Pay premium rates
Gamble on who shows up.

Call it what it is: the consultancy lottery. Booking a consultancy for every scan means no consistency in scoping, pricing or methodology — the outcome and the consultant both vary. And because that cost is priced by the day and by the asset, your security spend rises in lockstep with your size. The routine majority of the programme — the part your own team could own — stays trapped in a vendor.

The work your team
can already do.

The routine security programme is yours to run — on your schedule, not a vendor's.

Own the routine programme

External attack surface, OSINT, vulnerability scanning and security reviews — run with the same tools a good operator would, auto-parsed into findings, good-practice observations and technical commentary in real time. No booking a consultancy for every scan; no waiting a year to know what changed.

A programme, not a pentest

Your pentest was true for one day in March. A persistent estate and finding ledger turn any two runs into a plain change list — what appeared, what closed, what came back. The scan that stops seeing an issue is the proof it's fixed; retest becomes a diff, not a rewrite.

The operator's toolkit

This isn't a dumbed-down in-house tool — it's the same platform security professionals use to deliver to their own clients. What counts as a finding is a rule you author, not a vendor's opinion, and severity follows CVSS v4 or your own impact/likelihood matrix.

Security that clears
the path.

Continuous, evidenced security stops being the gate the business waits behind.

A business enabler

External exposure assessments that de-risk an acquisition before you sign, supplier onboarding assessed on a cadence instead of a questionnaire, delivery that moves because assurance is already in hand. The programme becomes a capability the business runs on, not a gate it waits behind.

Accreditation without being accredited

Your team runs and evidences the programme, then hands an accredited assessor a clean, traceable pack to validate and sign off — engagement authorisation with client co-attestation, per-tool licence attribution, and framework evidence mapped to NIST, CMMC, OWASP, MITRE and CWE. AI-free and reproducible, which is exactly what an auditor relies on.

Your data never leaves

Self-hosted on your own infrastructure — for a multinational that's residency and regulatory sovereignty, not just privacy. The only thing that leaves the box is a daily licence heartbeat carrying zero findings data, and no client data is ever fed to a model.

NIST 800-53 r5 — Coverage evidence evidence, not a score
18 observed-satisfied 6 tested — gap 42 not evidenced
AC-17 — Remote AccessAccess Control
Observed-satisfied
SC-8 — Transmission ConfidentialitySystem & Communications
Tested — gap
AU-6 — Audit Review & ReportingAudit & Accountability
Not evidenced
No percentage, no pass/fail — only what the testing actually evidenced.

Representative view · framework coverage

Work that used
to take
a vendor.

External attack surface and OSINT, attributed back to the assets you own — so you see what the internet already knows before an attacker does
A live asset estate with scan-to-scan diff — so every run answers "what changed?", and a retest is a diff, not a rewrite
Detection rules you author, plus good-practice findings no commercial scanner emits — so a finding is your judgement, not a vendor's opinion
Framework evidence across NIST 800-53 r5, 800-171 r3, CMMC L2, OWASP and MITRE ATT&CK — shown as evidence, never a score, ready to hand an assessor
A separate organisation per business unit or acquisition, with MFA and row-level isolation — so one platform covers the whole group without co-mingling data
Acme · External — Findings parsed in real time
High
Anonymous FTP allowed10.0.4.30:21 · rule: ftp-anon-login (yours)
CVSS 8.1
Medium
Outdated OpenSSH 7.410.0.4.18:22 · CVE-2018-15473
CVSS 5.3
Low
Missing HSTS headerportal.acme.com · web-exposure
CVSS 3.1
Good practice
TLS 1.3 enforced, HSTS preloadedapi.acme.com · credited, not only flagged
A finding is a rule you author — dry-run previewed before it goes live.

Representative view · parsed findings

Where you'd still
call a specialist.

Being straight about the boundary is the point. The platform owns the routine majority; some work stays with an external expert by design — complex application testing, red team and threat-led exploitation, and independent third-party assurance where you can't mark your own homework. Insourcing the routine doesn't mean self-attesting the hard assurance. Buy the platform to run the routine programme yourselves — and keep us for the hard 20% and the assurance you can't self-attest.

Due diligence,
then the
live programme.

For an acquisitive group, Dispatch carries an acquisition from a pre-deal exposure scan, through authorised deep-dive once you have access, into your live programme — as one continuous record. No scanner or GRC tool touches the whole lifecycle.

Pre-deal: external attack-surface and OSINT only — see what the internet already knows about the target before you sign
With access: authorised deeper testing, made defensible by the engagement-authorisation record
Post-acquisition: onboard as a separate organisation and quantify inherited security debt as a price chip or integration plan
See it against your own estate

Reclaim the budget.
Own the programme.

The fastest way to judge it is to watch it work against something you own. Tell us what you believe is exposed, and we'll show you the gap between your asset list and reality.

Book a Demo Explore the Platform