ALCE Consulting ALCE
Optimus · Vendor Security Monitoring · Live Now

One vendor breach
is your breach.

Optimus automates your vendor security assessment program — DNS-verified domain scanning, daily CVE cross-referencing, single-use vendor invite links, and a unified supply chain risk dashboard. No manual follow-up. No spreadsheets.

No setup fees · No per-scan charges · Cancel anytime

Daily
CVE Updates
3yr
Consent Record Retention
0
Manual Follow-up Steps
Vendors on Unlimited Plan
Why Optimus

Your vendors are your
biggest security blind spot.

Most vendor risk programs live in spreadsheets — if they exist at all. Optimus replaces manual outreach, one-off scans, and chased-down documentation with an automated, evidence-backed assessment pipeline.

Built from 15+ Years of DoD Security Experience
Built by an operator with 15+ years inside DoD and national security systems — applying external threat analysis discipline to your vendor program.
DNS-Verified Authorization
Vendors prove domain ownership via DNS TXT record before any scan fires. No contested scans. No unauthorized assessments. Every result is consent-backed.
3-Year Immutable Consent Records
Every vendor scan is backed by a timestamped consent record retained for 3 years — independent of account status. Ready for audits, disputes, or compliance review.
Daily CVE Cross-Reference
Technology stacks detected during scans are cross-referenced against CVEs every day at 6 AM UTC. New matches trigger instant alerts — no manual checking required.
Single-Use Vendor Invite Pipeline
Generate cryptographically unique invite links per vendor. Three-acknowledgment consent is recorded with IP, timestamp, and terms version before any scan fires.
Unified Supply Chain Dashboard
All your domains and vendors in one view — scores, grades, finding counts, scan history, CVE status. No manual aggregation, no switching between tools.
Core capabilities

Everything your vendor risk
program actually needs.

Built for security teams that need documented evidence, not just visibility.

Monitoring
Automated Domain Scanning
Monthly automated scans of your own domains with daily CVE cross-referencing. Re-verification every cycle — if DNS token is removed, scanning stops.
Onboarding
Vendor Invite Pipeline
Send a single-use invite link. Vendor verifies domain ownership. Ghost's full 21-check audit fires automatically. Result is timestamped and stored to their profile.
Intelligence
Daily CVE Alerts
Technology stacks from every scan are checked against the CVE database every morning. New matches trigger email alerts immediately — no dashboard check needed.
Visibility
Risk Dashboard
One view across all monitored domains and vendors. Security scores, finding counts, scan history, SSL expiry timelines, and CVE match status — aggregated automatically.
Compliance
Audit-Ready Consent Records
Every vendor assessment is backed by an immutable consent record — IP address, timestamp, terms version — retained for 3 years independent of account status.
Alerting
Automated Notifications
SSL expiry warnings, DNS token removal notices, CVE matches, and vendor scan completions — all delivered automatically by email. No manual monitoring required.
Who needs this

If a vendor can reach your systems,
their posture is your problem.

Optimus is built for any organization that manages third-party vendor relationships and needs documented evidence of their security posture.

Security teams managing 10+ vendors
Manual vendor outreach and one-off scans don't scale. Optimus replaces the spreadsheet with an automated, evidence-backed pipeline that runs without you.
Companies pursuing SOC 2 or ISO 27001
Both frameworks require documented vendor risk management. Optimus generates the timestamped, audit-ready evidence your assessor will ask for.
Defense contractors preparing for CMMC
CMMC Level 2 and above requires vendor security assessment documentation. Optimus handles the scanning, consent records, and findings documentation automatically.
Enterprises onboarding new vendors
Know a vendor's external security posture before you sign. Send an invite link, they verify their domain, Ghost scans it — you have a scored report before the contract closes.
MSPs managing client vendor programs
Run vendor assessments across multiple client accounts from one platform. Consistent process, documented evidence, no manual coordination per client.
Any business with critical third-party dependencies
Payroll, cloud storage, payment processing — if a vendor handles sensitive data or critical operations, their breach becomes your breach. Optimus keeps you informed.
Pricing

Simple monthly pricing.
Cancel anytime.

No setup fees. No per-scan charges. No contracts. Data retained for 30 days after cancellation.

Standard
$499/mo
1 Domain · 15 Vendor Invites
For teams managing a focused vendor program with one primary domain.
  • Monthly automated domain scan
  • Daily CVE monitoring + alerts
  • SSL certificate expiry alerts
  • Vendor invite pipeline
  • Risk dashboard
  • Audit-ready consent records
Get Started →
Unlimited
$1,499/mo
Unlimited Domains & Invites
For enterprises and MSPs running vendor programs at scale across multiple accounts.
  • Everything in Professional
  • Unlimited monitored domains
  • Unlimited vendor invites
  • Priority support
  • Custom enterprise onboarding
Get Started →

Your vendor program deserves
more than a spreadsheet.

Automated assessments. Documented evidence. No manual follow-up. Start your enterprise trial today.

Start Enterprise Trial →