A full vulnerability scanner pointed at a site you own — mapped, attacked, graded on one severity ramp, and written up so the person who has to fix it can read it.
DNS, WHOIS, SSL, open ports and a screenshot — collected before the scan so it knows what it is looking at.
The spider maps the site. Nothing is attacked until there is a map to attack.
Active scanning against what was mapped, with the policy you picked.
Findings deduplicated and grouped, then placed on one severity ramp — six links, one verdict.
HTML, PDF, JSON, SARIF, and compliance views for OWASP, PCI DSS and NIST.
A scanner that overstates is worse than no scanner. These are the rules it holds to.
If the target could not be reached, the run is reported as failed — never as a clean result with zero findings.
Severity is decided in exactly one place. A CVE is shown as evidence beside a finding, never as a reason to re-grade it.
Each scan gets a fresh scanner session, so last month's alerts cannot leak into this month's numbers.
Hundreds of raw alerts become a handful of findings with instance counts, so the list is one a human can work through.
A v1 REST API with per-client bearer keys, so another product can queue scans and read findings without a browser.
Built for people who look after other people's websites — each account's scans and findings stay its own.
Accounts here are opened by arrangement. Tell us what you need scanned.
Request access