Free diagnostic · no signup

Most SMB websites have a flaw. Does yours?

Find your security score in 5 seconds: your flaws, how serious they are, and how to fix them. Free, no jargon — you don't need to be technical.

3 free checks per hour · 100% non-intrusive · no data collected

Non-intrusive scan
Instant result
No signup
Data hosted in Europe
Who is it for?

Two ways to use CyberTool.

Whether you manage 50 sites for clients or just your own, the same cyber team has your back. Pricing scales — the service doesn't.

Cyber agencies · IT freelancers · MSPs

I manage other people's sites

You're responsible for the security of several SMBs.

You're a cyber consultant, IT freelancer, or digital agency hosting client sites. Your clients rely on you — and need proof that everything is fine.

  • All your clients on one screen
  • PDF reports with your logo and brand
  • You set your prices, you keep the margin
  • 12 AI teammates working 24/7 in your stead
  • We never contact your clients — you remain the only point of contact
SMB · small business · e-commerce

I manage my own site

You want to know if your site is safe, without paying for a £5,000 audit.

You're a leader, IT lead, or simply the person looking after the site. You want certainty about security — not impenetrable jargon.

  • Your cyber team, no hiring, no contract
  • A score out of 100, refreshed every day
  • Plain-language alerts, with what to do and who to call
  • Audit-ready for GDPR and contracts with large clients
  • Set up in 2 minutes, nothing to install
Sovereignty · transparency

A French service, hosted at home. Your data doesn't fly over to Uncle Sam.

You shouldn't have to choose between site security and data privacy. CyberTool is designed in France, hosted in Europe, and contractually committed to never exploiting your information.

Your data stays in Europe

Everything is stored in Frankfurt and Paris. Your data never leaves the European Union under normal operations.

French company

French team, French law contract, French-language support. No offshore hotline, no support that never picks up.

GDPR-compliant, zero tracking

No advertising cookie, no Google or Facebook pixel, no tracking. Your data is never sold to anyone.

End-to-end encryption

Everything is encrypted in transit (TLS 1.3) and at rest (AES-256). Your passwords are protected by the strongest standards.

Aligned with official standards

Checks aligned with the CNIL, ANSSI (the French cybersecurity agency) and NIS2 (the new European standard). Data processing agreement available for agencies.

Take your data back whenever you want

Full export in one click, permanent deletion on cancellation. No hostage-taking, no commercial lock-in.

Our written commitments
Respectful scanning

Our scanner identifies itself publicly, respects your rules (robots.txt) and rate-limits its requests. We never touch a site unless you've declared the domain.

No reselling, ever

Your scans, alerts and logs are neither sold nor shared with third parties. We charge you for a service, full stop. That's our entire business model.

Each client's data isolated

Each client is isolated in the database. It's technically impossible for one client to see another's data — locked down at the engine level.

Leave whenever you want

On cancellation, you get everything back as CSV or JSON. 90-day retention if you change your mind, then it's permanently deleted.

No reselling · No ads · No tracking · No offshore call centre · No US cloud.

What you get

Your site's security, finally understandable.

Not yet another scanner spitting out jargon. A clear score, real priorities, and a team that keeps watch — whether you manage your own site or your clients'.

💬

In plain language, not jargon

Every flaw explained simply, with the real risk for your business and the exact fix to apply.

🛡️

We watch while you work

New flaws appear every day. We monitor 24/7 and alert you before your clients do.

🇪🇺

Sovereign and compliant

Hosted in Europe, GDPR and NIS2. Your data never leaves the continent.

Comment ça marche

Branché en moins de 2 minutes.

01

Vous tapez votre adresse

Juste le nom de votre site (ex : monsite.fr). Pas d'installation, pas d'accès admin à donner. Vraiment rien à faire.

02

On surveille tout, jour et nuit

Cadenas, protections, emails, listes noires, failles WordPress — nos vérifs tournent chaque jour, sans déranger votre site.

03

Vous êtes prévenu si ça cloche

Email pour les petits trucs, SMS pour les urgences. Chaque alerte vous dit en clair quoi faire et qui appeler.

Product preview

The dashboard, for real.

One page to see your clients, who's working and what's blocked. No marketing mock-up — this is the screen you use every day.

Your whole team on one screen

The 12 AI teammates, what they're doing live, their open alerts and scores. All on a single page.

Urgencies at the top, sorted

Attack attempts, critical flaws, exposed files — every issue surfaces with severity and the exact fix.

Audit-ready

Security score across your whole portfolio, GDPR and ANSSI compliance, white-label PDF reports for your clients or the regulator.

Delegate in a single sentence

You speak to Sofia, she dispatches to the right teammate (Malik, Yuki, Claire…), and you get the finished work back.

Open the dashboard →
Your security team

12 AI specialists behind every audit.

Encryption, email, known flaws, data leaks… each one covers an angle. Like a full security department — without the hire. Once your monitoring is on, the same team watches your site around the clock.

Direction
Détection & Réponse
Offensive & Audit
Gouvernance
Sofia, CISO
Direction

Sofia

CISO

Votre directrice cyber virtuelle. Elle pilote la sécurité de bout en bout, priorise ce qui est vraiment urgent, et vous fournit un tableau de bord clair pour vos décisions de dirigeant — sans jargon technique.

