India's AI-powered cyber resilience platform. Unifying SOC monitoring, VAPT, brand intelligence, dark web monitoring, GRC compliance, and cyber insurance — all in one console built for enterprises.
| Employee | Dept | Score | Risk | Top Signal |
|---|---|---|---|---|
| Rahul Kumar | Finance | 87 | HIGH | 3 phishing clicks |
| Sneha Joshi | Sales | 74 | MED | Shared credentials |
| Priya Sharma | HR | 61 | MED | Weak password, no MFA |
| Arjun Mehta | Engineering | 22 | LOW | Clean record |
Gordon's SOC module combines AI-powered alert triage with expert human analysts — eliminating 90% of false positives before they reach your team, and escalating only what truly matters.
Gordon continuously scores every employee from 0–100 based on real behaviour signals — phishing clicks, credential reuse, off-hours access, data exfiltration patterns — and surfaces the highest-risk individuals before incidents occur.
| Employee | Dept | Score | Risk | Top Signal |
|---|---|---|---|---|
| Rahul Kumar | Finance | 87 | HIGH | 3 phishing clicks |
| Sneha Joshi | Sales | 74 | MED | Shared credentials |
| Priya Sharma | HR | 61 | MED | Weak password, no MFA |
| Arjun Mehta | Engineering | 22 | LOW | Clean record |
Continuous automated scanning combined with CERT-In empanelled expert testers — covering web apps, APIs, networks, cloud infrastructure, and mobile apps. CVSS-scored findings with PoC-backed reports.
Gordon continuously monitors the security posture of every vendor in your supply chain — scoring them on 200+ signals including CVEs, misconfigurations, dark web exposure, and compliance gaps.
Gordon monitors the dark web, typosquatting domains, social media, paste sites, and app stores — detecting impersonation, credential leaks, and brand abuse before they damage your customers or reputation.
Gordon runs automated phishing simulations, micro-learning campaigns, and gamified training — tracking completion, click rates, and improvement over time. Fully localised for Indian enterprises.
Gordon's financial impact module translates technical vulnerabilities into board-ready financial exposure estimates — using FAIR methodology calibrated for Indian regulatory and business context.
Gordon's Security Checklist maps your controls against RBI CSCRF, SEBI Cybersecurity Framework, DPDP Act 2023, and CERT-In guidelines — giving you a real-time compliance score with prioritised remediation steps.
Gordon analyses your risk posture and matches you with the optimal cyber insurance policy from India's leading insurers — with live premium estimates, coverage gap analysis, and claims support.
| Capability | Gordon Console | Point Solutions | In-house SOC |
|---|---|---|---|
| Unified platform (single pane) | ✓ | ✗ | ~ |
| India-specific compliance (RBI, SEBI, DPDP) | ✓ | ✗ | ~ |
| SOC + VAPT + Brand + Workforce in one tool | ✓ | ✗ | ✗ |
| Financial impact quantification (₹) | ✓ | ✗ | ✗ |
| Cyber insurance integration | ✓ | ✗ | ✗ |
| Setup time | Hours | Weeks–months | 6–12 months |
| Annual cost (SME) | $1,787/mo | $5K–$20K/mo (combined) | $50K–$200K/yr |
| CERT-In empanelled | ✓ | ~ | ~ |
Choose the plan that fits your team. Upgrade or cancel anytime.
For growing companies up to 100 employees. Core security, GRC, and insurance in one platform.
Start Free TrialFor companies with 100–500 employees. Expanded limits across all modules.
Start Free TrialFor large enterprises 500+ employees. Unlimited scale, dedicated support, and custom SLAs.
