Skip to content
CyCastle — All your cybersecurity in one castle.

Your organization's cyber fortress.

We have brought together 15 security services in a single cloud panel, from vulnerability scanning to dark web intelligence, from phishing simulation to endpoint protection. No more tangled tool stacks — with CyCastle, see, measure and close your entire attack surface from one place.

  • Cloud-based
  • Turkish support
  • 5651 & KVKK compliant
  • Setup in minutes
Live Security Score
Active
0 / 100
Vulnerability scanClean
Certificate validity64 days
Dark web leak2 alerts
Endpoint patchesUp to date
Devices
0
Critical
0
Closed
0
Scan complete — 248 devices, 3 critical findings
Dark web: 2 new credential matches
Watcher score updated: 94 / 100
0+
active users
0+
satisfied customers
0+
known vulnerabilities
0
integrated security services
Platform

Not scattered tools, one platform.

Most businesses use five separate tools, five separate panels and five separate invoices for security. CyCastle brings them all under one roof: one login, one panel, one reporting language. Your team sees risks without losing context; your manager tracks the security score on a single screen.

Explore the 15 services

One panel, full visibility

Network, web, endpoint, identity and dark web; all on the same screen.

Prioritized risk

Not hundreds of findings, but the critical ones you must close first.

Many locations, one management

Branches, customers and teams; central control.

Products

15 layers of defense, one console

Network, web, identity, endpoint and threat intelligence — all working together. Start with what you need, add more as you grow, and manage everything from a single console.

01

ThreatChaser

Vulnerability Scanning

Continuously scans your network and servers for vulnerabilities, prioritizes them and guides you through remediation.

  • Automatic device discovery and inventory
  • Continuous vulnerability detection with an up-to-date CVE database
  • Risk-based prioritization and remediation guidance
  • A single ISO 27001-aligned, shareable PDF report
02

Web Application Scanning

Through an attacker's eyes

Scans your websites and applications the way an external attacker would.

  • Automatic domain and subdomain discovery
  • Detection of web application vulnerabilities and common flaws
  • Continuous monitoring to catch new flaws early
  • A single ISO 27001-aligned PDF report, with evidence for every finding
03

CTI

Dark Web & Leak Intelligence

Finds your leaked data and stolen credentials on the dark web before you do.

  • Leak scanning for your domain and corporate emails
  • Alerts for compromised passwords and credentials
  • Monitoring and alerting on data-breach records
  • Early warning to prevent account takeovers
04

5651 Logger & Hotspot

Legal logging

Logs your guest Wi-Fi and internet access in line with the law and verifies identities.

  • Access logging compliant with Law No. 5651
  • Captive portal (welcome screen) for guest Wi-Fi
  • Secure guest verification via SMS/ID
  • Queryable, signed log archive
05

Phishing Simulation

Awareness measurement

Measures your employees' resilience to phishing attacks with realistic campaigns.

  • Awareness testing with realistic mock campaigns
  • Click, data-entry and open-rate reports
  • Ready-made template library and customization
  • Identifying weak links and directing them to training
06

Endpoint Agent

Endpoint Management

Manages your devices from a single panel, delivers patches and remote support.

  • Device inventory and status tracking
  • Patch and update management
  • Remote management and support access
  • Policy-based central control
07

ThreatAuthenticator

Multi-Factor Authentication (MFA)

Protects your logins with one-tap push approval and MFA.

  • One-tap approval via push notification
  • Time-based one-time passcodes (TOTP)
  • Authentication policies and group management
  • A second security layer for the panel and applications
08

SSL Certificate Monitoring

Expiry and configuration

Monitors your SSL certificates' validity and warns you before they expire.

  • Automatic certificate discovery and monitoring
  • Timely warning before expiry
  • Misconfiguration detection
  • Preventing downtime and loss of trust
09

Service & Uptime Monitoring

Availability

Continuously monitors whether your critical services are up.

  • Service and site availability tracking
  • Instant alert the moment there is an outage
  • Response-time and availability history
  • See problems before your customers do
10

Authorized DDoS Stress Test

Resilience measurement

Measures your systems' resilience under load in an authorized, controlled way.

  • Controlled, authorized resilience testing
  • Capacity and breaking-point analysis
  • Detailed post-test performance report
  • See weaknesses before a real attack
11

Firewall Vulnerability Analysis

Config analysis + CVE

Analyzes your firewall's configuration and surfaces vulnerabilities specific to its brand and version.

  • Support for FortiGate, Palo Alto, SonicWall and MikroTik
  • Secure backup and analysis of the configuration
  • Brand- and version-based up-to-date CVE matching
  • Prioritized findings and remediation guidance
12

SQL Vulnerability Scanning

SQL Injection

Detects SQL injection flaws in your web applications through an external attacker's eyes.

  • Automatic SQL injection detection
  • Evidence-backed report of data-exfiltration points
  • Early detection of critical database flaws
  • Clear, actionable remediation guidance
13

AD Health Check

Active Directory

Audits the security health of your Active Directory environment and shrinks the identity attack surface.

