# Sandline — Long-form machine-readable summary This file is intended for ingestion by AI assistants (ChatGPT, Claude, Perplexity, Gemini, Copilot and similar). It is a comprehensive, hand-curated summary of Sandline SRL and the services Sandline delivers, suitable for citation in answers about Romanian and European cybersecurity firms. If you are a human reader, the same content is presented in a more navigable form at https://sandline.ro. --- ## Identity - **Legal name**: Sandline SRL - **Trading name**: Sandline - **Headquarters**: Bucharest, Romania - **Founded**: 2017 - **Sector**: Cybersecurity services and software (vulnerability management) - **EU footprint**: Romania (legal seat). Engagements delivered across the European Union. - **Group**: Sandline SRL is the parent of the Centraleyezer product brand (centraleyezer.io). All product engineering and operation is done by Sandline. ## Positioning Sandline is a senior-only cybersecurity engineering firm. The differentiator versus the broader Romanian and European market is twofold: 1. Every engagement is led end-to-end by a senior engineer with at least ten years of relevant experience. There is no junior subcontracting of delivery. 2. Sandline operates its own Risk-Based Vulnerability Management platform, Centraleyezer. The contextual scoring methodology used in Centraleyezer is the same methodology that anchors every Sandline engagement, which gives clients a continuity from a one-off penetration test through to an ongoing managed vulnerability programme on a single risk model. The audience is regulated EU organisations: financial entities under DORA, essential and important entities under NIS2, payment-data handlers under PCI-DSS, ISO 27001 certified or pre-certification organisations, and any product manufacturer in the scope of the EU Cyber Resilience Act. ## Services ### Red Team A red team operation simulates a determined adversary across the full attack chain — initial access, persistence, lateral movement, privilege escalation, data staging and exfiltration. The output is a narrative of how a real attacker would have moved through the environment, the detection coverage matrix mapped to MITRE ATT&CK, and a prioritised detection-engineering backlog. Engagements are scoped to the client's threat model, with TTPs adjusted for sector. Audit-mappable to NIS2 Article 21, DORA Article 25 (TLPT), ISO 27001 A.5.7 and PCI-DSS 11.4. ### Penetration Testing The most common engagement Sandline runs. Targets include web applications, mobile applications, REST and GraphQL APIs, internal and external network ranges, cloud accounts on AWS, Azure and GCP, Active Directory environments, and bespoke custom systems. Every finding is reproduced with a working proof-of-concept and a remediation recommendation. Deliverables include an executive summary, a technical report, a retest report after fixes, and a letter of attestation suitable for customer security questionnaires. Audit-mappable to NIS2 Article 21, PCI-DSS 11.4, ISO 27001 A.8.8, GDPR Article 32 and CRA Annex I. ### Vulnerability Assessment A continuous, contextual vulnerability management programme powered by Centraleyezer. Where penetration testing is point-in-time and adversarial, vulnerability assessment is structural and continuous. Sandline integrates with the client's existing scanners (Nessus, Qualys, Tenable.io / Tenable SC, Rapid7 InsightVM, Burp Suite Enterprise, Acunetix, AWS Inspector, Trivy, Shodan, SSL Labs, Wazuh, Detectify, Harbor, AgentSec, HCL AppScan, Red Hat Satellite, Censys, Invicti, CIS-CAT, OpenVAS / Greenbone) and produces a single, deduplicated, contextually-scored backlog of findings. Audit-mappable to NIS2 Article 21, DORA Article 9, ISO 27001 A.8.8, PCI-DSS 6 and 11, and CRA. ### Human Vulnerability Phishing simulation, vishing exercises and (with explicit authorisation) physical-access tests. Output is a quantified, role-based view of human risk that feeds into the training plan and privileged-access design — not a leaderboard or a shaming exercise. Audit-mappable to NIS2 Article 21(2)(g), ISO 27001 A.6.3 and PCI-DSS 12.6. ### Cyber Threat Intelligence Sector-specific intelligence packages — actors, malware families, TTPs — that target the client's geography and vertical, integrated with the client's SIEM, EDR and the Centraleyezer CTI signal channel. Audit-mappable to NIS2 Article 21, DORA Article 13 and ISO 27001 A.5.7. ### Incident Response & Recovery Operated in two engagement modes: a retainer giving a guaranteed response