Attack Surface Management and Phishing Simulation in Your Own Cloud
HailBytes ASM and SAT deploy into your AWS or Azure account. Your scan data, campaign results, and audit logs stay inside your environment — no SaaS vendor can access them.
Why enterprise security teams deploy HailBytes
Enterprise ASM and SAT tools are typically SaaS: your scan data sits in a vendor's multitenant database, your phishing campaign results are stored on their infrastructure, and your compliance artifacts pass through systems you don't control. For security-conscious organizations — especially those in regulated industries, government-adjacent workloads, or those that have experienced a supply-chain incident — that model is increasingly hard to justify to a board or auditor.
HailBytes takes a different approach. Both HailBytes ASM (attack surface management) and HailBytes SAT (security awareness training and phishing simulation) deploy as marketplace images directly into your AWS or Azure account. Your data never leaves your environment. You control the encryption keys, the network access rules, the data retention policy, and when the instance gets patched. HailBytes has no access to your instance or your data after the marketplace deployment completes.
The cost model reflects that architecture too. Pricing is per vCPU/hour through the cloud marketplace — a single infrastructure bill that covers software, hosting, and updates. No per-seat licensing, no per-user tiers, no surprise invoices when headcount grows. Add 500 employees to a phishing campaign: your SAT cost doesn't move.
ASM + SAT as a combined program
Most compliance frameworks require both external attack surface visibility and demonstrated security awareness training. HailBytes ASM and SAT are designed to work together: ASM surfaces the external exposure that informs which business units need more aggressive phishing testing, and SAT generates the training completion and phishing simulation evidence that satisfies the auditor's security awareness requirement.
The ASM API feeds cleanly into any SIEM — Elastic, Splunk, Microsoft Sentinel, QRadar, Wazuh — so findings surface alongside your internal telemetry without a separate console to monitor. SAT exports structured audit logs in JSON and CSV, integrates with ServiceNow, Jira, Slack, Teams, and PagerDuty, and supports Microsoft Sentinel for SIEM-side phishing event correlation.
Your Cloud Account. Your Data.
Both products deploy via AWS Marketplace or Azure Marketplace into an account you own. HailBytes has zero access post-deployment.
Your Encryption Keys
Sensitive credentials (SMTP secrets, API tokens) are encrypted at rest with AES-256-GCM. You control the keys, the KMS configuration, and the rotation schedule. No shared key material with HailBytes.
Your Retention Policy
Set data retention to match your legal hold requirements. Purge scan history, phishing campaign results, and audit logs on your schedule — not the vendor's. Export everything to S3, Azure Blob, or SFTP before deletion.
Your Network Perimeter
Deploy inside a private VPC subnet with no public internet exposure. Air-gapped subnets are a first-class deployment target — HailBytes SAT self-hosts its fonts and front-end assets with zero outbound CDN dependencies.
SSO, SCIM, and SAML — Out of the Box
Connect to your existing identity provider. No manual user provisioning. No separate credential set for your security tools.
SAML 2.0 & OIDC SSO
Okta, Microsoft Entra ID, Google Workspace, OneLogin, JumpCloud, Auth0, and any standards-compliant IdP. Single sign-on means your analysts and security team use their corporate credentials — no password to manage, no shared account, full audit trail tied to real identities.
SCIM 2.0 Auto-Provisioning
Okta, Entra ID, Google Workspace, and any RFC 7644-compliant IdP. Users created in your identity directory are automatically provisioned in HailBytes SAT. Users deactivated in the directory are automatically deprovisioned — no manual offboarding checklist item required.
Role-Based Access Control
Administrator, User, and Read-Only roles. Separate admin accounts from analyst accounts from read-only executive access. API tokens are scoped per user with last-used timestamps — the controls your auditors expect to see.
Per-Organization Isolation
Org-scoped data isolation is enforced at the model layer with user_id filtering on every query. If you run HailBytes SAT for multiple business units or subsidiaries, each unit's data is invisible to the others. No shared campaign templates, no shared results, no cross-org audit log leakage.
Feeds Your Existing Security Stack
HailBytes ASM and SAT are API-first. Connect to the tools you already operate, not the other way around.
ASM → SIEM
HailBytes ASM pushes findings, new asset discoveries, and exposure events as structured JSON to Elastic, Splunk, Microsoft Sentinel, QRadar, and Wazuh via REST API and webhooks. ASM findings surface in the same correlation layer as your internal telemetry — no separate console.
SAT → Ticketing & Comms
Phishing events and training completions route to ServiceNow, Jira, PagerDuty, Slack, Teams, and Twilio via native integrations. Repeat clickers can trigger an automatic ServiceNow ticket; campaign results can push to a security Slack channel without analyst intervention.
Scheduled Exports
Export campaign results, audit logs, and compliance evidence on a schedule to S3, Azure Blob, or SFTP. Feed your data lake, satisfy long-term retention requirements, or automate evidence collection for annual audits without manual exports.
