Products

Two tools for shipping
secure software.

A free instant web scanner for launch-blocking issues, and VulnPilot — an open-source CLI for prioritizing what actually matters in your findings.

Available now

Web ScannerFree · No account

Instant security checks for any web application.

Paste a URL. Get a full security report — TLS health, missing headers, cookie flags, CORS policy, and exposed API keys. No account required.

  • TLS & HTTPS analysis
  • Security headers & CSP
  • Exposed API key detection
  • Cookie flag audit
  • CORS policy check
Try the scanner →
VulnPilotOpen Source · MIT

Rank vulnerabilities by exploitation probability, not severity.

Ingest your Nessus export. VulnPilot cross-references CISA KEV and FIRST EPSS to surface the findings that are actively exploited right now, then generates your SOC 2 evidence in one command.

  • Nessus CSV import
  • CISA KEV + EPSS composite scoring
  • SOC 2 & ISO 27001 evidence
  • Exception register
  • Local-only — no cloud upload
View on GitHub →

Platform — Future / Roadmap, not built yet

What's real today vs. what we might build later.

Only the Web Scanner and VulnPilot are shipped products. Everything else below is roadmap only — see the future Platform concept for what "roadmap" means here.

CapabilityDiscoverNormalizePrioritizeDecideRemediateAuditStatus
Web ScannerGA
VulnPilot (CLI)GA
Cross-repo Policy EngineRoadmap
Cross-repo Exception ManagementRoadmap
Cross-repo SLA ManagerRoadmap
Organization Evidence VaultRoadmap
AI AssistantRoadmap

Start with what's available today.

Scan a website for free, or install VulnPilot and run your first triage in minutes.