2026 · AI changed cyberattacks · continuous monitoring

What if anyone could read your customers’ data?

It used to take a hacker. Today, AI lets anyone attack a site, with zero skills. And the next flaw that hits yours could drop tomorrow morning.

Kalisecu records your site’s tech stack and checks it every week. The moment a dangerous new flaw appears anywhere in the world and affects your site, you get an email, often before the attackers use it.

Only your site, with your written consent. We never touch anyone else’s.

The risk

The day your customers get the email.

It’s not “other people, big companies” anymore. With AI, automated attacks scan the web on a loop and land on small sites, the least protected. And on the day of a breach, you don’t have six months: you have 72 hours, and customers closing the tab.

01 · THE ATTACK

It’s not a hacker anymore. It’s a bot.

Today, an AI-driven script probes your site on a loop, with nobody really steering it. One open flaw, and it’s in. It doesn’t need to target you: it targets everyone.

02 · THE 72 HOURS

Notify the authority. Then your customers.

The law is clear: 72 hours to report a breach under GDPR. If it’s serious, you also have to email your customers. They don’t read the law. They leave.

03 · YESTERDAY’S TEST

One test isn’t enough anymore.

Maybe you’ve had your site tested. But a new flaw can drop the week after and make it vulnerable overnight. A dated test doesn’t protect you from tomorrow.

Real example

You built your site with a “no-code” tool.

Many sites today (Lovable, and others) are wired to an online database. The question isn’t “is it modern?”. It’s: can a stranger open the list of your customers? If yes, we tell you. If it’s locked, we tell you that too, just as clearly.

sample checkto review with you
1  Your site is public          ok
2  Customer form                checking
3  List visible without login?  to confirm with you
4  If yes                       we show how to close it
5  If no                        nothing to panic about

The clock

72 hours. Not six months.

A breach starts a countdown. Mishandled, it can cost a GDPR fine of up to 4% of your annual revenue, and customers who don’t come back. We’re here to find the hole before, not to write the press release after.

What we do

We watch your site around the clock. In plain English.

We record your site’s tech, check it every week, and watch for new flaws as they’re published. The moment a threat hits your site, you get a clear email, not an 80-page report. You have nothing to monitor.

01

We map your stack

We note your site’s tech: the CMS, the database, the tools, the versions. It’s its ID card, and what we have to protect.

02

We scan you every week

An external check every 7 days. We test your site from the outside, the way an automated attacker would, to find the hole before it does.

03

We watch for new flaws

The moment a new flaw drops anywhere in the world, we check whether it affects your stack. Often, we know before it’s exploited.

04

We email you

“All clear” or “⚠️ Heads-up, here’s what to do”. In plain English, right away. Nothing for you to watch yourself.

KaliCertif SAS

Kalisecu is run by KaliCertif SAS, a French company. Nobody anonymous behind the screen.

Your data in France

Reports and technical data hosted at OVH and Scaleway, in France, no transit outside the EU.

Encrypted, isolated

TLS, multi-factor authentication, every client isolated. We protect what we collect, too.

Written consent required

We only test sites you own, after you sign. Never the site next door.

Plans

Monitoring that never stops.

Security is something you check over time: we test you every week and watch for new flaws as they’re published. The one-off diagnostic exists too, if you just want to see where you stand today. Prices shown, nothing without your written consent.

Diagnostic

1 site · external check, once

€99once

  • We test your site from the outside, like an attacker
  • Report delivered within 24 business hours of your go-ahead
  • Report in plain English: what’s wrong, what to do
  • Deducted from your first month if you switch to Sentinelle within 30 days
Order now

Custom

multiple sites

on quote

  • Several sites at once
  • In-depth manual pentest (beyond the auto scan)
  • Reports for your team or your clients
Request a quote

A one-off diagnostic costs €99, and it’s deducted from your first month if you switch to Sentinelle within 30 days. For the same price per month, your site is monitored all year, not just one day. We only test your sites, with your written consent.

Getting started

This week. Not in six months.

  1. You give us the site address. You confirm it’s yours.
  2. We record your stack and run the first external check.
  3. Every week we re-scan you; continuously, we watch for new flaws.
  4. You get your emails: “all clear” or “⚠️ Heads-up, here’s what to do”.

30 minutes to see if it’s for you

We look at your site, we explain in plain English what we found. Nothing more, and nothing without your consent.

Guarantee: the Diagnostic is refunded on simple request, no questions asked, within 30 days of report delivery. Or you deduct it from your first month of Sentinelle. The two benefits don’t stack: you choose.

Email bonjour@kalisecu.com

FAQ

The questions people actually ask us.

I’m too small, nobody’s going to attack me.

It’s the line we hear most, and it’s false. Most breaches aren’t a hacker who picked you. They’re bots that scan the internet non-stop and stop at the first open door, without knowing or caring who you are. A small site is often an easier target: less protected, and on the day of a breach you have no crisis team, no legal department to cushion it. Small doesn’t mean invisible.

I already have a developer / an agency handling this.

Your developer builds your site: their job is to make it work, not to attack it. Those are two different reflexes: “does it work?” isn’t “can a stranger get in?”. And nobody easily finds their own mistakes, it’s like proofreading yourself. We’re the outside eye that tests what they built, with no blame: when we find something, we tell you exactly what to ask them. Often, they fix it in five minutes.

Why a subscription, and not just a one-off check?

Because a test is a snapshot at one moment. The next day, a new flaw can drop and make your site vulnerable, without you changing a thing. With AI, automated attacks never stop. A one-off diagnostic tells you where you stand today; the subscription protects you from tomorrow too. The diagnostic alone is still an option if you just want a check-up.

Am I going to get emails all the time?

No. You get a regular “all clear” email: short, so you know someone’s watching. And a “⚠️ Heads-up” email only when there’s really something, with what to do. No spam, no needless stress.

I’m not technical. Will I understand the report?

Yes. We write the way we talk: “your customers are visible without a password” or “it’s locked”. If we’re not sure, we tell you it’s a doubt, not a disaster.

Are you going to “hack” my site?

We test your site the way a real attacker would: we look for the same open doors, the same flaws a hacker would target to grab your customer data. That’s the whole point: finding the hole before they do. But we stop there: we break nothing, steal nothing, create no fake accounts, write nothing into your database. We spot the open door, we show it to you, we don’t go in. And only on the site you authorized in writing.

What if you find a leak?

We tell you first, in plain English, with what to ask whoever built the site. We don’t notify your customers for you. We publish nothing.

Does this replace a lawyer / an official audit?

No. It’s not a “GDPR-compliant” stamp or an audit to wave in front of an investor. It’s a sentinel: we check whether customer data is exposed, regularly. The regulator side is still on you.

My site is built with Lovable / Wix / an agency. Does it work?

Yes, especially. Many breaches today aren’t a movie hacker: it’s a list left too open. That’s exactly what we’re built for. You don’t need to know how it’s built.

How much does it cost?

A diagnostic of one site is €99, once, and it’s deducted from your first month if you switch to Sentinelle within 30 days. The Sentinelle subscription (weekly check, new-flaw watch and email alerts) is €99/month with no commitment. Multiple sites, or an in-depth manual pentest: on quote. And if the Diagnostic isn’t right for you, it’s refunded on simple request within 30 days, no questions asked (refund and deduction don’t stack).

Are you going to see my customers’ data?

We don’t take it. We check whether it’s visible without a login. If it is, that’s already the problem: anyone on the internet could do the same. The report tells you, without copying your files.

Do I have to stop everything to start?

No. You give us the site address, you confirm it’s yours, we run the first check. Your site stays online.