Stratégie cyberReporting CODIRBudget sécurité
décisions/jour~40
Malik, SOC Analyst
Détection & Réponse

Malik

SOC Analyst

Votre vigile cyber 24h/24. Il surveille en permanence vos sites et serveurs, repère les comportements suspects (tentatives d'intrusion, vols de données) et bloque immédiatement ce qui est dangereux avant que ça ne vous coûte cher.

SIEMEDRMITRE ATT&CKC2 detection
menaces bloquées2 847/j
Amara, Threat Intel
Détection & Réponse

Amara

Threat Intel

Elle scrute en permanence le dark web et les forums pirates pour vous prévenir AVANT qu'une attaque ne vous touche. Si les mots de passe de vos employés ou de vos clients fuitent quelque part, elle vous alerte sous 24h.

MITRE ATT&CKIOC feedsDark webOSINT
IOC ajoutés/sem312
Noah, Incident Response
Détection & Réponse

Noah

Incident Response

Le pompier de l'équipe. Si un de vos sites se fait pirater, il intervient dans la minute pour stopper l'attaque, comprendre ce qui s'est passé, remettre tout en marche et préserver vos données — sans interruption de service prolongée.

IR playbooksForensicPost-mortemContainment
incidents clos18 en 30j
Rio, SOAR / Automation
Détection & Réponse

Rio

SOAR / Automation

Le robot qui s'occupe des tâches répétitives à votre place. Quand un même type d'incident revient, Rio le règle automatiquement : isolation du serveur, blocage de l'attaquant, notification de l'équipe — sans réveiller personne la nuit.

SOARPlaybooksWebhooksZapier
playbooks actifs24
Yuki, Pentest Web
Offensive & Audit

Yuki

Pentest Web

Il attaque volontairement vos sites comme le ferait un vrai pirate, mais avec votre accord — pour vous montrer les failles avant que quelqu'un de mal intentionné ne les exploite. Vous recevez la liste précise de ce qu'il faut corriger.

OWASP Top 10Burp SuiteAPI testingJWT
sites pentestés/mo42
Diego, Vulnerability Mgmt
Offensive & Audit

Diego

Vulnerability Mgmt

Il connaît toutes les failles de sécurité publiquement référencées et vérifie en continu si vos sites en sont victimes (WordPress, plugins, frameworks). Vous recevez la liste à corriger, classée par gravité réelle, avec les étapes pour patcher.

CVE scoringEPSSWPScanOSV
CVE suivies12 847
Claire, Audit & Compliance
Offensive & Audit

Claire

Audit & Compliance

Elle note la sécurité de chacun de vos sites sur 100, comme un contrôle technique automobile. Vous voyez immédiatement ce qui ne va pas (certificat, configuration, conformité) et la marche à suivre pour passer au vert — alignée sur les standards officiels français.

SSL/TLSHeaders HTTPANSSINIST CSF
audits/semaine18
Ethan, Cloud Security
Offensive & Audit

Ethan

Cloud Security

Il vérifie que vos serveurs hébergés sur AWS, Azure ou Google Cloud ne sont pas mal configurés : fichiers oubliés en accès public, mots de passe en clair, droits trop larges. Il vous indique précisément quelles portes refermer et comment.

IAMCSPMCIS BenchmarksSecrets mgmt
config drifts7 détectés
Julien, Legal / RGPD / NIS2
Gouvernance

Julien

Legal / RGPD / NIS2

Votre juriste numérique. Il s'assure que vous êtes en règle avec le RGPD et la loi NIS2, prépare vos documents pour la CNIL, et surveille pour vous le délai légal de 72h en cas d'incident — pour éviter les amendes qui font mal.

RGPDNIS2CNILDPA
contrôles RGPD3/sem
Priya, GRC
Gouvernance

Priya

GRC

Elle tient à jour le registre des risques de votre entreprise et celui de vos prestataires. Elle vous accompagne pour décrocher les certifications qui rassurent les grands clients (ISO 27001, SOC 2) — sans vous noyer dans les acronymes.

ISO 27001SOC 2Risk scoringTPRM
risques suivis47
Léa, Security Awareness
Gouvernance

Léa

Security Awareness

Elle forme vos équipes à reconnaître les arnaques par email (phishing). Elle envoie de faux mails piégés pour tester, puis personnalise la formation pour ceux qui se sont fait avoir — sans les juger, et avec des résultats mesurables.

Phishing simAwarenessE-learningKPI humains
clics phishing12% → 3%

Included in Agency and Enterprise plans · the same team behind your audit and your 24/7 monitoring

Pricing · no commitment

Start free. Pay when it actually protects you.

The audit is free. The subscription monitors your site continuously and guides you step by step. No commitment, cancel anytime.