Audit-Ready Evidence, North American Frameworks First
ASM and SAT generate exportable evidence reports for the frameworks your US Enterprise auditors check first, with Latin American (LGPD, BACEN, LFPDPPP, Argentina) and global (ISO 27001, GDPR) mappings published alongside.
HailBytes ASM — External Exposure Evidence
North American frameworks (US Enterprise priority):
- SOC 2 CC7.x (system monitoring & vulnerability identification)
- NIST CSF 2.0 (Identify, Protect, Detect)
- HIPAA Security Rule (technical safeguards)
- GLBA Safeguards Rule (Section 314.4)
- PCI DSS 4.0 (Req. 11.3 external scans)
- FedRAMP Moderate (RA-5, CM-7, SI-2, SI-4)
- NYDFS 23 NYCRR Part 500 (500.5, 500.9)
- CIS Controls v8 IG1 & IG2
Latin American · Global:
- LGPD Art. 46 (Brazil) · BACEN, LFPDPPP, Argentina mappings published
- ISO/IEC 27001:2022 (A.8.8) · GDPR Art. 32
HailBytes SAT — Training & Simulation Evidence
North American frameworks (US Enterprise priority):
- SOC 2 Type II (security awareness controls)
- NIST CSF PR.AT (awareness and training)
- HIPAA Security Awareness (annual requirement)
- PCI-DSS Requirement 12.6 (security awareness training)
- GLBA training-and-awareness expectations
Global:
- ISO 27001 A.7.2.2 (information security awareness)
- Branded PDF training certificates per completion
Buying via AWS Marketplace and Azure Marketplace
For enterprise procurement, especially international, the primary commercial vehicle is the marketplace private offer. The hyperscaler is the reseller of record, which simplifies tax, FX, and local-currency invoicing.
Private offers carry negotiated terms
Multi-year commitments, negotiated pricing, and customer-specific terms route through AWS Marketplace and Azure Marketplace private offers. The marketplace contract layer sits alongside the standard HailBytes DPA; no separate direct master agreement is required for the data-protection terms. Marketplace charges count toward AWS Marketplace Annual Spend and Azure MACC commitments, so the purchase typically draws down existing committed spend rather than adding a new procurement vehicle.
International invoicing routes through the hyperscaler
For Brazilian customers, AWS Brasil (Amazon's CNPJ-registered Brazilian entity for AWS services) or Microsoft do Brasil acts as reseller of record. They invoice in BRL and issue the Brazilian Nota Fiscal Eletrônica; ICMS, ISS, PIS/COFINS, and import-of-services tax route through the hyperscaler's established Brasil compliance infrastructure. Equivalent local-entity invoicing applies in other countries the hyperscaler supports.
Professional services bundle two ways
Professional services and onboarding bundle into the ASM private offer, or can be purchased separately via the HailBytes Support Hub SaaS listing (Azure Marketplace today; AWS Marketplace listing in flight). For Brazilian customers buying via Azure, the Support Hub SaaS subscription invoices in BRL through the same Microsoft do Brasil pipeline as the ASM license.
Direct contracts remain available
Where customer procurement prefers a non-marketplace path, direct HailBytes LLC contracts execute under the standard export-of-services arrangement. For most international customers the marketplace path produces less friction on tax and FX, which is why we lead with it. For private-offer construction or DPA counter-signature, email [email protected].
Full procurement guide (by-region invoicing-entity table, private-offer mechanics, direct-contract alternative): how to buy HailBytes → · Brazilian-specific LGPD posture: LGPD posture & procurement →
Three Deployment Topologies — Pick the One That Matches Your SLA
The same marketplace image deploys into one of three reference shapes. Enterprise customers with formal uptime SLAs almost always choose HA hot-hot; MSSPs serving multiple customers and SecOps teams with bursty workloads choose auto-scaling.
Single Instance
PoC, evaluation, single-AZ sovereign deployments, smaller enterprises (sub-5k targets) where snapshot-based recovery is sufficient. Lowest cost shape — ~$435/month all-in.
High Availability
The shape enterprise security teams choose by default. Two VMs across availability zones, ALB, Multi-AZ RDS, Multi-AZ Redis, S3 backup bucket with Object Lock, pre/post-patch SSM verifiers. ~$1,215/month all-in.
Auto-Scaling
ASG / VMSS for MSSPs, multi-region enterprises, and bursty workloads. Read replicas, rolling instance refresh with auto-rollback, ElastiCache shared session store. ~$2,250/month at 3-instance steady state; scales linearly.
Deploy in Your Account. Talk to a Solutions Engineer.
Start with a 30-day free trial through AWS or Azure Marketplace, or book 30 minutes to scope your ASM and SAT deployment against your specific compliance requirements.