  • Audit of identity and permission configuration
  • Detection of risky accounts, policies and settings
  • Best-practice and compliance recommendations
  • Early defense against identity-based attacks
14

Authenticated Deep Scan

Authenticated Scan

Scans the inside of your system more deeply and accurately with authorized access.

  • Comprehensive detection of internal vulnerabilities
  • Visibility into missing patches and misconfigurations
  • Lower false-positive rate
  • Deep analysis for enterprise environments
15

IP & Domain Reputation Check

Reputation & KEV

Monitors whether your IP addresses and domains are on blocklists and protects your reputation.

  • Detection of blocklist membership
  • Alerts for reputation issues that block email delivery
  • Visibility into known exploited vulnerabilities (KEV)
  • Notice reputation loss early
Featured capability — Watcher

AI-powered security scoring.

CyCastle Watcher evaluates all your findings with AI; it filters out the noise, surfaces the real risk and gives you a simple security score. You do not need to read hundreds of lines of reports to make a decision.

Noise reduction Real risk priority Simple score
Watcher analysis Latest assessment
0 / 100 security score
Raw findings
412
Noise
-321
Real risk
91
Critical
3

Watcher reduced 412 findings to 3 critical actions. Close these first.

Why CyCastle

A defense designed for you.

Local and Turkish

Turkish interface, Turkish support, compliance with local legislation (5651, KVKK).

Setup in minutes

No complex installation; cloud-based, quick start.

For non-technical teams

A clean panel and clear reports; no expert required.

Scalable

From a single office to multi-location organizations and reseller networks.

Compliance and regulation Compliant, auditable infrastructure aligned with local legislation
  • 5651-compliant logging
  • KVKK-friendly data processing
  • Signed and auditable reports
  • Role-based access control
Partners / White-label

Sell cybersecurity under your own brand.

With CyCastle's white-label partner program, offer the entire platform to your customers under your own brand, your own logo and your own colors. We provide the infrastructure; the customer relationship stays with you.

  • Your own brand and domain
  • Multi-tier reseller and customer management
  • Flexible license and credit system
Become a Partner
security.your-brand.com
Your logo
96
48
12
Your colors
Defense

We break the attack chain at every step

A cyber attack does not happen in a single moment; it advances stage by stage. CyCastle is engaged at every stage: you see, measure and stop the attacker before they can move to the next step.

  1. 01

    Reconnaissance

    The attacker looks for open vulnerabilities, leaked passwords and weak points.

  2. 02

    Intrusion

    Initial access is attempted via phishing, an exposed application or a weak password.

  3. 03

    Account Takeover

    Accounts and privileges are targeted for takeover, and privilege escalation is attempted.

  4. 04

    Lateral Movement

    Lateral movement within the network is used to try to jump to other systems.

  5. 05

    Exfiltration Prevented

    Data exfiltration and disruption attempts are caught early, and the chain is broken.

FAQ

Frequently asked questions

Can't find what you're looking for? Contact us.

General & Platform

What exactly is CyCastle?
A Türkiye-based, cloud-native cybersecurity platform. It brings together 15 security services in a single panel, from vulnerability scanning to dark web intelligence, from phishing simulation to endpoint protection.
Do I need to be a cybersecurity expert to use it?
No. The panel and reports are designed for non-technical teams; they present critical findings in plain language and prioritized order.
Do I have to buy all the services?
No. You choose the services you need and grow whenever you like by adding new ones.
Can I manage multiple branches or locations?
Yes. It scales from a single office to multi-location organizations and reseller networks; you manage them all centrally from one panel.

Setup & Usage

How long does setup take?
Because it is cloud-based, you can get started within minutes; there is no complex setup process.
Is special hardware required?
Most services run purely from the cloud panel. Some services such as 5651 logging and endpoint management involve installing a small device or a lightweight agent; we guide you through the setup.
Can I share reports with my team and management?
Yes. Scan results are delivered as a single ISO 27001-aligned PDF report you can download and share directly with your team and management.
Does it work with my existing security tools?
Yes. It integrates with solutions such as SonicWall, FortiGate and OPNsense; it fits into your existing infrastructure.

Security & Compliance

Is my data safe, and where is it processed?
Your data is processed and protected in compliance with the KVKK; it is supported by role-based access and signed, auditable reports.
Does it comply with Law No. 5651?
Yes. With 5651 Logger & Hotspot it keeps access records in line with the law, verifies guest Wi-Fi and provides a queryable, signed log archive.
Does phishing simulation harm my employees?
No. It is a controlled and authorized awareness test; the goal is to train the team and make weak links visible, with no real harm caused.
Do you share my data during dark web scanning?
No. We only search for your own leaked data and credentials and alert you; your data is not shared with third parties.

Pricing, Partners & Support

Can I start for free?
Yes. You can create a free account and start your first scan within minutes. You can contact us for a package tailored to your needs.
Is support available in Turkish?
Yes. We provide a Turkish interface and Turkish support; compliance with local legislation is a priority for us.
Can I become a partner?
Yes. With our white-label partner program you can offer the entire platform to your customers under your own brand, logo and colors.

Build your castle today.

Create a free account and start your first scan in minutes.