Dimension scores are derived from public data and fields; weighted into the composite. Reference only.
purpleleaf is a continuous penetration testing platform developed and operated by Virtue Security. According to the available text, it is designed for cloud, application, and network assets, using a combination of “real human testing + intelligent automation” to provide more continuous coverage than traditional annual penetration tests. It is positioned not as a simple scanner, but as a platform-based service that combines tooling with the research capabilities of penetration testers.
In terms of protection coverage, purpleleaf focuses on continuous penetration testing, attack surface visualization, cloud asset coverage, and vulnerability retesting. In its workflow, the vendor first assesses the size and complexity of the application or infrastructure before providing a quote; the initial report is typically delivered within 1–2 weeks. After that, testing is conducted periodically throughout the year, with monthly reports and notifications for new vulnerabilities, new assets, and new applications.
For management and alerting, it emphasizes presenting the overall security posture while allowing users to drill down into low-level configuration data. It also visualizes applications and risky services, and groups findings by business unit. This is useful for organizations that need to assign remediation work to different business teams. As for integrations, the text only explicitly mentions connecting cloud assets so that cloud services remain continuously in scope for testing; it does not disclose details about API, SIEM, ticketing system, or other integrations.
Pricing is not public. purpleleaf uses a scope-based quote model: pricing is assessed according to the size and complexity of the application or infrastructure, similar to traditional annual penetration testing. Its statement that customers “pay only for what they need” suggests costs may be controlled by testing hours or coverage scope, but the specific billing unit, minimum spend, and packages are not disclosed. A usability highlight is one-click on-demand retesting, which can reduce the communication and scheduling overhead often involved in traditional retesting.
The main advantages are its longer coverage cycle, which helps reduce the long blind spots created by once-a-year penetration testing, and its combination of human testing with automation, which offers more depth than pure scanning. Attack surface visualization, business-unit grouping, monthly reports, and new-asset notifications make it well suited to continuous security governance. The drawbacks are that information on compliance certifications, SLA, support channels, payment methods, and third-party integrations is limited; the boundaries of the platform’s capabilities are also less clear than those of security products with more complete documentation.
purpleleaf is suitable for companies with cloud applications and a significant number of external network assets that want to upgrade annual penetration testing into continuous security validation. The text does not state how well it can be accessed from China. Its forms use reCAPTCHA, so access from mainland China may be affected by the network environment, but this cannot be confirmed from that alone. Payment methods are unknown. If you need local contracts, MLPS-related services, or Chinese-language deliverables, you may want to compare it with domestic providers such as Chaitin Tech, Knownsec, DBAPPSecurity, and NSFOCUS.
⚠ This review is compiled from public sources and does not constitute a purchase recommendation. Verify all facts on the vendor's official site. Verify on purpleleaf.io official site.
purpleleaf.io is an overseas Security provider. TG4G tracks its product information, an overall rating of 8.0/10, and a China-accessibility score of China direct-connect friendly. Click "Visit Official Site" to reach purpleleaf.io directly.