Real security isn't a one-time check. It's an ongoing picture of where your business stands.
Most businesses find out about a cyberattack only after the damage is done — customer data stolen, systems locked, or money lost. UltraViolet checks your business regularly, so you always know exactly where you stand.
The goal: measurable risk reduction, sustained over time.
Attackers don't work on a yearly schedule
Once-a-year audit
Like checking your locks once a year and hoping for the best. By the time the next audit comes around, months of new exposure have gone unwatched.
UltraViolet, monthly
Your business is scanned every month, not once a year — so new exposure gets caught in weeks, not sitting unnoticed until your next annual check.
Monthly is our standard cadence. If a regulatory requirement — PCI DSS, SOC 2, ISO 27001, or an insurer or client mandate — calls for more frequent scanning, we can customize the schedule. Talk to us about your specific requirement.
The business case, in plain terms
Keep your customers' trust
One data breach can undo years of hard work. We find the weak spots before attackers do, and tell you exactly how to fix them.
Stay open for business
A cyberattack can shut your business down for days or weeks. Catching threats early means less disruption, less cost, and faster recovery.
Meet your legal obligations
Data protection laws require businesses to protect customer data. UltraViolet gives you the proof you need to show regulators and clients that you take security seriously.
Enterprise-grade coverage, without the overhead
Get human-validated analysis and clear remediation guidance without the cost and complexity of hiring an in-house security team. One predictable monthly fee.
What happens after you sign up
Monthly security assessment of your business
We check your critical systems for any weaknesses an attacker could use to get in.
We monitor attacker markets and forums
Where stolen business information is bought and sold. If your staff emails, passwords, or sensitive company data are being traded online, we find it and alert you before it's used against you.
You get a regular report on exactly where you stand
No technical jargon — just the risks that matter and what to do about them.
You are not alone
When something needs attention, we're right there with you with a clear action plan so you and your team know exactly what to do next.
No hidden fees. No setup fee. Cancel with 30 days' notice.
Vulnerability scanners are everywhere, at every price point — and most are good at what they do. The problem is what they hand you: a list of findings and technical jargon, then leave you to work out which ones actually matter. UltraViolet runs every finding through AI-powered analysis, validates it with a human analyst, and explains it in plain English, with a prioritized list of what to fix first.
Scan & Report
What you get
- ✓ External attack surface scanning — exposed ports and services, SSL/TLS issues, and known vulnerabilities
- ✓ Subdomain and asset discovery
- ✓ Credential leak detection
- ✓ Email security checks (SPF, DMARC, DKIM)
- ✓ Monthly PDF report
- ✓ AI analysis with exploitability assessment
Scan frequency: monthly
Get startedMonitoring & Guidance
Everything in Scan & Report, plus:
- ✓ Human analyst validation of findings
- ✓ Ransomware threat intelligence for your industry
- ✓ Plain-English risk explanation
- ✓ Prioritized remediation roadmap
- ✓ Remediation verification re-scan
- ✓ Monthly 30-minute walkthrough call
- ✓ Dashboard access
- ✓ Vulnerability management — accept, remediate, and track lifecycle across your infrastructure
- ✓ Security health score tracking
Additional domains are ₱2,500/month each on any plan. All prices exclusive of 12% VAT; corporate clients: 2% expanded withholding tax applies.
Which plan fits your business?
Scan & Report — you have internal IT capability and want the data. You'll interpret the findings and act on them yourself. Delivered as a monthly report; monitoring without the interpretation layer.
Monitoring & Guidance — you have no dedicated security staff, or your IT is a generalist or outsourced provider. You need someone to tell you what matters, why, and what to do first. This is where most of our clients sit.
Larger or regulated environments — multiple domains, a board reporting requirement, or an insurer or enterprise customer asking questions — usually need something scoped rather than picked off a list. Talk to us and we'll build it around what you actually have to satisfy.
What we do — and what we don't
We identify issues, explain them, tell you how to fix them, and then verify the fix worked. We don't log into your systems or apply changes ourselves — your team or your IT provider does that, and keeps control of your environment. What you get from us is the part that's hard to buy elsewhere: knowing what to fix, and independent confirmation that it's actually fixed.
Findings stay open in your dashboard and reports until a verification re-scan confirms closure. Nothing gets marked resolved because someone said it was.
What's included in Scan & Report vs. Monitoring & Guidance
What people ask before signing up
We already have a firewall and antivirus. Why do we need this?
Both are essential, and both protect the perimeter and the endpoint. Neither tells you that a forgotten subdomain is running an unpatched application, that your finance manager's password appeared in a breach dump last month, or that a ransomware group is currently targeting your industry. Those are the things we look for — outside your perimeter, where your firewall doesn't reach.
How is this different from a cheaper scanning tool?
Scanning is a commodity and we don't pretend otherwise. The difference is what happens after the scan. A scanner gives you ninety findings ranked by severity score. We tell you which four you should fix this month, why those four, what happens if you don't, and how to fix them. If you have a security analyst on staff who can do that interpretation, a cheaper tool is the right choice.
Can we get more frequent scanning than monthly?
Monthly is our standard cadence on both plans. Some businesses need more — a specific regulatory framework (PCI DSS, SOC 2, ISO 27001), an insurer's requirement, or a client's vendor security questionnaire that calls for continuous or weekly external scanning. We can scope a custom cadence for those cases, priced separately from the standard plans.
Tell us what you need to satisfy and we'll quote it against your actual requirement, rather than a generic upsell.
Do you fix the issues, or just tell us about them?
We tell you what to fix, in what order, and how — then we verify it worked. We don't apply changes to your systems ourselves. That's deliberate: fixes belong with whoever is accountable for your environment, and handing production access to an outside monitoring provider adds risk rather than removing it. If you have an IT provider, we work alongside them and give them findings they can act on directly. If you don't, we'll walk your team through each fix.
Where we do add value after the fix is verification. You tell us it's remediated, we re-scan and confirm — and if it isn't actually closed, we say so. In our experience a meaningful share of "fixed" findings aren't, usually because a change was applied to one host and not the other three running the same service.
Do you need access to our network?
No, not for monitoring. All monitoring plans are entirely external — we assess what an attacker can see from the internet, using only your domain name. Nothing is installed and no access is granted. The one-time assessment does include internal scanning, which requires a virtual machine inside your network, provisioned by you.
Is scanning our systems legal?
Yes, with your written authorization, which we require before any scanning begins. Unauthorized scanning would be an offence under the Cybercrime Prevention Act (RA 10175), which is exactly why the authorization letter is non-negotiable on our side.
What happens to our data?
Findings are stored on infrastructure in Singapore and retained for 12 months, giving you a full year of history for trend reporting and audit purposes. Generated PDF reports are removed from our servers after 90 days — download and keep any you need for your own records. On termination, we delete your data within 30 days on request. We handle your data as a personal information processor under the Data Privacy Act (RA 10173), and a data processing agreement is part of every contract. We don't sell, share, or use your data to train anything.
What's the commitment?
Monthly plans are month-to-month with 30 days' notice. Annual plans are 12 months and include two months free. No setup fee on any plan.
Can we start small and move up?
Yes, and many clients do. You can upgrade at any time, prorated. Downgrades take effect at the end of your current term. Most clients who start on Scan & Report move to Monitoring & Guidance within a few months, usually after receiving a report they'd rather have explained to them.
Every engagement starts with a free external snapshot.
We scan your primary domain and walk you through what we find — no cost, no obligation. It takes about 48 hours and tells you more about your exposure than any sales call will.