Products
Two tools for shipping
secure software.
A free instant web scanner for launch-blocking issues, and VulnPilot — an open-source CLI for prioritizing what actually matters in your findings.
Available now
Instant security checks for any web application.
Paste a URL. Get a full security report — TLS health, missing headers, cookie flags, CORS policy, and exposed API keys. No account required.
- TLS & HTTPS analysis
- Security headers & CSP
- Exposed API key detection
- Cookie flag audit
- CORS policy check
Rank vulnerabilities by exploitation probability, not severity.
Ingest your Nessus export. VulnPilot cross-references CISA KEV and FIRST EPSS to surface the findings that are actively exploited right now, then generates your SOC 2 evidence in one command.
- Nessus CSV import
- CISA KEV + EPSS composite scoring
- SOC 2 & ISO 27001 evidence
- Exception register
- Local-only — no cloud upload
Platform — Future / Roadmap, not built yet
What's real today vs. what we might build later.
Only the Web Scanner and VulnPilot are shipped products. Everything else below is roadmap only — see the future Platform concept for what "roadmap" means here.
| Capability | Discover | Normalize | Prioritize | Decide | Remediate | Audit | Status |
|---|---|---|---|---|---|---|---|
| Web Scanner | GA | ||||||
| VulnPilot (CLI) | GA | ||||||
| Cross-repo Policy Engine | Roadmap | ||||||
| Cross-repo Exception Management | Roadmap | ||||||
| Cross-repo SLA Manager | Roadmap | ||||||
| Organization Evidence Vault | Roadmap | ||||||
| AI Assistant | Roadmap |
Start with what's available today.
Scan a website for free, or install VulnPilot and run your first triage in minutes.