Talk to Sales| Features | Free | Startup $1,787/mo |
Mid-Market $3,382/mo |
Enterprise $6,607/mo |
|---|---|---|---|---|
| ▶Attack Surface Monitoring12 scans/year | ||||
| Monitored Assets (Domains, IPs, Mobile Apps) | — | 1 asset | 3 assets | 10 assets |
| Exposed subdomains & open ports | — | ✓ | ✓ | ✓ |
| SSL/TLS certificate health | — | ✓ | ✓ | ✓ |
| DNS anomalies & misconfigurations | — | ✓ | ✓ | ✓ |
| Web technology fingerprinting | — | ✓ | ✓ | ✓ |
| CVE & vulnerability scoring | — | ✓ | ✓ | ✓ |
| Continuous monitoring & alerts | — | ✓ | ✓ | ✓ |
| ▶SOC Monitoring24/7 | ||||
| Monitored Endpoints | — | Upto 100 | Upto 500 | Upto 2,000 |
| AI-powered alert triage | — | ✓ | ✓ | ✓ |
| Kill-chain reconstruction (MITRE ATT&CK) | — | ✓ | ✓ | ✓ |
| Automated response playbooks | — | ✓ | ✓ | ✓ |
| CERT-In 6-hour incident reporting | — | ✓ | ✓ | ✓ |
| Threat intelligence (IOCs, Campaigns) | — | 10 threats, 5 IOCs | 50 threats, 20 IOCs | Unlimited |
| ▶Workforce Risk & Security Awareness | ||||
| Monitored Employees | — | Upto 100 | Upto 500 | Upto 2,000 |
| Email phishing simulation | — | ✓ | ✓ | ✓ |
| Custom phishing templates | — | ✓ | ✓ | ✓ |
| Security awareness training + LMS | — | ✓ | ✓ | ✓ |
| ▶Dark Web Monitoring | ||||
| Monitored Keywords (brand, legal name, vendors) | — | 1 keyword | 1 keyword | 5 keywords |
| Tor forums, paste sites, Telegram channels | — | ✓ | ✓ | ✓ |
| Breach databases & data dumps | — | ✓ | ✓ | ✓ |
| Ransomware & APT group monitoring | — | ✓ | ✓ | ✓ |
| ▶Cloud Security & Billing Monitoring | ||||
| Cloud Instances Monitored | — | 1 instance | 2 instances | 5 instances |
| Misconfiguration detection (CIS 572 benchmark) | — | ✓ | ✓ | ✓ |
| IAM & privilege escalation checks | — | ✓ | ✓ | ✓ |
| S3 / Blob public exposure alerts | — | ✓ | ✓ | ✓ |
| Cloud billing tracking & optimisation | — | ✓ | ✓ | ✓ |
| ▶GRC & ComplianceAudit charges extra | ||||
| Compliance Frameworks | — | 2 frameworks | 4 frameworks | 5 frameworks |
| Automated control mapping | — | ✓ | ✓ | ✓ |
| AI gap assessment & remediation tasks | — | ✓ | ✓ | ✓ |
| Policy & procedure auto-generation | — | ✓ | ✓ | ✓ |
| Risk register automation | — | ✓ | ✓ | ✓ |
| AI-based internal audit & audit-ready reports | — | ✓ | ✓ | ✓ |
| Trust center | — | ✓ | ✓ | ✓ |
| ▶Third Party Risk Management (TPRM) | ||||
| Vendors Monitored | — | 100 vendors | 250 vendors | 1,000 vendors |
| AI security questionnaire dispatch & scoring | — | ✓ | ✓ | ✓ |
| Continuous external surface scan | — | ✓ | ✓ | ✓ |
| Breach & dark web alerts for vendor | — | ✓ | ✓ | ✓ |
| Risk rating (A–F) with trend | — | ✓ | ✓ | ✓ |
| ▶Gordon AI | ||||
| AI Credits / Tokens | — | 500 credits | 1,000 credits | 1,000 credits |
| Auto-generated risk narratives | — | ✓ | ✓ | ✓ |
| One-click remediation playbooks | — | ✓ | ✓ | ✓ |
| Executive summary generation | — | ✓ | ✓ | ✓ |
| AI-assisted questionnaire filling (CRQ) | — | ✓ | ✓ | ✓ |
| Threat intelligence summaries | — | ✓ | ✓ | ✓ |
| ▶Brand Intelligence & Takedowns | ||||
| Brand Assets Monitored | — | 1 asset, 20 keywords | 3 assets, 60 keywords | 5 assets, 100 keywords |
| Fake domain / phishing page / typosquat monitoring | — | ✓ | ✓ | ✓ |
| Reverse imaging / logo detection | — | ✓ | ✓ | ✓ |
| Social media & counterfeit listing monitoring | — | ✓ | ✓ | ✓ |
| Takedowns (Rogue app, DMCA, Phishing pages) | — | 25 takedowns | 100 takedowns | 125 takedowns |
| ▶Consent Manager (DPDPA) | ||||
| Unique Consents (website / mobile app users) | — | 25K consents | 100K consents | 500K consents |
| Granular consent collection & withdrawal | — | ✓ | ✓ | ✓ |
| 15+ platform integrations | — | ✓ | ✓ | ✓ |
| 22 Indian language translation (DPDPA Art. 18) | — | ✓ | ✓ | ✓ |
| Cookie scanner, data deletion & grievance requests | — | ✓ | ✓ | ✓ |
| Google Consent Mode V2 support | — | ✓ | ✓ | ✓ |
All plans include a 15-day free trial — no credit card required.