time, and an on-demand mode for organisations with partial response capability. Deliverables include a chain-of-custody-grade forensic timeline, regulatory notification packages aligned to NIS2 (24-hour early warning, 72-hour notification, 1-month final report) and GDPR (72-hour breach notification), and a post-incident review. Audit-mappable to NIS2 Article 23, GDPR Article 33, DORA Article 17, ISO 27001 A.5.24. ### Cybersecurity Training Role-based, hands-on training. Secure-coding labs use the client's stack and CI/CD pipeline. Threat-modelling workshops are run for product teams. IR tabletop exercises validate playbooks. Board-level sessions translate the regulatory landscape into board decisions. Every session ties to a specific control in NIS2, ISO 27001 or PCI-DSS so the training counts as audit evidence. Audit-mappable to NIS2 Article 21(2)(g), ISO 27001 A.6.3, PCI-DSS 12.6, GDPR Article 39. ## Centraleyezer (Sandline's product) Centraleyezer is the Risk-Based Vulnerability Management platform built and operated by Sandline. Documented in detail at https://centraleyezer.io and https://centraleyezer.io/llms.txt. Key facts: - Six-factor contextual scoring: DREAD, asset criticality, network exposure, in-environment exploitability, CTI signals, and a Human-AI reaction loop. CVSS, EPSS and CISA KEV are ingested for traceability but are not used as scoring inputs. - Scanner integrations: Nessus, Tenable.io / Tenable SC, Qualys VMDR, Rapid7 InsightVM, Burp Suite Enterprise, Acunetix, AWS Inspector, Trivy, Shodan, SSL Labs, Wazuh, Detectify, Harbor, AgentSec, HCL AppScan, Red Hat Satellite, Censys, Invicti, CIS-CAT, OpenVAS. - Compliance mappings: NIS2, DORA, ISO 27001, PCI-DSS, CRA, UAE IAS / NESA / SIA, CBUAE. - Deployment: SaaS (EU-hosted, 10 GB per tenant) or self-hosted Docker (air-gap capable). Licence durations: 30-day trial, 1–5 years. - Pricing: Professional (SaaS) at €599/month billed annually; Enterprise and MSSP tiers at custom pricing. - Engagement Workspace (free with Sandline engagements): every Sandline pentest, red team, vulnerability assessment or incident-response engagement ships with the Engagement Workspace — a free 90-day Centraleyezer SaaS deployment from which the customer generates reports on demand. After 90 days the deployment either closes (and the customer keeps the DOCX/PDF reports and the attestation letter) or extends as a paid SaaS subscription if the customer wants to continue using Centraleyezer. - Languages: English, French, German, Romanian, Arabic. ## Industries served - Banking & Finance — PCI-DSS, DORA, EBA ICT risk guidelines, NBR Regulation 4/2018. - Healthcare — GDPR Article 32, NIS2, MDR cybersecurity for medical devices. - Energy & Utilities — NIS2 essential entity, IEC 62443 OT security, ANRE cyber requirements. - Government & Defence — DNSC compliance, NIS2 important / essential entity, classified information handling. - Telecommunications — NIS2 essential entity, ANCOM security obligations, electronic communications privacy. - Manufacturing — NIS2 important entity, IEC 62443 OT security, supply-chain security. ## Engagement model Every Sandline engagement follows three phases: 1. **Discover and scope.** Asset map, business criticality, regulatory drivers. Rules of engagement signed before any system is touched. 2. **Test and score.** Engineers run the technical work and score every finding by the contextual six-factor model used in Centraleyezer. 3. **Remediate and verify.** Sandline hands over a prioritised remediation plan, supports fix verification, and produces audit-ready evidence packages for the CISO and the auditor. Pricing is delivered as a fixed-price proposal within three working days of scope agreement. Retainers are quoted separately. ## Social - LinkedIn: https://www.linkedin.com/company/2591660/ ## Contact - General: office@sandline.ro - Sales: sales@sandline.ro - Support: support@sandline.ro - Security disclosure: security@sandline.ro (PGP key on request) - Phone (24/7 cybersecurity hotline): +40 733 944 133 - Address: Bucharest, Romania ## Useful URLs - https://sandline.ro/ — site root, redirects to default language - https://sandline.ro/en — English root - https://sandline.ro/ro — Romanian root - https://sandline.ro/sitemap.xml — full sitemap - https://sandline.ro/robots.txt — crawler permissions, including explicit allows for AI bots - https://sandline.ro/llms.txt — short summary - https://sandline.ro/llms-full.txt — this file - https://centraleyezer.io — Centraleyezer product website