Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.




Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.

CSAI FoundationChaptersEventsBlog
Discover how AI is transforming phishing, business email compromise, and social engineering. Register for the free September 1 webinar →

STAR Registry Listing for

Defensio® SaaS

Defensio® SaaS

Defensio SaaS is a cloud-native External Attack Surface Management (EASM) and vulnerability scanning platform developed by Fidem S.r.l. Delivered as-a-Service with zero installation, it provides continuous monitoring of the customer's Internet-facing perimeter: asset and subdomain discovery, vulnerability detection with 115,000+ automated checks (CVEs, misconfigurations, OWASP Top 10), dark web credential monitoring, and SSL/TLS, SPF/DKIM/DMARC configuration auditing. AI-driven risk scoring correlates findings into a prioritized remediation plan with audit-ready reports. Access is protected by role-based access control with mandatory two-factor authentication; a white-label multi-tenant mode is available for MSSPs. The service is EU-hosted and operated by Fidem S.r.l., ISO/IEC 27001:2022 certified (with ISO/IEC 27017 and 27018 extensions), in full compliance with the GDPR.

Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).
Information about Defensio® SaaS
Listed Since: 08/26/2026

STAR Level 1

Cloud Controls Matrix

ValidAIted CAIQ Self-assessment v4.0.3

Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).

Created or renewed 1 day ago, on August 26, 2026.