Safe scanning starts with verified scope
VulnerabilityScan verifies ownership, blocks unsafe targets, and keeps every finding tied to clear evidence.
Start freeView sample reportIncluded free during your trial.
Clear workflow for your first verified domain.
Built around transparent, industry-standard risk signals
Every priority keeps its evidence visible.
Safe by scope. Transparent by design.
Authorization, target boundaries, and scan policy stay visible from setup through remediation.
Verified target
app.northstar.dev
Recorded authorization
Verify control of every target and preserve the requester, scope, and consent in an audit trail.
Bounded scan policy
Keep scans predictable with approved checks, request ceilings, schedules, and emergency stops.
Controls that begin before the first scan
A conservative external scan policy protects your organization, your customers, and the wider internet.
- Verified ownership
- Require DNS, hosted-file, or reviewed proof of control before an active scan begins.
- Unsafe target blocking
- Reject private, loopback, link-local, metadata, multicast, and rebound addresses.
- Rate-limited jobs
- Enforce request ceilings, concurrency limits, and emergency stops centrally.
- Explainable evidence
- Keep observed behavior and contributing priority signals attached to each finding.
- Audit history
- Record scope, policy, requester, consent, and status changes for every scan.
- Tenant isolation
- Separate customer data with least privilege, encryption, and explicit retention controls.
Everything needed to keep exposure under control
From safe scanning policies to audit-ready evidence, the essentials are included in every workspace.
Continuous coverage
Schedule recurring external checks across the assets your team verifies.
Fast triage
Filter by severity, asset, exploit status, owner, and remediation state.
Public administration interface
app.northstar.dev:8443
Predictable pricing
Pay for monitored assets you select—never for every domain discovery uncovers.
Monitored assets
12 of 25
Discovery never creates surprise charges.
Enterprise‑grade security
Ownership verification, scoped policies, audit trails, and tenant-aware controls are built into the workflow.
Exposure insights
Track asset coverage, open findings, remediation progress, and risk trends at a glance.
Open risk
7
Safe scan engine
Rate-limited, non-destructive templates run only against explicitly verified targets.
Frequently Asked Questions
Clear answers about assets, safe scanning, reports, and billing.
General
Scanning and reports
Can't find what you're looking for? Contact our customer support team
Your first scan is one verified domain away
Three assets free for 14 days. No card required.
Start free