASTA-AI: Dynamic Application Security Testing

AI-aware DAST covering Web apps, REST and GraphQL APIs, with CLI, CI/CD integration, and a privacy-first pipeline.

What is DASTA-AI?
DASTA-AI is our proprietary privacy-centric Dynamic Application Security Testing (DAST) platform. It scans Web applications, REST APIs, and GraphQL APIs for OWASP Top 10, CWE Top 25, and OWASP LLM Top 10 vulnerabilities. It ships with a developer CLI for local and scripted runs, CI/CD pipeline integration for GitHub Actions, GitLab CI, Jenkins and others, a zero-setup serverless scan engine, and mobile-first scan initiation. Try the free demo at dasta-ai.com.
What vulnerabilities does DASTA-AI detect?
DASTA-AI covers OWASP Top 10 (the ten most critical web application risks), CWE Top 25 (the most dangerous software weaknesses), and OWASP LLM Top 10 (AI and large language model-specific vulnerabilities). It is the only combined DAST platform that covers all three in a single scan engine.
What application surfaces and types does DASTA-AI scan?
DASTA-AI scans Web applications, REST API endpoints, and GraphQL APIs. All surface types are covered in the same scan session. It also supports framework-agnostic authenticated scanning, so protected pages behind any login system are covered.
Does DASTA-AI include a developer CLI and CI/CD integration?
Yes. DASTA-AI ships with a native CLI for local development runs, scripted scans, and dev-loop validation. It also provides CI/CD integration with structured exit codes and JSON output compatible with GitHub Actions, GitLab CI, Jenkins, and other CI runners, enabling shift-left security gates in your pipeline.
Does DASTA-AI support authenticated scanning behind login pages?
Yes. DASTA-AI supports framework-agnostic authenticated scanning, allowing the scan engine to operate behind login pages regardless of the frontend framework or authentication method used. This enables comprehensive coverage of protected application surfaces that unauthenticated scanners cannot reach.
What makes DASTA-AI different from other DAST tools?
Four pillars differentiate DASTA-AI. First, a Privacy-First Pipeline that de-identifies IPs, PII, and API keys before any AI analysis, ensuring GDPR and EU AI Act compliance. Second, an Executive Translation Engine that automatically identifies Key Risk Indicators (KRI) and generates business-impact summaries for non-technical stakeholders. Third, Mobile-First Initiation: DASTA-AI is the only enterprise-grade DAST tool that allows scan initiation and monitoring directly from a smartphone. Fourth, a Zero-Setup Serverless Engine delivering a 15-minute recursive scan window with zero infrastructure overhead.
What is CyberScore?
CyberScore is DASTA-AI's proprietary application risk score, generated automatically for every scan. It quantifies the overall security posture of the scanned application on a 0 to 100 scale, incorporating findings severity, count, and exploitability. CyberScore includes trend analysis across scans so security teams and executives can track risk reduction over time. Every plan, including the free demo, receives a full CyberScore report with an executive risk summary and PDF export.
Is DASTA-AI compliant with GDPR and the EU AI Act?
Yes. DASTA-AI's Privacy-First Pipeline is designed for compliance with GDPR and the EU AI Act. Before any AI analysis is performed, the pipeline automatically scrubs all findings data, removing IP addresses, personally identifiable information (PII), and API keys. Sensitive data from your application never reaches third-party AI services, giving security teams full data sovereignty.
Can I try DASTA-AI for free?
Yes. DASTA-AI offers a free demo account at dasta-ai.com/auth/demo that includes one full scan with no credit card required. The demo covers all three policy tiers (OWASP Top 10, CWE Top 25, OWASP LLM Top 10) and generates a full CyberScore report with an AI executive risk summary and PDF export.
What are DASTA-AI's standalone pricing plans?
DASTA-AI offers four tiers. Free Demo: 1 lifetime scan, no credit card required. Personal: $100/month per seat for 30 scans/month, self-serve via Stripe. Pro: 300 scans/month at the org level with invoiced billing (contact sales for pricing). Enterprise: unlimited scans, BYOK (Bring Your Own OpenAI Key), domain-locked invites, and a custom contract. Every tier runs the same hardened scan engine; plans differ only by quota and team features.
How does DASTA-AI integrate with Cynoculist service plans?
DASTA-AI is bundled into all Cynoculist service plans. Every bundled plan includes access to all scan policies. Scan quotas scale with the Cynoculist tier: Basic and Advanced plans include 30 scans/month (Personal tier), Premium plans include 300 scans/month (Pro tier), and Exclusive plans include unlimited scans with BYOK (Enterprise tier). DASTA-AI can also be purchased standalone at dasta-ai.com.
Proprietary Product

