What your domain already publishes
Cassini reads your domain's public traces and shows what an attacker sees before ever targeting you. No intrusive probing, no connection to your systems.
What Cassini does not do
Cassini looks at the facade, publicly, without testing anything. It does not hunt for vulnerabilities, it does not touch your applications and it is not a pentest. A Fleuret pentest looks behind the facade.
What a pentest sees that this cannot
Cassini reads the facade. It never touches your application, so it cannot tell you whether a logged-in user can read another customer's data. That answer takes a test, and Fleuret runs one in hours instead of the two to four weeks a consulting firm quotes, from 4,000 euros.