Run our scanner on us
The fastest way to judge a security tool is to point it at the vendor. Same checker, same grading, no special case for our own domain.
Grade neoshieldsecurity.com →NeoShield Quantum X
Assess authorized websites, investigate suspicious messages, review code and configurations, and turn potential findings into prioritized, reviewable actions without building a full security operations team.
A privacy-conscious, AI-assisted cybersecurity workspace for developers, MSPs, and lean security teams.
Illustrative example only. This is not a real scan, customer result, or security certification. View all sample reports
One HTTP request against your public response headers. No account, no credit card, result in seconds.
Reads publicly visible response headers only, the same information your browser receives. No login, port scan, or intrusive request is performed.
Verifiable, not claimed
Security tooling should not ask for faith. Every statement here links to something you can read, test, or run yourself — including running our scanner against us.
The fastest way to judge a security tool is to point it at the vendor. Same checker, same grading, no special case for our own domain.
Grade neoshieldsecurity.com →Full sample reports, clearly labelled as samples. Read the finding detail, the evidence, and the remediation steps with no account.
View sample reports →Findings may reference MITRE ATT&CK, OWASP, CWE, and NIST guidance. AI assists the analysis; the evidence is shown so you can disagree with it.
Read the methodology →NeoShield provides security tooling and AI-assisted guidance. It is not a certification body, and using it does not constitute a security certification or a guarantee of compliance. Data handling, security practices, and disclosure policy →
Choose the security question you need to address. Each option opens an existing NeoShield workflow, and most are available to try free.
Review publicly observable headers, TLS, DNS, and exposed configuration, then examine prioritized findings and practical remediation guidance.
Start free → Is this email or message suspicious?Review a suspicious text, email, or direct message for phishing, impersonation, and scam indicators explained in plain language.
Start free → Could this code or configuration contain security risks?Review submitted code or configuration for potential injection, authorization, exposed-secret, and security-misconfiguration risks.
Start free → See what needs your team’s attentionReview telemetry coverage, aging devices, open incidents, alert delivery, and access risks in one organization-isolated workspace.
Team plan · 5 users included Open Team Security Center →Move from a security question to an evidence-supported, reviewable next step.
Submit an authorized website, message, code sample, configuration, or defensive-security question.
Review prioritized findings with supporting evidence, plain-language context, and applicable security references.
Use remediation, containment, reviewable patch, or investigation guidance as a starting point for informed action.
Build repeatable security practices through reports, shared workflows, and practical learning resources.
Security questions often arrive before a small team has dedicated security staff.
Surface potential risks earlier and organize reviewable evidence for technical, management, and customer discussions.
Alerts, suspicious messages, and security questions compete with everyday operational work.
Triage potential issues and prepare clear, structured findings for technical and management review.
Consistent assessments and clear reports can be difficult to produce across multiple engagements.
Use repeatable defensive checks and structured results to support client-facing recommendations.
Choose a workflow based on the outcome you need. Free access includes core tools, while fixed-term paid plans provide higher allowances and additional modules.
Check an authorized website, review code and infrastructure configuration, and prepare reviewable patch suggestions.
Review suspicious messages, email indicators, unusual patterns, and possible identity exposure with explainable reasoning presented for human review.
Work through an incident using a structured process and prepare a clear record for relevant stakeholders.
Bring posture, incidents, device information, and seat management into an organization-isolated workspace.
Identify potentially quantum-vulnerable cryptography and organize a phased post-quantum migration plan aligned with applicable NIST guidance.
Build practical defensive-security skills and review current CVE and CISA KEV information.
Control self-assessment
36 automated technical controls tested against the live production system — not a questionnaire — each mapped to SOC 2 Trust Services Criteria and ISO/IEC 27001:2022 Annex A.
We publish the failures too. A scorecard that never fails is not measuring anything.
Result from July 21, 2026. Checks run on a schedule; this is the most recent completed assessment.
This is a self-assessment against recognised control frameworks — not a certification audit. We do not hold SOC 2 or ISO 27001 certification and do not imply it.
Data handling
Stated per input type, not as a general assurance. Each row is the same commitment published on our trust and privacy pages.
| What you submit | What we do with it | Where it goes |
|---|---|---|
| Offline tool input | Processed in memory and discarded. Never written to disk. | Stays on our server |
| AI-assisted analysis | Only the content needed for the request is sent — without your email or IP. | Anthropic |
| Quantum Vault payloads | Encrypted. No plaintext at rest. | Encrypted store |
| Sign-in | No passwords. A single-use email code, stored only as a salted hash. | Our database |
| Card details | Never touch our server. | Stripe |
| Account record | Your email address, plus sign-in metadata needed to operate the account. Contact us to export or delete it. | Our database |
| Payment reconciliation | Retained for accounting. Processed-session IDs are capped at the most recent 500. | Our database |
Sub-processors: Anthropic (AI features), Stripe (payments), Google. We do not sell data and do not run third-party trackers by default. Operating principle: we assume breach and minimise what we retain.
Human oversight
NeoShield supports authorized defensive analysis and more informed security decisions. It can help streamline investigation, but it cannot guarantee that a system is secure.
AI-assisted results can be incomplete, inaccurate, or unsuitable for a particular environment. Review the evidence, recommendations, and potential impact before acting. Human judgment remains essential, and you remain responsible for your decisions. AI-generated code is not executed automatically on NeoShield servers.
Displayed prices include applicable tax. Paid access is prepaid for the stated fixed term, with no automatic renewal.
Free
¥0 Core security-tool access with no credit card requiredPro
¥1,980 for 30 days of Pro access, including tax. No automatic renewal.Team
¥7,980 for 30 days of Team access, including tax. Five users included.NeoShield Quantum X is an AI-assisted defensive security workspace for developers, small SaaS teams, MSPs, and lean IT or security teams. It brings website assessment, suspicious-message analysis, code and configuration review, incident-response guidance, threat intelligence, post-quantum readiness, and practical security tools into one service.
Core defensive tools and limited use of selected AI-assisted features are available without a credit card. Pro and Team plans provide higher allowances and additional modules. Available features and limits are shown on the pricing page.
Processing depends on the tool. Some analyzers process submitted information in memory without retaining it, while selected AI-assisted tools send the material you submit to the configured AI provider for that analysis. Review the processing notice presented by the relevant tool before submitting sensitive information.
NeoShield treats model output as untrusted data. AI-generated code is not executed automatically on NeoShield servers. Generated tool specifications are reviewed, and server-side operations are limited to approved mechanisms documented by NeoShield.
The scanner is designed to perform non-invasive checks of publicly observable information such as headers, TLS, DNS, metadata, and exposed configuration. It does not intentionally exploit, brute-force, or flood a target. Use it only on systems you own or are explicitly authorized to assess.
Paid access ends after the fixed period shown at purchase. The account returns to the Free plan unless you choose to purchase another pass. Eligible account data remains available according to the retention policy, while paid features and Team workspace access become unavailable without an active pass.
Choose a free tool, review the evidence and explainable result, then decide the next step. No credit card is required for core free access.
Use NeoShield only for authorized defensive work. Review AI-assisted findings, evidence, and recommendations before acting.