Intelligent GRC Platform

Centralized AI risk, gap, and compliance management for 10+ frameworks including NIST AI RMF, GDPR, ISO 27001, and EU AI Act.

What is the Cynoculist intelligent GRC platform?
Our intelligent GRC platform at audit.cynoculist.com is a centralized AI risk, gap, and compliance management system. It unifies internal audit management, AI-driven risk and gap analysis, automated cloud evidence collection, continuous vendor risk monitoring, compliance tracking across 15+ frameworks, and evidence management in a single platform. NIST AI RMF is built in as a first-class governance framework for organizations deploying AI systems.
How does automated cloud evidence collection work?
Connect AWS, GCP, or Azure with a read-only IAM role, service account, or app registration. Cynoculist inspects identity, storage, compute, networking, encryption, logging, and posture services, then maps findings to SOC 2, HIPAA, NIST 800-53, NIST CSF 2.0, PCI DSS, and CIS controls. One scan reuses evidence across multiple frameworks. Findings stream directly to your audit page.
What is Continuous Vendor Risk Monitoring (TPRM)?
Continuous TPRM uses DASTA-AI to scan vendor public attack surfaces on daily, weekly, or monthly cadences. Each scan produces a CyberScore, CVE list, and AI-generated report mapped to SOC 2, NIST CSF, ISO 27001, GDPR, and NIST 800-53. Delta email alerts notify your team of score regressions and new exposures.
Which compliance frameworks are supported?
The GRC platform supports 15+ frameworks and regulations including NIST AI RMF, NIST CSF 2.0, SOC 2 Type II, ISO 27001:2022, FedRAMP, PCI DSS, CIS Controls, TexRAMP, CMMC, GDPR, EU AI Act, CCPA/CPRA, CIPA, EU Cookie Law, and UK PECR.
What is AI Regulation Discovery?
AI Regulation Discovery translates any regulation, statute, or framework into structured trackable requirements with suggested control mappings. Compliance status is derived automatically from your existing audit control ratings where controls already cover the obligation.
Can one audit control satisfy multiple frameworks?
Yes. Audit control mapping derives compliance status from your control ratings automatically. A single well-rated control can satisfy overlapping requirements across GDPR, EU AI Act, NIST CSF 2.0, ISO 27001, and internal audit frameworks simultaneously.
What reports does the GRC platform generate?
The platform generates board-ready risk, gap, and compliance narratives with AI-assisted PDF export. These include actionable executive summaries for leadership, detailed manager reports for remediation teams, and granular technical reports for engineers and auditors.
How do I access the GRC platform?
Visit audit.cynoculist.com to sign in if you have credentials, or contact us through the contact page to request portal access and a demo.
Proprietary Product

Aether: Autonomous SOC Platform

Autonomous security operations across AWS, GCP, Azure, and Wazuh, with under-15-second triage and one-click compliance reports.

