Vocabulary
Pricing
Policy Engine
Ranier vs Classic
100

The scoring system NowSecure Platform uses for severity that is now customizable via a calculator in Policy Engine

What is the Common Vulnerability Scoring System (CVSS)?

100

Free

How much does a mobile SBOM cost?

100

Medical technology companies can create a custom policy to help comply with this law (though it does not *certify* compliance)

What is HIPAA?

100

This new-to-Rainier UI option is easy on the eyes

What is Dark Mode?

200

The information surfaced from a Software Bill of Materials

What are the components of an app (open source libraries, closed source libraries, proprietary code)?

200

$3k

What is the price for 1 year of baseline integrated testing of 1 app?

200

These are the 2 different ways that users can apply policy coverage.

What are app level & organization level?

200

This new to Rainier feature enables users to pick just what they want to see

What is Filtering

300

The term for “dependencies of dependencies”

What are transitive dependencies?

300

$8k

What is the price for 1 year of advanced testing of 1 app?

300

The number of pre-set policies available in the Rainier release of the Policy Engine

What are the 5?

300

This new-to-Rainier UI option allows users to change how your apps are laid out on the homepage

What is view selector/card and table app view?

400

Customized compliance requirements, CVSS scores, and reprioritized findings at an organization, team, or app level.

What is a policy?

400

$16k, $24k, & $32k

What is the price for 1 year of guided testing for 4, 8, and 12 apps respectively?

400

The one industry standard available as a default policy

What is OWASP MASVS?

400

This new-to-Rainier section of the Platform security report allows users to create notes, attach useful information, and create an audit trail for analysts.

What is the "Declarations" section of the new security reports?

500

Rainier exports reports in these 2 file formats

What are .PDF & .JSON?

500

$15k


What is the cost of a full-scope mobile pentest?

500

This feature in Policy engine allows you to dynamically change how each finding is scored.

What is the CVSS calculator?

500

With this new-to-Rainier feature, users can now separate this file from the exported PDF and send it separately to their Dev teams in order to verify vulnerabilities in their code.  In Classic, this was included in the security report and could not be separated.

What is an evidence .JSON file?