The security your first large customer is going to ask for
The programme opens Aranis to early-stage startups that have to answer a security questionnaire before they have a GRC team. Entry is by application, not by card.
What the programme opens
Third-party risk
Assess who you hire with a structured questionnaire, a vendor portal and an automatic score.
Cyber risk
Measure your own posture against the frameworks the buyer will name — NIST CSF 2.0 and SOC 2.
Privacy risk
Data protection compliance under LGPD and GDPR, from the inventory to the processing record.
A scan of your own domain
DNS, TLS, DMARC and reputation: what your startup exposes to the internet, seen from outside.
Aranis Academy
Seats in the course catalogue, so the team learns the vocabulary alongside the tool.
Aranis Training
Hands-on simulation tracks to exercise risk decisions before the incident is real.
Who it is for
- ✓An early-stage startup building its security programme now — not replacing one that already exists.
- ✓Someone named as owner of the security answer, even if it is not their main job.
- ✓A concrete need: a customer questionnaire, investor due diligence, or a certification in sight.
- ✓An active CNPJ — the programme is for an incorporated company that is trading.
Applications are read one by one. Commercial terms travel in the reply.
How it works
- 1You send the application with your startup’s context and what prompted the search.
- 2We read it and reply with the terms — duration, scope, and what the programme covers in your case.
- 3If you accept, the account is provisioned and you start with whatever is closest to blocking a deal.
Participation lasts at most 24 months, with the first review at 12. At the end of each period, continuing depends on a new application — without one, the account moves to the free plan and the data is kept.
Aranis for Startups application
Three steps. The answers decide eligibility, so being specific pays.