Evidence tier Source Confirmed · 4 captures on record
What the publisher says
As described on AWS Marketplace.
CYTRIX is an automated pentesting platform scanning for web applications, APIs and cloud, leveraging a database of over 30,000 vulnerabilities. With the ability to scan any asset with no integration and create immediate value. CYTRIX has a unique understanding and way of analyzing digital assets security posture providing new insights and recommendations that will generate huge value for your organisation.
We develop all our technologies in-house. We are not using third party technologies, building our own proprietary AI and our own automated pentest solution.
Show the rest of the publisher’s description (2 more lines)
CYTRIX developed our solution in micro services in order to enable easy integration in all levels, giving any partner flexibility to grow with our solution.
As a company CYTRIX is an innovative, high-growth cybersecurity company providing a critical security solution in an era of increasing cyber threats. With its proven technology, strong leadership, and scalable business model, CYTRIX is well-positioned for success in the global cybersecurity market.
Highlights
Highlighted by the publisher on AWS Marketplace.
AI technology - the way it is built allows the implementation of AI on top of the real-time explanation technology. Remediation Chaning Login AI Form & endpoint detection Flutter support Browser usage - SPA full support, exploitation with browser, work with Recaptcha (google/cloudflare etc), nobody will block chrome usage. Work with CSRF Tokens. APi security - Postman/Swagger/HAR file/GraphQL - fully support graphQL vulnerabilities and introspection (build schema)
Full-login authentication - which allows the system to authenticate to any type of system, regardless of the type of login, - which allows us to check 99.9% of the property. Real-time exploitation technology - which allows the system to write the exploits in real time according to the type of site and the technologies embedded in it - which allows us to find weaknesses that others do not find.
Agent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Vendor
External enrichment
Plans and pricing as listed
9 listed- Units
- Units
- Units
- Units
- Units
- Units
- Units
- Units
- Units
Refund terms
As stated by the publisher on AWS Marketplace.
Our refund policy is easily accessible on the product detail page, our EULA contract and during the purchase process.
Sources
Publisher resources
3 linksLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

