Services Platform FAQ Contact Book a call

Cybersecurity for startups, SMBs and companies · LATAM

Find out what your company is exposed to. And what to fix first.

Penetration testing, vulnerabilities and data law. All in one place.

30 minutes free no strings attached

Prefer to write? contacto@arkanasecurity.com

We work aligned to

ISO/IEC 27001 NIST CSF OWASP Top 10 MITRE ATT&CK
Services

What we do for your company

Four fronts that back each other up.

Offensive

Pentesting

We attack your systems the way a real attacker would. Every finding comes with a proof of concept and the steps to close it.

Web and APIs Mobile External OWASP Top 10 Internal network Phishing
What sets us apart

Vulnerabilities and risk

We do not hand you 200 loose findings. They come sorted by impact: whatever stops your revenue comes first.

Domain scanning Code review Prioritised plan
Compliance

Data protection

If you hold customer or employee data, the law already applies to you. We leave the evidence ready for when you are asked for it.

Law 25.326 · AR Law 21.719 · CL Data leaks
Best practice

ISO 27001 alignment

The controls from the standard, at your company's scale. Without the paperwork machine of a multinational.

ISO/IEC 27001 NIST CSF Phased roadmap

Argentina

Law 25.326, in force. It already applies to you today.

Chile

Law 21.719, in force from December 2026.

We also work with the rules of Brazil, Colombia, Mexico and Peru. Arkana does not replace legal advice: it organises the technical evidence that advice needs.

Platform

Here is what it looks like inside

Pick a module and see the real screen.

Your score and risk level, at a glance. Sample data
FAQ

What people ask us first

It depends on the scope, so we do not publish a price list that ends up bearing no resemblance to the real thing. There are two formats: one-off audits paid once, and monthly monitoring plans. The 30-minute call ends with a concrete number, no strings attached.

No. Automated attacks sweep entire address ranges without caring how big the company is. Arkana is built precisely for the ones with no security team, and the scope adjusts to yours.

The platform runs in the browser, not inside your network. The only thing that connects, and only if you decide so, is a code repository, with revocable read permissions. The pentest is intrusive by definition: scope, time window and written authorisation before we touch anything.

Antivirus acts on what already reached your network. We work before that. A good share of incidents starts with a deceptive email, a reused password or a misconfigured cloud: an antivirus does not step in there.

No, and be wary of anyone who says they do: certification is granted only by an accredited body. We implement best practice aligned to the standard and leave the evidence in order, which is the work any audit will ask you for afterwards. Our own controls follow that framework and are not certified yet; we say it plainly.

Contact

Let's start with a 30-minute conversation

No middlemen and no hard sell. Pick your channel.

Or leave us your details

We reply within the next 24 business hours.

Incident in progress? Do not use the form: message us on WhatsApp.

One step to stop automated mail. There are no images to decipher.

We use your data only to reply to you, and we neither sell it nor pass it on for commercial purposes. You can request access, rectification or deletion whenever you want: it is all explained in the privacy policy (in Spanish).

Message us
Book a call