20+ paid pilots, 100% audit pass rate

Remediate without disrupting your estate

Agentless discovery across your IT network. Nothing installed, ever.

Agentless Scanner

Agentless discovery across your IT network. Nothing installed, ever. The scan tells you what's actually running and how it's configured — not what a spreadsheet says should be there.

No agents · IT network
0

agents installed on your IT network to scan it.

20+

paid pilots scanned and remediated to date.

Five engines. One continuous loop.

Our method to elimination

Compliance-as-Code

easyPII converts regulatory text into executable infrastructure control, then acts on it. Fully agentic, end to end.

01

Regulation Parsing

Ingests regulatory frameworks using NLP and maps every obligation to a specific technical control. The resulting Compliance Knowledge Graph links each control to each live asset and re-derives control state when regulation changes.

02

Agentless Scanner

No agents · IT network

Discovers IT assets and network topology at the network layer. Nothing installed on any device, ever. Cloud-config and OT/SCADA discovery are in active development; talk to us if you need either as a design partner.

03

AI Remediation

Core IP

Our core intellectual property. Generates and deploys Ansible playbooks inside constrained action spaces, with rollback verification on every playbook. This is the step other platforms leave to your engineers.

04

Evidence Generator

Produces cryptographically signed, audit-ready evidence packs continuously, not assembled retrospectively the week before an assessment.

05

Audit Automation

Drives the certification workflow end to end, including Cyber Essentials Plus. The platform supports and evidences the process; certification stays with the accredited certifying body.

Why act now?

Regulatory obligation is expanding faster than SMEs can absorb it, and between audits you are uncovered and undocumented.

NIS2 already in force
DORA binds financial supply chains
Manual audits cost £5k–£15k
Point-in-time results decay fast
legacy solutions
100%

Audit pass rate

Every paid pilot to date has passed certification under Cyber Essentials and IASME. Detection was never the hard part; deploying and proving the fix was.

95%

Faster remediation

easyPII cuts remediation time by 95% against a manual, engineer-led fix cycle. What used to take weeks now closes in days.

£5k–£15k

Cost of one manual audit

A single certification cycle costs £5,000–£15,000 and hands you a point-in-time result that starts decaying the moment it is issued.

AI Auto remediation

Autonomous, not
unsupervised.

Constrained Action Spaces

The remediation agent operates inside a bounded set of permitted actions. It cannot invent an operation outside that set.

Rollback Verification

Every playbook is verified as reversible before it is applied.

Configurable Approval Gates

Set per control. Run fully autonomous where you're comfortable, human-in-the-loop where you're not, and move the line as trust builds.

Our core intellectual property. easyPII generates and deploys Ansible playbooks inside constrained action spaces.

This is the step other platforms leave to your engineers, with rollback verification on every playbook.

SELECT * FROM users WHERE name = ''
+ user_input + `
username="admin"; password="password123"
gets(buffer);
system("ls " + dirname);
eval(request.getParameter("code"));
strcpy(dest, src); // No bounds check
if (user.isAdmin == true)
DEBUG_MODE = true;
db.query("SELECT * FROM users WHERE name = ?",
[sanitize(user_input)])
const creds = vault.getSecret("db_admin");
fgets(buffer, sizeof(buffer), stdin);
execvp(allowList[cmd], safeArgs);
sandbox.run(compiledPolicy);
strncpy(dest, src, sizeof(dest) - 1);
if (rbac.hasRole(user, "ADMIN"))
config.set("debug", env.isDev());

How we compare

Traditional Compliance
easyPII
Propose the fixSuggested, not appliedGenerated & deployed
Deploy the fixHuman engineerAutonomous
Rollback safetyRarely verifiedEvery playbook
EvidenceAssembled retrospectivelySigned continuously
DeploymentCloud-only SaaSOn-prem connected today
JurisdictionsSeparate tool eachOne control base
Cost per cycle£5k–£15k, one frameworkFrom £3,588 / year

See it fix something.

Thirty minutes. We scan a representative environment, show you a real gap, and deploy the fix live. No slideware.

Book a 30-minute demo

In active development

OT/SCADA visibility and a fully air-gapped, zero-connectivity deployment mode are both in active design, built passive-only from day one, to meet the same safety constraints your ICS and OT engineers already work under. If your organisation needs either of these (critical infrastructure, defence, government, or anywhere a hard data-localisation mandate applies), talk to us. We're recruiting a small number of design partners to help shape both before general release.

Talk to us about OT / air-gapped deployment

Pricing

Priced against the audit you are already paying for: £5,000–£15,000 for a point-in-time result.

STARTER

£299

per month

£3,588 / year

Micro and small businesses, single framework
  • 1 compliance framework
  • Agentless scanning: IT network
  • Autonomous remediation, core playbooks
  • Cryptographically signed evidence packs
  • Compliance dashboard and reporting
  • Email support
Get started
Most Popular

PROFESSIONAL

£799

per month

£9,588 / year

SMEs with multi-framework obligations and cloud infrastructure
  • Multi-framework from one control base
  • Agentless scanning: IT network
  • Full autonomous remediation with approval gates
  • Cryptographically signed evidence packs
  • Multi-jurisdiction output: UK and EU
  • Audit evidence export and reporting API
  • Priority support
Get started

ENTERPRISE

£2,499

per month

£29,988 / year

Multi-site, regulated sectors, design-partner OT roadmap
  • Unlimited frameworks, including Gulf
  • Agentless scanning: IT network
  • Full autonomous remediation, custom action spaces
  • Cryptographically signed evidence packs
  • Multi-jurisdiction output: UK, EU and GCC
  • Multi-tenant management and white-label
  • Named customer success manager and SLA
Contact sales
The comparison that matters

Against a manual audit cycle.

Manual / consultant-ledeasyPII
Cost per cycle£5,000–£15,000, one frameworkFrom £3,588 per year, continuous
CoveragePoint-in-time, decays immediatelyContinuous
RemediationBacklog handed to your engineersGenerated and deployed
EvidenceAssembled before the assessmentSigned as it is produced
Second frameworkA second engagementSame control base
Second jurisdictionA second consultantSame control base

Manual baseline reflects typical UK SME certification cycle costs across Cyber Essentials and ISO 27001 engagements. Your figure will vary with estate size and framework scope; we will work it through with you on the call rather than quote you a percentage.

Pricing questions

Setup and any variable usage are quoted separately from the subscription. We will set both out in writing before you commit.

Yes. Expansion is the normal path: customers typically add assets, then a second framework, then a second jurisdiction. Because everything derives from the same control base, moving up does not mean reimplementing.

Yes, on the Enterprise tier, with multi-tenant management and revenue share. Compliance work you currently deliver as chargeable manual labour becomes a platform you deliver at margin.

UAE PDPL and Saudi PDPL output is included at Enterprise. Because roughly 75% of controls overlap with UK GDPR, adding a Gulf jurisdiction is a mapping exercise against controls we already scan rather than a separate product.

No. easyPII supports and evidences those processes: surfacing the processing inventory, tracking DPIA status and generating the evidence trail. Lawful basis determination and DSAR decisions are expert judgements your organisation makes.