N0FREE
Initial Posture and Exposure Assessment
An honest first look at your public exposure: a brief posture survey plus a non-invasive review of open sources (OSINT) about your domain. The ideal entry point if you’ve never done a formal evaluation.
Includes: Simplified survey · OSINT audit of your main domain (with Heimdall Cyberposture CLI) · 5 to 10 immediate prioritized recommendations.
N1
Basic Posture Assessment
For medium-sized SMEs without their own security team who want to go beyond the initial assessment. An advanced 84-question survey based on NIST CSF 2.0, correlation with actively exploited vulnerabilities, up to 15 prioritized recommendations, and a results presentation meeting.
Who it’s for: Companies with no prior formal cybersecurity evaluation.
N2Core product
Advanced Posture Assessment
For companies with significant digital surface: SaaS, APIs, mobile apps, or multiple domains. Adds social media reconnaissance, basic dark web monitoring, threat intelligence, and full threat modeling (STRIDE + DREAD).
Who it’s for: Mid-size companies with exposed digital assets, without a dedicated security team.
N3
Ley 21.663 Compliance Assessment
For Vital Importance Operators (OIV) or providers with contractual obligations under the Cybersecurity Framework Law. Everything in N2, plus a full gap analysis of the Regulatory Compliance function and audit-ready evidence for Chile’s National Cybersecurity Agency.
Who it’s for: Designated OIVs and providers with regulatory obligations under Ley 21.663.
AppSec
Offensive Security and AppSec
The next step when your organization has SaaS, mobile apps, or APIs that need to go beyond OSINT: web application pentesting, white-box audits (OWASP ASVS), API pentesting, mobile audits, and basic Red Team — coordinated by Araucaria alongside our network of specialized technical partners.
Who it’s for: Organizations with SaaS, mobile apps, or APIs that require offensive testing.