Frequently asked questions
Recurring questions in the evaluation process.
The answers below consolidate the questions most frequently raised during evaluation. Matters not covered may be submitted through the contact channel, with a response within one business day.
01
Platform suitability
Is there a minimum organizational size for contracting?
The platform is sized for organizations with between 10 and 500 employees, and investment follows the size of the monitored environment. It is worth noting that target selection in automated attacks considers ease of exploitation rather than organizational size.
Is an IT team required to use the platform?
Capacity to execute the corrections identified is required, which may be met by an internal IT professional, the vendor responsible for the infrastructure, or, under the Managed plan, a CyberSeven analyst. Following the platform and reading the security index require no technical knowledge.
Does the platform replace existing antivirus and firewall solutions?
No. The layers are complementary. Antivirus addresses malicious files already present in the environment, and firewalls address network traffic according to established rules. Neither determines the organization’s current exposure or establishes the order of remediation, which is the function of CyberVision.
02
Artificial intelligence
What is the effective role of artificial intelligence in the platform?
Artificial intelligence performs the stage that traditionally demands a specialist: it converts natural-language instructions into technical scans, correlates findings across the different monitoring fronts, classifies each risk considering technical severity and asset criticality, and presents the recommended action in clear terms.
Is technical knowledge required to operate the assistant?
No. Interaction takes place in natural language, without specific syntax and without configuring technical parameters. Requests such as an assessment of current priorities, the issuing of an executive report, or the scheduling of recurring scans are expressed in ordinary text.
Does the artificial intelligence make changes to the environment autonomously?
No. The platform identifies, classifies, and instructs. Executing changes depends on formal approval from the organization and remains restricted to the automation scope expressly authorized in contract.
How is consistency of risk classification assured?
Classification combines the technical severity recorded in public vulnerability databases with the criticality of the asset in the organization’s context. The impact and likelihood matrix documents the criteria applied to each record, allowing prioritization to be verified in audit processes.
03
Operation
Which fronts are effectively monitored?
Up to six fronts, according to the contracted plan and the established scope: internal network, external network, known vulnerabilities in operating systems, web applications, cloud resource configuration, and exposure of corporate credentials in restricted forums.
Does implementation require software installation?
Monitoring the internet-facing surface requires no installation. Monitoring the internal network requires an agent installed on a machine in the corporate network, with installation carried out jointly with the organization.
Is there a risk of downtime during scanning?
Scans are parameterised to operate without impact on system availability, with scope and execution window agreed in advance. Sensitive equipment, such as medical devices and industrial control systems, is subjected exclusively to passive verification.
04
Investment and contracting
What investment is required?
The figure derives from three variables: the volume of assets included in monitoring, the modules enabled, and the level of follow-through performed by CyberSeven. The proposal with scope and investment is presented within one business day of the scoping meeting.
Why are figures not published on the site?
Because the surface to be monitored varies considerably between organizations of the same nominal size. A fixed table would transfer cost between materially different environment profiles. Sizing the scope precedes presenting the investment.
Is there an implementation cost beyond the subscription?
Implementation is conducted by the CyberSeven team and its composition appears in the commercial proposal, together with any associated costs. Amounts additional to the subscription, where they exist, are presented in that document.
Must a contract be signed before the evaluation?
No. The evaluation period precedes any contractual commitment and requires no credit card. The scope of the evaluation is recorded in writing before scans are executed.
05
Data and compliance
What data does the platform collect?
Technical configuration and exposure data: asset inventory, published services, software versions in operation, and applicable known vulnerabilities. The platform does not scan mailboxes, working files, or client databases on its own initiative.
How does verification of suspicious messages operate?
Verification is executed exclusively on content voluntarily submitted to the assistant by the user. There is no automated access to the organization’s mailboxes.
Does the platform meet data protection requirements?
Processing of the data collected observes Brazil’s General Data Protection Law. The platform also contributes to the organization’s own compliance obligations by identifying exposures involving personal data. Details appear in the privacy policy.
Who at CyberSeven has access to the monitored environment?
Access is restricted to the team assigned to the organization’s account and limited to the authorized scope. Under the Managed plan, the assigned analyst follows the risk queue, which corresponds precisely to the service contracted.
Establish your current exposure.
The evaluation runs against the organization’s real environment and delivers the initial security index and the prioritized risk queue within the first week.