Agentless discovery across your IT network. Nothing installed, ever.
Agentless discovery across your IT network. Nothing installed, ever. The scan tells you what's actually running and how it's configured — not what a spreadsheet says should be there.
No agents · IT networkagents installed on your IT network to scan it.
paid pilots scanned and remediated to date.
Five engines. One continuous loop.
easyPII converts regulatory text into executable infrastructure control, then acts on it. Fully agentic, end to end.
Ingests regulatory frameworks using NLP and maps every obligation to a specific technical control. The resulting Compliance Knowledge Graph links each control to each live asset and re-derives control state when regulation changes.
Discovers IT assets and network topology at the network layer. Nothing installed on any device, ever. Cloud-config and OT/SCADA discovery are in active development; talk to us if you need either as a design partner.
Our core intellectual property. Generates and deploys Ansible playbooks inside constrained action spaces, with rollback verification on every playbook. This is the step other platforms leave to your engineers.
Produces cryptographically signed, audit-ready evidence packs continuously, not assembled retrospectively the week before an assessment.
Drives the certification workflow end to end, including Cyber Essentials Plus. The platform supports and evidences the process; certification stays with the accredited certifying body.
Regulatory obligation is expanding faster than SMEs can absorb it, and between audits you are uncovered and undocumented.
Every paid pilot to date has passed certification under Cyber Essentials and IASME. Detection was never the hard part; deploying and proving the fix was.
easyPII cuts remediation time by 95% against a manual, engineer-led fix cycle. What used to take weeks now closes in days.
A single certification cycle costs £5,000–£15,000 and hands you a point-in-time result that starts decaying the moment it is issued.
The remediation agent operates inside a bounded set of permitted actions. It cannot invent an operation outside that set.
Every playbook is verified as reversible before it is applied.
Set per control. Run fully autonomous where you're comfortable, human-in-the-loop where you're not, and move the line as trust builds.
Our core intellectual property. easyPII generates and deploys Ansible playbooks inside constrained action spaces.
This is the step other platforms leave to your engineers, with rollback verification on every playbook.
SELECT * FROM users WHERE name = ''+ user_input + `username="admin"; password="password123"gets(buffer);system("ls " + dirname);eval(request.getParameter("code"));strcpy(dest, src); // No bounds checkif (user.isAdmin == true)DEBUG_MODE = true;
db.query("SELECT * FROM users WHERE name = ?",[sanitize(user_input)])const creds = vault.getSecret("db_admin");fgets(buffer, sizeof(buffer), stdin);execvp(allowList[cmd], safeArgs);sandbox.run(compiledPolicy);strncpy(dest, src, sizeof(dest) - 1);if (rbac.hasRole(user, "ADMIN"))config.set("debug", env.isDev());
| Traditional Compliance | easyPII | |
|---|---|---|
| Propose the fix | Suggested, not applied | Generated & deployed |
| Deploy the fix | Human engineer | Autonomous |
| Rollback safety | Rarely verified | Every playbook |
| Evidence | Assembled retrospectively | Signed continuously |
| Deployment | Cloud-only SaaS | On-prem connected today |
| Jurisdictions | Separate tool each | One control base |
| Cost per cycle | £5k–£15k, one framework | From £3,588 / year |
Thirty minutes. We scan a representative environment, show you a real gap, and deploy the fix live. No slideware.
OT/SCADA visibility and a fully air-gapped, zero-connectivity deployment mode are both in active design, built passive-only from day one, to meet the same safety constraints your ICS and OT engineers already work under. If your organisation needs either of these (critical infrastructure, defence, government, or anywhere a hard data-localisation mandate applies), talk to us. We're recruiting a small number of design partners to help shape both before general release.
Talk to us about OT / air-gapped deploymentPriced against the audit you are already paying for: £5,000–£15,000 for a point-in-time result.
STARTER
£3,588 / year
PROFESSIONAL
£9,588 / year
ENTERPRISE
£29,988 / year
| Manual / consultant-led | easyPII | |
|---|---|---|
| Cost per cycle | £5,000–£15,000, one framework | From £3,588 per year, continuous |
| Coverage | Point-in-time, decays immediately | Continuous |
| Remediation | Backlog handed to your engineers | Generated and deployed |
| Evidence | Assembled before the assessment | Signed as it is produced |
| Second framework | A second engagement | Same control base |
| Second jurisdiction | A second consultant | Same control base |
Manual baseline reflects typical UK SME certification cycle costs across Cyber Essentials and ISO 27001 engagements. Your figure will vary with estate size and framework scope; we will work it through with you on the call rather than quote you a percentage.
Setup and any variable usage are quoted separately from the subscription. We will set both out in writing before you commit.
Yes. Expansion is the normal path: customers typically add assets, then a second framework, then a second jurisdiction. Because everything derives from the same control base, moving up does not mean reimplementing.
Yes, on the Enterprise tier, with multi-tenant management and revenue share. Compliance work you currently deliver as chargeable manual labour becomes a platform you deliver at margin.
UAE PDPL and Saudi PDPL output is included at Enterprise. Because roughly 75% of controls overlap with UK GDPR, adding a Gulf jurisdiction is a mapping exercise against controls we already scan rather than a separate product.
No. easyPII supports and evidences those processes: surfacing the processing inventory, tracking DPIA status and generating the evidence trail. Lawful basis determination and DSAR decisions are expert judgements your organisation makes.
Insights on PII protection, compliance frameworks, and building security into your stack from the ground up.
Personally identifiable information is everywhere in your stack. Understanding what counts as PII, and the real cost of exposing it, is the first step toward building a defensible business.
Post-Brexit, UK businesses must navigate two overlapping data protection regimes. Here's a clear-eyed look at where they converge, where they diverge, and what it means for your compliance strategy.
Annual penetration tests catch point-in-time vulnerabilities. Continuous automated scanning catches everything in between. Here's why the shift matters and how to implement it without alert fatigue.