Skip to content
Revelion

Company

The autonomous offensive security platform

Revelion proves what is exploitable across an estate, as often as that estate changes. It runs for enterprise security teams directly, for MSPs as a white-label service line, and for UK public services as 360 Protect.

The premise

Testing stopped matching the way software is delivered

The annual penetration test made sense when estates changed annually. It describes a single day, and every deployment after that day is untested until the next engagement comes round.

The industry response was to scan more often. But a scanner answers a different question. It reports what might be vulnerable, not what is reachable, and it hands the work of deciding which findings matter back to the people who have the least time to do it.

The question that actually matters, which of these weaknesses combine into a route somebody could walk, is the question an offensive tester answers and a scanner cannot. Revelion exists to answer it as often as you deploy.

01

What we believe

Proof, not adjectives

A finding should be demonstrated
If exploitability was not shown, it should not be claimed. Unvalidated findings transfer work rather than reduce risk.
Autonomy needs authorisation
An agent that tests production must run under declared scope and documented authorisation, or it is a liability.
Evidence beats scoring
A severity number derived from a generic table says less than a reproduction that ends in access.
Claims should be checkable
That applies to our marketing as much as our reports, which is why this site says what we do not yet have.

How Revelion is delivered

Four routes to the same platform

The engine is one product. How it reaches an estate depends on who is responsible for that estate.

Direct to security teams
Enterprise teams run Revelion against their own estate, under their own scope and authorisation, as often as they deploy.
As a white-label service line
MSPs and MSSPs run it multi-tenant across a client base, with reporting issued under their brand rather than ours.
Through distribution partners
Partners bring the platform to providers inside their own channel, alongside providers who prefer to buy direct.
To UK public services as 360 Protect
Public sector work is delivered under the 360 Protect brand, with that route and its certifications stated plainly rather than implied.

Where it runs

Estates across four regions and a dozen sectors

Offensive testing generalises badly, so breadth of estate is the thing that makes a platform trustworthy on the next one.

The UK, Europe, the Gulf and South Africa
Customer estates span all four, which is what keeps the engine honest against different hosting, different suppliers and different regulatory expectations.
Regulated and unregulated alike
Lending, wealth and professional services sit alongside hospitality, wholesale, travel, storage and real estate.
Single estates and whole client books
The same engine covers one enterprise estate in depth and dozens of client estates at once, which are different operational problems.
Web, network, cloud, API, Active Directory and IoT
Coverage is documented per surface rather than asserted as a whole, so you can see what is in scope before you buy.

How we work

Everything we assert is published with its method attached

Revelion Labs publishes the benchmark results, the attack chains and the methodology behind both. Benchmark numbers without a method are marketing, so ours ship with the environments named and the procedure written down for anyone who wants to reproduce them.

The same standard applies to the parts that are less flattering. This site states where Revelion is not accredited, where a human red team remains the better instrument, and which facts we have not yet confirmed. Those are on the page because a buyer finds them out eventually, and it is better they find them here.

Operationally, every mission runs against a documented Letter of Authorisation, inside a scope declared before anything starts, with destructive actions refused by the engine rather than by a reviewer. The authorisation template, the sub-processor list and the data processing agreement are all published or available on request.

Governance

The corporate record

Revelion is built and operated in the United Kingdom. Revelion Limited is registered at Companies House under number 17015507, with a registered office at 167-169 Great Portland Street, 5th Floor, London, W1W 5PF.

Revelion holds Cyber Essentials, the UK government-backed certification covering the controls that stop the most common internet-borne attacks. The certificate is held on the issuing registry so it can be verified independently rather than taken on the strength of a badge on our own site.

Where a scheme, an insurer or a contract requires a CREST or CHECK engagement, Revelion does not satisfy that requirement. We say so here for the same reason we publish the benchmark method: it is the part a procurement process will test.

Everything we claim is meant to be checkable. Start here.

Read the Trust Centre