Piscium SecurityPISCIUMSECURITY
Piscium Radius

Radius attacks the path, proves it, and proves the fix.

Autonomous attack-path validation across IT, cloud and OT/ICS. Every finding ships with the chain that produced it, the change that collapses the most paths, and a re-attack the moment the fix lands.

Nine documents per run

Three reports (executive, technical, compliance), each at three levels: the whole run, a single asset, or a single finding.

A safety trail for every action

What was attempted, what was decided, why, and the rules of engagement in force at that moment.

A knowledge base that compounds

Configuration as found, how things connect, what was found before, and what changed since the last run.

Observe

Assets, services, identities and dependencies, including what was never in the inventory. It starts passively, so nothing is written to a controller.

Radius scans management screen

Reason

The attack graph decides what to try first by where each path leads, not by severity score.

  • Every path traced to what it reaches
  • Chains that share a hop share a fix
  • MITRE ATT&CK technique mapping
Radius MITRE ATT&CK mapping screen

Attack, then validate

Radius runs the real chain against your environment, inside the rules of engagement you signed, and confirms how far it got. It stops before the destructive payload. Every action is logged with the decision and the rules in force at that moment.

Real chain
The method is the attack itself, not a simulation
Re-attack
The same path again, once you fix it
Radius vulnerabilities management screen
A Look Inside

See the platform in action

Real screens from the product, on demo data: discovery, autonomous testing, exposure analytics and the correlated attack graph.

Piscium dashboard showing attack-surface widgets, severity breakdown and findings trend

Roll up your whole exposure (assets, critical findings and remediation pace) on one configurable board.

Five steps, then the same path again.

Radius runs the same loop an attacker runs, and does not stop at the report. After you fix a path, it attacks that path again.

  1. 01

    Observe

    Discovers and watches the surface: assets, services, identities and dependencies, including what was never in the inventory. It starts passively, so nothing is written to a controller.

  2. 02

    Reason

    Builds the attack graph and decides what to try first, by where each path leads, not by severity score.

  3. 03

    Attack

    Runs the real chain against your environment, inside the rules of engagement you signed. It does not simulate it.

  4. 04

    Validate

    Confirms whether the path worked and how far it got. Stops before the destructive payload. Every action logged.

  5. 05

    Report

    Delivers reproducible evidence, the fix and the priority in three reports, each at three levels. After you fix it, attacks the same path again.

Safe enough for OT/ICS, so safe anywhere.

The controls were built for hardware you cannot reboot. They apply unchanged to a bank or a hospital.

  • Passive discovery by default: no packet reaches a controller unless you authorize it, asset by asset
  • No writes to controllers, and the attack stops at the point before impact
  • Rules of engagement you sign, enforced by the engine before every action, with a stop button that works mid-run
  • Autonomous testing aligned with the OWASP Autonomous Penetration Testing Standard (APTS)
Industrial infrastructure with piping and sensors

Output your auditor can use

A run is only as useful as what survives it. Every run produces three reports (executive, technical, compliance), each at three levels: the whole run, a single asset, or a single finding. That is nine documents, so nobody has to reinterpret someone else's.

The whole runA single assetA single finding

Executive

What was exposed and what changed after remediation. Written for people who do not run the tooling.

Technical

The validated paths, hop by hop, with the command, the timestamp and the evidence captured at each step.

Compliance

The run as control evidence: what was tested, when, under whose authorization, and with what outcome.

Alongside them: the safety trail

Every action an agent attempted, the decision taken on it, the reason, and a snapshot of the rules of engagement in force at that moment.

How you buy it

Pay for what you use. Start with a single scoped run (fixed scope, fixed price, re-validation included) or run Radius continuously. You supply the AI model key, or we do. The scope is the same and only the price differs.

  • A single run: fixed scope, fixed price, re-validation included
  • Continuous coverage: the run is credited if you continue inside the re-validation window
  • Your AI model key or ours: same scope, different price

Frequently Asked Questions

How does Radius differ from a vulnerability scanner?
A scanner lists flaws. Radius attacks them. It builds the attack graph, runs the real chain against your environment inside the rules you signed, and reports how far it got, so a finding is a proven path rather than a possible one.
Is Radius safe to run against production?
Radius observes passively by default and writes nothing to a controller unless you authorize it, asset by asset. The rules of engagement you sign are enforced by the engine before every action. The attack stops before the destructive payload, and every decision is logged with the rules in force at that moment. See the testing safety posture for the full model.
Does it simulate attacks?
It does not. Radius runs the real attack chain against your environment, inside the rules of engagement you signed, and stops before the destructive payload. What you see in the demo environment is demo data. The method itself is the real attack.
What standard does Radius follow?
Autonomous discovery and validation follow the OWASP Autonomous Penetration Testing Standard (APTS), operating within boundaries you define. Findings are mapped to MITRE ATT&CK techniques, and the compliance report can feed your own audit process. Piscium does not issue regulatory attestations and holds no certifications yet; SOC 2 and ISO 27001 are on the roadmap.
How long does a run take?
Two to four weeks, depending on asset count and whether OT zones are in scope. It starts with a 30-minute call and the rules of engagement are signed before anything runs. Critical findings are communicated the moment they are validated, not at the end.

Start with one run.

A scoped run against the environment you authorize. It starts with a 30-minute call. The rules of engagement are signed before the run does.

Scope a run