Aranis for Startups

The security your first large customer is going to ask for

The programme opens Aranis to early-stage startups that have to answer a security questionnaire before they have a GRC team. Entry is by application, not by card.

What the programme opens

Third-party risk

Assess who you hire with a structured questionnaire, a vendor portal and an automatic score.

Cyber risk

Measure your own posture against the frameworks the buyer will name — NIST CSF 2.0 and SOC 2.

Privacy risk

Data protection compliance under LGPD and GDPR, from the inventory to the processing record.

A scan of your own domain

DNS, TLS, DMARC and reputation: what your startup exposes to the internet, seen from outside.

Aranis Academy

Seats in the course catalogue, so the team learns the vocabulary alongside the tool.

Aranis Training

Hands-on simulation tracks to exercise risk decisions before the incident is real.

Who it is for

  • ✓An early-stage startup building its security programme now — not replacing one that already exists.
  • ✓Someone named as owner of the security answer, even if it is not their main job.
  • ✓A concrete need: a customer questionnaire, investor due diligence, or a certification in sight.
  • ✓An active CNPJ — the programme is for an incorporated company that is trading.

Applications are read one by one. Commercial terms travel in the reply.

How it works

  1. 1You send the application with your startup’s context and what prompted the search.
  2. 2We read it and reply with the terms — duration, scope, and what the programme covers in your case.
  3. 3If you accept, the account is provisioned and you start with whatever is closest to blocking a deal.

Participation lasts at most 24 months, with the first review at 12. At the end of each period, continuing depends on a new application — without one, the account moves to the free plan and the data is kept.

Aranis for Startups application

Three steps. The answers decide eligibility, so being specific pays.