Run the programme
yourself.
Dispatch is a self-hosted platform your own team operates — external attack surface, OSINT, scheduled vulnerability scanning and security reviews — keeping a living record of your estate between every run. The same platform professionals deliver with, not a lite version.
Pay premium rates
Gamble on who shows up.
Call it what it is: the consultancy lottery. Booking a consultancy for every scan means no consistency in scoping, pricing or methodology — the outcome and the consultant both vary. And because that cost is priced by the day and by the asset, your security spend rises in lockstep with your size. The routine majority of the programme — the part your own team could own — stays trapped in a vendor.
The work your team
can already do.
The routine security programme is yours to run — on your schedule, not a vendor's.
Own the routine programme
External attack surface, OSINT, vulnerability scanning and security reviews — run with the same tools a good operator would, auto-parsed into findings, good-practice observations and technical commentary in real time. No booking a consultancy for every scan; no waiting a year to know what changed.
A programme, not a pentest
Your pentest was true for one day in March. A persistent estate and finding ledger turn any two runs into a plain change list — what appeared, what closed, what came back. The scan that stops seeing an issue is the proof it's fixed; retest becomes a diff, not a rewrite.
The operator's toolkit
This isn't a dumbed-down in-house tool — it's the same platform security professionals use to deliver to their own clients. What counts as a finding is a rule you author, not a vendor's opinion, and severity follows CVSS v4 or your own impact/likelihood matrix.
Security that clears
the path.
Continuous, evidenced security stops being the gate the business waits behind.
A business enabler
External exposure assessments that de-risk an acquisition before you sign, supplier onboarding assessed on a cadence instead of a questionnaire, delivery that moves because assurance is already in hand. The programme becomes a capability the business runs on, not a gate it waits behind.
Accreditation without being accredited
Your team runs and evidences the programme, then hands an accredited assessor a clean, traceable pack to validate and sign off — engagement authorisation with client co-attestation, per-tool licence attribution, and framework evidence mapped to NIST, CMMC, OWASP, MITRE and CWE. AI-free and reproducible, which is exactly what an auditor relies on.
Your data never leaves
Self-hosted on your own infrastructure — for a multinational that's residency and regulatory sovereignty, not just privacy. The only thing that leaves the box is a daily licence heartbeat carrying zero findings data, and no client data is ever fed to a model.
Representative view · framework coverage
Work that used
to take
a vendor.
Representative view · parsed findings
Where you'd still
call a specialist.
Being straight about the boundary is the point. The platform owns the routine majority; some work stays with an external expert by design — complex application testing, red team and threat-led exploitation, and independent third-party assurance where you can't mark your own homework. Insourcing the routine doesn't mean self-attesting the hard assurance. Buy the platform to run the routine programme yourselves — and keep us for the hard 20% and the assurance you can't self-attest.
Due diligence,
then the
live programme.
For an acquisitive group, Dispatch carries an acquisition from a pre-deal exposure scan, through authorised deep-dive once you have access, into your live programme — as one continuous record. No scanner or GRC tool touches the whole lifecycle.
Reclaim the budget.
Own the programme.
The fastest way to judge it is to watch it work against something you own. Tell us what you believe is exposed, and we'll show you the gap between your asset list and reality.