What is Aether?
Aether (aethersoc.online) is our proprietary autonomous SOC platform. It triages, enriches, and escalates every security alert in under 15 seconds, so your team spends time on real threats, not noise. It cuts alert noise by roughly 94% and delivers mean-time-to-respond up to 10x faster than a manual SOC. No additional headcount required.
Which cloud and SIEM platforms does Aether connect to?
Aether connects natively to AWS GuardDuty, GCP Security Command Center, Azure Sentinel, and Wazuh SIEM via native connectors and webhooks. It also provides a generic webhook for any custom alert source. No custom scripts or ongoing maintenance required.
How fast does Aether triage security alerts?
Aether triages every incoming alert in under 15 seconds. Each alert is automatically classified, severity-scored, and false-positive rated. Only high-confidence true positives reach your analysts, complete with full context, evidence, and a recommended action.
How does Aether enrich security alerts?
Aether queries threat intelligence, IP reputation, and internet exposure data the moment an alert arrives, so analysts see full threat context instantly rather than after 20 minutes of manual lookups. This enrichment is fully automatic and requires no configuration.
Does Aether generate compliance reports?
Yes. Aether generates audit-ready evidence packages for SOC 2, ISO 27001, and NIST with one click. The platform tracks the full incident lifecycle, captures MITRE ATT&CK techniques, and maintains a complete case history for auditors.
How does Aether's role-based access control work?
Aether uses a five-tier RBAC model: CISO/Platform Admin (org-wide visibility and control), Team Lead (full access plus escalation authority), Analyst (triage, cases, and report generation), Auditor (read-only access for compliance reviews), and Viewer (read-only). Every action is logged in a full audit trail.
How do I get started with Aether?
Visit aethersoc.online to sign up or read the documentation. No setup fees, multi-cloud ready on day one, and SOC 2-compliant infrastructure. You can also contact the Cynoculist team at cynoculist.com/contact if you need a guided onboarding.
Services & Pricing

Services & Pricing

Cynoculist service tiers, AI security services, and how proprietary products integrate with consulting engagements.

What service tiers does Cynoculist offer?
Cynoculist offers four service tiers: Basic (AI-powered MDR, DASTA-AI 30 scans/month, quarterly assessments), Advanced (24/7 monitoring, vulnerability management, DASTA-AI 30 scans/month), Premium (comprehensive security program, DASTA-AI 300 scans/month, GRC platform access), and Exclusive (full AI security program, unlimited DASTA-AI scans with BYOK, Aether SOC access, dedicated support). All tiers run on the same scan engine; they differ by quota and feature depth.
What is AI Security and Risk Assessment?
AI Security and Risk Assessment is a service where we identify, evaluate, and mitigate AI-specific risks in your organization. This includes reviewing AI systems for security vulnerabilities, assessing governance and compliance gaps against NIST AI RMF, and producing a prioritized remediation roadmap. It is powered by our proprietary GRC platform.
What is AI Model Red Teaming?
AI Model Red Teaming is adversarial security testing of your AI models and LLM-integrated applications. We attempt to elicit harmful outputs, bypass safety guardrails, extract sensitive training data, and exploit prompt injection vulnerabilities, then provide a detailed findings report and hardening recommendations.
What is AI Governance and NIST AI RMF compliance?
We establish formal AI Governance programs aligned to the NIST AI Risk Management Framework (AI RMF). This includes building AI policy frameworks, implementing risk controls mapped to NIST AI RMF functions (Govern, Map, Measure, Manage), and configuring the GRC platform to track and report compliance status on an ongoing basis.
Is DASTA-AI included in Cynoculist service plans?
Yes. DASTA-AI is bundled into all Cynoculist service plans. Basic and Advanced plans include 30 scans/month (Personal tier), Premium plans include 300 scans/month (Pro tier), and Exclusive plans include unlimited scans with BYOK (Enterprise tier). All bundled plans include all three scan policies: OWASP Top 10, CWE Top 25, and OWASP LLM Top 10.

Still have questions?

Our team is happy to walk through your specific requirements for DASTA-AI, the GRC platform, Aether, or any of our consulting services.