For agencies & MSPs
Run and schedule scans across your entire client portfolio from one account - subdomain discovery, team seats for the whole account team, and an API/MCP integration for whatever tooling you already run.
4 domains · one dashboard
client-acme.com
Last scanned 2 hours ago
client-brightpath.io
Last scanned yesterday
client-northwind.co
Last scanned 3 days ago
client-summit-labs.com
Last scanned 1 week ago
Features for agencies & MSPs
Scanning
Web server software disclosed in response headers (Apache, nginx, IIS, PHP, and more) is matched against the National Vulnerability Database, with the exact version and CVE ID shown for anything found.
Scanning
Detects the CMS or e-commerce platform a site runs on - WordPress, Joomla, Drupal, Magento, Shopify, Wix, Squarespace, Webflow, and more - and checks any self-hosted, version-disclosed platform against the National Vulnerability Database.
API Security
Finds REST, GraphQL, and SOAP APIs via OpenAPI/Swagger specs, GraphQL introspection, WSDL definitions, and a common-path scan of both a wordlist and your site's own JavaScript - then runs safe, non-destructive tests on each: does it require auth when it should, is GraphQL introspection left open in production, does it leak data via misconfigured CORS.
AI Pentesting
Sandboxed runs of sqlmap (SQL injection, including login forms), dalfox (XSS), ffuf (hidden parameter discovery), nuclei (exposure & misconfiguration deepening), and jwt_tool (JWT weak-secret cracking) against targets your scan already flagged - a fixed toolkit, not an AI improvising attacks.
AI Pentesting
Every confirmed finding carries the exact request and response that proved it, not just a plausible-looking signal - and results that were blocked or inconclusive (a WAF, a TLS handshake failure) are labelled as such rather than shown as a false clean or false positive.
AI Pentesting
Each run happens in an ephemeral, isolated sandbox with network egress scoped to only the domain being tested. Requires its own explicit consent checkbox on top of Active Testing's - real exploitation attempts, not passive observation.
AI Pentesting
Computed only from confirmed pentest findings and shown alongside - never blended into - your overall security score and your Active Testing Score, so you can see exactly what real exploitation attempts found.
AI Pentesting
A dedicated, auditor-ready PDF scoped to pentest results only - proof-of-exploit evidence included - separate from both your main report and your DAST report.
AI Pentesting
The Pentest Report PDF is bundled into the same audit evidence ZIP export as your main and DAST reports, ready to hand to an auditor without hunting down a third download.
Expert Mode
Switch your team into Expert Mode to get named, reusable Scan Profiles: requests-per-second throttling, crawl depth and page limits, retries/backoff, custom User-Agent/headers/cookies, and URL exclusions - so a scan behind an aggressive WAF slows down instead of getting blocked halfway through.
Expert Mode
Turn individual tools (sqlmap, dalfox, ffuf, nuclei, jwt_tool) on or off per Scan Profile, exclude specific paths from testing, and opt into an Aggressive tier (elevated sqlmap risk/level, dalfox WAF-bypass) behind its own explicit liability confirmation.
Expert Mode
See real request counts, throttle rate, and retries as a scan runs, and every finished report carries a summary of exactly which Scan Profile settings applied - so what ran is never a guess.
DNS & Subdomains
Finds forgotten staging, dev, and admin subdomains via common-name enumeration plus a certificate transparency log lookup (real hostnames a public CA has issued a certificate for), with a quick reachability check on each - and a one-click button to run a full scan on any of them.
DNS & Subdomains
Every discovered subdomain's CNAME record is checked against commonly-hijacked services (GitHub Pages, Heroku, S3, Azure, Netlify, and others) for dangling or unclaimed targets an attacker could register and serve content from.
Scanning
When you scan a bare IP directly, a passive connect-only probe checks common non-web service ports (databases, remote access, file transfer) for exposure, captures any banner offered, and runs a reverse DNS (PTR) lookup - never sends payloads or attempts exploitation.
AI Investigation
An AI agent crawls your entire site - or a defined scope - running all 8 layers on every page it decides is worth investigating.
AI Investigation
A ranked top-25 fix list from your latest scan, deduplicated and written in plain English, exportable as a PDF you can hand straight to a client or developer without them opening the full report.
Reports
Every scan you run is preserved indefinitely. Filter by domain, date, or severity to find any past report instantly.
Reports
Side-by-side diff between any two scans of the same site. See exactly what findings are new, what has been resolved, and what has changed severity.
Reports
Put your own logo, name, accent colour, and font on every PDF report, DAST report, and evidence package you export - no Decloak branding, ready to hand straight to your clients.
Automation
Set a weekly, monthly, or quarterly cadence and scans run automatically. Never miss a security check-in for SOC2, ISO 27001, NIS2, or DORA again.
Automation
Push findings to any system - Jira, Linear, PagerDuty, or your own. Signed payloads (HMAC), per-endpoint event selection, and a delivery log.
Automation
Trigger scans programmatically and pull results via a REST API - poll status, fetch findings, list scans for a domain. Full OpenAPI docs included.
Automation
Let Claude, Cursor, or any MCP-compatible AI agent trigger scans and poll results directly - create_scan, get_scan, list_scans, and wait_for_scan tools, no glue code required.
Support
A chat assistant that knows your scan results - ask it to explain a finding, walk through remediation, or find the right guide, right from the report or dashboard you're already on.
Team
A glanceable, colour-coded report card for your whole account and every domain - security score, findings by severity, DNS/TLS posture, active testing, and compliance coverage all in one grid. Free for every account; paid tiers unlock more tiles as you upgrade.
Team
Your account shows all scans organised by domain - current grade, last scanned, open findings. Free for all accounts. Pro adds team sharing and bulk actions.
Team
Invite team members with role-based permissions. Developers see findings and remediation; managers see scores and reports; admins manage everything.
Team
Tag any finding to a specific team member, with bulk-assign by category or by scan. A dedicated "My Assigned Findings" page tracks status and remediation notes.
Starter and up
Nobody wants to walk a client through a 40-page report. The Priority Remediation Plan turns each domain's scan into a ranked top-25 list with plain-English AI guidance, exportable as a branded PDF - send it as-is, or use Pro's status/assignment tracking to show the client exactly what your team is already working on.
Every finding scored by severity, then whether a CVE is involved, then how long it has sat open - so the list is always "fix this first," not just "everything we found."
Each item comes with specific, actionable remediation advice - not a CVE ID and a shrug.
Hand a finished plan straight to a client or developer - no one has to click into individual findings to know what to do next.
Mark items Open, In Progress, or Resolved and assign them to a teammate, right from the plan - a Pro-plan upgrade on top of Starter.
Pricing
Pro and Enterprise both include team seats and a multi-domain dashboard - no per-client billing.