How a scan runs, from first target to continuous monitoring
No agents to install on the target, no intrusive testing. Four stages take you from zero visibility to an always-current view of your exposure.
Add a website or repository
Point it at a website URL for passive scanning, or a repository — a local path on the server, or a public GitHub repo cloned just for the scan. Website scans are read-only: no authentication testing, no intrusive probing.
The scan runs
Website scans check headers, CSP, cookies, TLS, DNS, and mixed content in seconds. Repository scans resolve dependencies across 8 package ecosystems via OSV.dev, and check for secrets, container misconfiguration, risky code patterns, and LLM-usage risk.
Findings are scored and correlated
Each finding gets a severity and confidence rating. Related findings — within the same scan, and across scans and assets — are correlated into attack paths, so you see how issues compound rather than a flat, unordered list.
Monitoring keeps watching
Turn on monitoring for an asset and it re-scans on a schedule, tagging each finding new, persisting, fixed, or regressed against the previous run — with alerts routed to a webhook if something changes.
Scoring, in plain terms
Each scan produces an overall score and a per-category score, both 0–100. Higher severity findings with higher confidence weigh down the score more; the same math runs whether it's a single scan or a CI gate.
Watch it, step by step
Ten short walkthroughs of the real product — from your first scan to exporting your data. Every one is actual screen recording, silent with on-screen labels, and under a minute.
What this shows: The domain field, the authorisation attestation, and what happens next.
1 · Run your first website scan
What this shows: The score, the findings behind it, and the remediation package on each.
2 · Read a completed assessment
What this shows: Schedules, and why email and webhooks fire independently.
3 · Monitoring and alerts
What this shows: The DNS record or hosted file that unlocks deeper checks.
4 · Verify domain ownership
What this shows: Dependencies, secrets, containers, code patterns, and AI usage.
5 · Scan a repository
What this shows: Categories, risk weighting, and the trend that actually matters.
6 · Understand your score
What this shows: Every asset as one picture, and correlation across them.
7 · The attack surface view
What this shows: Four report types, plus SBOM and JSON for your other tools.
8 · Reports and exports
What this shows: Keys shown once, revoked instantly, and a pipeline gate you set.
9 · API keys and CI/CD gating
What this shows: Organizations with shared scope; export or erase your account yourself.
10 · Teams, and your data
Keep reading
Where most people go next
Try it on a real target
Free to start, and reading your surface in minutes.