Company
The autonomous offensive security platform
Revelion proves what is exploitable across an estate, as often as that estate changes. It runs for enterprise security teams directly, for MSPs as a white-label service line, and for UK public services as 360 Protect.
The premise
Testing stopped matching the way software is delivered
The annual penetration test made sense when estates changed annually. It describes a single day, and every deployment after that day is untested until the next engagement comes round.
The industry response was to scan more often. But a scanner answers a different question. It reports what might be vulnerable, not what is reachable, and it hands the work of deciding which findings matter back to the people who have the least time to do it.
The question that actually matters, which of these weaknesses combine into a route somebody could walk, is the question an offensive tester answers and a scanner cannot. Revelion exists to answer it as often as you deploy.
What we believe
Proof, not adjectives
- A finding should be demonstrated
- If exploitability was not shown, it should not be claimed. Unvalidated findings transfer work rather than reduce risk.
- Autonomy needs authorisation
- An agent that tests production must run under declared scope and documented authorisation, or it is a liability.
- Evidence beats scoring
- A severity number derived from a generic table says less than a reproduction that ends in access.
- Claims should be checkable
- That applies to our marketing as much as our reports, which is why this site says what we do not yet have.
How Revelion is delivered
Four routes to the same platform
The engine is one product. How it reaches an estate depends on who is responsible for that estate.
- Direct to security teams
- Enterprise teams run Revelion against their own estate, under their own scope and authorisation, as often as they deploy.
- As a white-label service line
- MSPs and MSSPs run it multi-tenant across a client base, with reporting issued under their brand rather than ours.
- Through distribution partners
- Partners bring the platform to providers inside their own channel, alongside providers who prefer to buy direct.
- To UK public services as 360 Protect
- Public sector work is delivered under the 360 Protect brand, with that route and its certifications stated plainly rather than implied.
Where it runs
Estates across four regions and a dozen sectors
Offensive testing generalises badly, so breadth of estate is the thing that makes a platform trustworthy on the next one.
- The UK, Europe, the Gulf and South Africa
- Customer estates span all four, which is what keeps the engine honest against different hosting, different suppliers and different regulatory expectations.
- Regulated and unregulated alike
- Lending, wealth and professional services sit alongside hospitality, wholesale, travel, storage and real estate.
- Single estates and whole client books
- The same engine covers one enterprise estate in depth and dozens of client estates at once, which are different operational problems.
- Web, network, cloud, API, Active Directory and IoT
- Coverage is documented per surface rather than asserted as a whole, so you can see what is in scope before you buy.
How we work
Everything we assert is published with its method attached
Revelion Labs publishes the benchmark results, the attack chains and the methodology behind both. Benchmark numbers without a method are marketing, so ours ship with the environments named and the procedure written down for anyone who wants to reproduce them.
The same standard applies to the parts that are less flattering. This site states where Revelion is not accredited, where a human red team remains the better instrument, and which facts we have not yet confirmed. Those are on the page because a buyer finds them out eventually, and it is better they find them here.
Operationally, every mission runs against a documented Letter of Authorisation, inside a scope declared before anything starts, with destructive actions refused by the engine rather than by a reviewer. The authorisation template, the sub-processor list and the data processing agreement are all published or available on request.
Governance
The corporate record
Revelion is built and operated in the United Kingdom. Revelion Limited is registered at Companies House under number 17015507, with a registered office at 167-169 Great Portland Street, 5th Floor, London, W1W 5PF.
Revelion holds Cyber Essentials, the UK government-backed certification covering the controls that stop the most common internet-borne attacks. The certificate is held on the issuing registry so it can be verified independently rather than taken on the strength of a badge on our own site.
Where a scheme, an insurer or a contract requires a CREST or CHECK engagement, Revelion does not satisfy that requirement. We say so here for the same reason we publish the benchmark method: it is the part a procurement process will test.
Everything we claim is meant to be checkable. Start here.
Read the Trust Centre