Free

To see where you stand

0/mo
1 site
  • Instant audit, score out of 100
  • Preview of the main flaws
  • 1 scan
  • No signup, no card
Run the free audit

Essential

For 1 site to keep an eye on

19/mo
≈ 19 €/site
1 site
  • 1 site monitored continuously
  • Email alerts
  • Full report + history
  • Access to Sofia, your copilot
Get started

Pro

To manage several sites

49/mo
≈ 10 €/site
5 sites
  • Up to 5 monitored sites
  • Priority alerts
  • PDF report export
  • Extended history
  • "Secured by CyberTool" badge
Get started
Most popular

Agency

Protect your clients under your brand

149/mo
≈ 6 €/site
25 sitesBest price per site
  • Up to 25 client sites
  • White-label reports
  • Multi-client agency dashboard
  • Priority alerts
  • "Secured by CyberTool" badge
Get started

Enterprise

Volume, SLA, dedicated support

Custom
Unlimited sites
  • Everything in Agency, unlimited sites
  • Service-level agreement (SLA)
  • Single sign-on (SSO)
  • Audit-ready exports
  • Dedicated contact
Contact us
No subscription

One-shot full audit

Your detailed security report on the current scope (encryption, DNS, headers), delivered with no subscription.

Fully credited if you subscribe within 30 days.

€99
one-time payment
Order the audit

Coming soon to the audit

New analysis areas (application flaws, cloud, compliance) are coming and will be added automatically to your monitoring. Today, the audit covers encryption (SSL/TLS), DNS and security headers.
Known vulnerabilities (CVE, CMS)Attack surface & exposed portsData leaks & exposureCloud & configurationGDPR / NIS2 compliance

No commitment · cancel in one click · data in Europe · secure payment

Frequently asked questions

What our users ask us

Got another question? contact@cybertool.fr

  • Is it really free?
    Yes. The scan and your score are free, no signup. You only pay for continuous monitoring, when you decide to keep your site under watch.
  • Do your scans break the site?
    No, never. We browse your site like a normal visitor — no intrusion attempts, no brute force, no spam. Our scanner identifies itself clearly, respects the rules you've set (robots.txt) and makes at most 5 requests per check. All details on /bot.
  • I don't know anything about security.
    That's exactly the point. Everything is explained in plain language, with the steps to follow: the real risk, the exact fix, and how long it takes. You don't need to be technical.
  • Is my data safe? Where is it stored?
    Yes, and everything stays in Europe (servers in Germany and Paris). No data is sold, no ads, no tracking. We sign a Data Processing Agreement (DPA) with every agency client. All details on /legal/privacy.
  • What is CyberTool in one sentence?
    A French service that monitors your sites' security continuously, like a cyber team that never sleeps. You give us the address of your site, we check everything every day (SSL, email, known vulnerabilities…) and we tell you in plain language whenever there's something to fix.
  • Why an AI team rather than a classic scanner?
    A classic scanner spits out a list of jargon-laden problems. Our 12 AI teammates analyse your situation and explain: what's truly urgent, who to ask for the fix, and how long it takes. Sofia is the team lead and dispatches to the 11 specialists (a watcher, a WordPress expert, a GDPR expert, etc.). You speak to them in plain language, like colleagues.
  • How is this different from a free scanner like SSL Labs?
    SSL Labs checks one site, on demand, once. CyberTool monitors dozens of sites continuously, writes white-label reports for your clients, alerts you by email or SMS the moment something goes wrong, and explains what to do in plain language. It's the difference between a thermometer and a hospital.
  • How much does it cost?
    Free to discover your score. Then Essential €19/mo (1 site), Pro €49/mo (up to 5 sites), Agency €149/mo (up to 25 client sites, white-label — the most popular) and Enterprise custom (volume, SLA, dedicated support). Prefer a report with no subscription? The one-shot full audit is €99, credited if you subscribe within 30 days. No commitment, cancel in one click.
  • What are the "credits" in the plans?
    Credits are what you spend when you chat with the AI team (Sofia and the others). Each plan includes a generous monthly quota. If a month is busy, you can buy a booster pack (10,000, 50,000 or 200,000 credits) that never expires. No nasty surprises on the invoice.
  • I'm an SMB, not an agency. Can I still use this?
    Of course. CyberTool is built for both. On signup we ask whether you're an agency (managing several clients' sites) or an SMB (looking after just your own). The interface and pricing adapt automatically.
  • Can I try before I pay?
    Yes. On signup, you receive a free audit with no credit card and no time limit. Enough to run your first full scan and chat with the AI team. You can also visit the dashboard in demo mode at cybertool.fr/dashboard before even creating an account.
  • What happens if I exceed my monthly quota?
    At 80% of the quota, we email you. At 100%, the service keeps running in economy mode — you never go down. You can buy a booster pack at any time to instantly restore full capacity. Booster credits never evaporate; they stick around until you use them.
From the team

Our agents speak up

Every week, a new article written by one of our specialised AI agents. Plain language, no jargon, for SMB and MSP decision makers.

All articles →
Après l'audit, le suivi

Un audit, c'est une photo. La sécurité, c'est un film.

Votre site évolue, les menaces aussi. Activez le suivi continu et gardez une longueur d'avance : vos 12 agents surveillent vos sites et vous alertent avant vos clients.

Activer le suivi continu →

Hébergé en Europe · RGPD · Résiliation en 1 clic