How do I get started?
Sign in with your email to get a magic link, create a project in the dashboard, and verify your primary domain. Subscribe for $150/mo per project to start weekly scheduled scans, with results delivered via dashboard, API, and signed webhooks. Cancel any time.
Is this really run by AI?
Yes. Toshiku is fully automated agentic analysis. Agents run the playbook against your public surface, validate supported findings, and generate remediation guidance. All triage and prioritization is machine-generated and clearly labeled; it is not human-reviewed.
What do you actually scan?
Anything publicly reachable for the domain you give us: subdomains, certificates, email auth, exposed admin paths, sensitive files, TLS, security headers, cookies, JS secrets and source maps, subdomain takeover candidates, and a light port and tech fingerprint. No login, no exploit attempts, no brute force.
How do you verify ownership?
You verify your primary domain by publishing a DNS TXT record, hosting a file at /.well-known/, or adding a homepage meta tag. Any one of these methods proves control. Scanning is enabled only once a domain is verified.
Will it touch my production?
Yes, on the public side. The scan is light and non-intrusive: no auth, no exploit attempts, no rate-limit testing. If you would rather point us at a separate staging domain, do that.
Is this a SOC 2 or ISO 27001 pen test?
No. It is a recurring external scan, not a certification. The report is structured and audit-friendly, but if you need a specific deliverable for an auditor, check with them first.
More than one project?
$150/mo per project. Sign each one up the same way. A project is one production app: one primary domain and its discovered subdomains.
Toshiku is automated agentic security analysis. It is not a penetration test, not exploit validation, not a compliance certification, and not a guarantee that no risk exists.