Every check, from response headers to AI usage
Passive scanning, repository analysis, AI-usage checks, monitoring, and reporting — built as one connected platform, not separate tools bolted together.
What this shows: A silent screen recording moving through the product: the dashboard's posture score and fix-first queue, the attack-surface view, the findings explorer, a scan's detail page with a finding opened, dependency risk with EPSS scores, AI usage risk, compliance mapping, the four report types, and the integrations page.
Real product footage on a representative dataset — not a mock-up.
Website scanning
Security headers & CSP
Checks for missing or misconfigured headers and Content-Security-Policy directives.
TLS & certificates
Certificate validity, chain, and configuration issues on the live endpoint.
DNS hygiene
SPF, DMARC, CAA, and DNSSEC posture for the target's domain.
Cookies & mixed content
Insecure cookie flags and HTTP resources loaded on HTTPS pages.
Subdomain visibility
Passive discovery of related subdomains as part of attack-surface context.
Repository & code scanning
Dependency vulnerabilities
Known-vulnerable packages across 8 package ecosystems, resolved via OSV.dev.
Secrets detection
Hard-coded credentials and tokens caught before they ship.
Dockerfile & Kubernetes
Common container and manifest misconfigurations.
Pattern-based SAST
Rule-based static analysis for risky code patterns.
LLM / AI usage risk
Flags patterns associated with unsafe LLM integration.
Monitoring & alerting
Scheduled re-scans
Set a monitoring interval per asset and let it run unattended.
Change tracking
Every finding is tagged new, persisting, fixed, or regressed since the previous scan.
Webhook delivery
Generic JSON, or pre-formatted for Slack, PagerDuty, Datadog, or Splunk.
Cross-scan correlation
Patterns visible only across multiple scans or assets, not a single run.
Risk & compliance
Attack-path correlation
Findings chained into narrative risk paths within a scan.
Security maturity ladder
A 5-level model tracking how your program's coverage evolves over time.
Framework situational mapping
Best-effort mapping to OWASP Top 10, NIST 800-53, CIS v8, ISO 27001, and SOC 2 — not a certification.
Exportable reports
Printable scan reports, including a compliance-audience variant.
Trust & access control
Tamper-evident audit log
Hash-chained event log you can verify end-to-end at any time.
Multi-factor authentication
TOTP-based MFA with backup codes.
Scoped API keys
Bearer tokens for CLI and CI usage, independent of session cookies.
Role-based visibility
Owner and user roles, plus organization-scoped shared visibility.
Developer workflow
CI/CD gating CLI
Fail a pipeline on score thresholds with the bundled CLI.
SBOM export
Software bill of materials generated per repository scan.
In-toto attestations
Evidence that a scan ran, for supply-chain record-keeping.
Organizations
A shared scanning scope for a team, alongside personal scans.
Keep reading
Where most people go next
See it on your own targets
Create an account and run your first scan in minutes.