A white hat for your company.
A small company has the same exposed surface as a big one — a website, a mail server, a handful of services — but rarely the budget for a yearly pentest. Beli Klobuk is a security agent that maps what is exposed, checks your domains and mail reputation, hunts typosquats, and hands you a report with the findings in the order to fix them.
First Look entry package · early access · launching soon
A first look, then a deeper test only with your word
The entry package is passive — it looks at what is already visible. Anything intrusive happens only after you confirm written authorisation, and it runs in a sandbox.
First Look
A passive assessment of your exposed surface, domains, mail reputation and typosquats. No intrusive testing — only what is publicly visible.
Report
Findings in priority order, written for a person who has to decide what to fix first. In Slovenian.
Authorise
If you want a deeper, active test, you confirm written authorisation for the assets in scope. The agent will not test anything outside it.
Active test
A multi-agent security agent runs the authorised test in an isolated sandbox, step-limited and time-boxed, and extends the report.
The things a small company is actually exposed on
Not a hundred-page report nobody reads. The handful of things that are both likely and worth fixing.
surfaceWhat of yours is reachable from the internet — sites, services, open ports.mailSPF, DKIM and DMARC on your mail domain; whether someone can spoof you.domainsTyposquats and look-alike domains registered to impersonate you.reputationWhether your mail server or IP is on a blocklist that hurts deliverability.TLSCertificates about to expire, weak configuration, mixed content.known issuesPublic, known weaknesses on the versions you are visibly running.Active testing is bound to your written word
This is the part a serious buyer asks about first, and the part that keeps everyone out of trouble.
Enforced in code, not a checkbox. The agent performs active security testing only against assets you own and only after confirmed written authorisation for exactly those targets. The check lives in the code path, so a scan outside the authorised scope does not run.
Sandboxed execution. Tools run in an isolated environment, step-limited and time-boxed, so a run cannot wander off your targets or loop. A tool that cannot reach the authorised target simply has no path.
Your report, your call. Findings stay with you, in priority order, with what to do about each. Beli Klobuk tells you where you are exposed; the fix is yours to schedule.
Companies that fall through the gap
A yearly penetration test from a consultancy starts in the thousands and takes weeks to schedule. Most small companies and startups simply skip it — and carry the same exposed surface unchecked. Beli Klobuk is the first look they can actually act on: a report they can read and a clear next step if they want to go deeper.
Questions buyers ask
Is this legal? You are testing systems.
Active testing runs only against assets you own and only after you have confirmed written authorisation in the system. That check is enforced in code, not a checkbox on a form, and execution runs in an isolated sandbox. The passive first look needs only a domain you control.
What do I get for the entry package?
The First Look is a passive assessment: your exposed surface, domain and mail-reputation checks, typosquats and known issues on what is publicly visible — no intrusive testing. You get a readable report with findings in priority order. It is the lowest-commitment way to see whether a deeper, authorised test is worth it.
We are a small company, not a bank. Do we need this?
A small company has the same exposed surface as a large one — a website, a mail server, a few services — but rarely the budget for a yearly pentest. Beli Klobuk exists for exactly that gap: a first look small companies can actually act on, with a clear next step if they want to go deeper.
Does my data or my systems leave the building?
The agent reports to you. Findings and the report stay with you. Active testing is sandboxed and scoped to the targets in your authorisation; a tool that cannot reach the authorised target has no path out.
Is the report in Slovenian?
Yes. The interface and the reports are in Slovenian; the agent works internally in English and translates. The findings and the priority order are written for a person who has to decide what to fix first, not only for a security specialist.