External vulnerability scanner

Assess internet-facing risk from verified scope

Run bounded, policy-approved checks against assets you control and turn trusted results into a prioritized remediation queue.

Three assets free for 14 days. Ownership verification and explicit authorization are required before scanning.

Control comes first

DNS or HTTPS ownership proof is bound to the exact authorization record before an asset can become scan eligible.

Public destinations only

Fresh address resolution, public-address validation, connection pinning, and redirect revalidation reduce SSRF and rebinding risk.

Bounded evidence

Trusted ingestion accepts sanitized, size-limited evidence—not response bodies, cookies, secrets, or raw scanner output.

How it works

From owned scope to a remediation queue

Every run starts from a verified target and an explicit policy—not an open-ended scanner instruction.

  1. 1

    Add the exact asset

    Import one or many domains, group eligible subdomains by registrable domain, and verify control at the apex where applicable.

  2. 2

    Review the policy

    Confirm the exact targets, approved check profile, verification source, exclusions, quotas, and policy version.

  3. 3

    Run and prioritize

    Queue an admitted scan, follow bounded progress, and work trusted findings from exposure to remediation.

Platform workflow

Useful security context without an oversized console

DNS and CAA checks

Review public resolution and certificate-authority authorization signals using code-owned checks.

TLS assessment

Evaluate supported certificate and protocol conditions within the authorized target and connection limits.

HTTP safety checks

Review HTTPS redirect and supported security-header behavior with bounded response sizes and redirect validation.

Approved catalog checks

Eligible comprehensive profiles use a signed, versioned, owner-approved catalog filtered by policy and target admission.

Deterministic ingestion

Result batches are validated, ordered, deduplicated, evidence-sanitized, and tied to the exact scan attempt.

Tenant-safe workflow

Assets, scans, findings, reports, audits, schedules, and billing entitlements remain organization scoped.

What this does not replace

Clear boundaries make automated findings more useful and safer to operate.

  • The scanner does not perform destructive checks, denial-of-service behavior, broad brute force, fuzzing, or indiscriminate port scanning.
  • Automated coverage depends on the authorized profile, discovered services, catalog version, safety classification, quotas, and execution outcome.
  • A completed automated scan is not proof that an asset is vulnerability-free and is not a penetration-test or compliance certificate.
  • Private, loopback, link-local, metadata, multicast, reserved, mixed-address, and revalidated-unsafe destinations are rejected.
Questions

Know the boundary before you scan

Need to evaluate a specific use case? Talk to the team.

Know what is exposed.
Know what is exposed.

Your first scan is one verified domain away

Three assets free for 14 days. No card required.

Start free