Scope and authorization
Define the allow-list and record the signed authorization. Nothing runs outside it.
- Signed authorization
- RoE
- In scope
api.example.com
Target allowed within the signed authorization.
Best-of-breed open-source engines, orchestrated inside a signed scope, with every finding ranked on one explainable scale.
Recon, scanning and triage across web, network and code — one normalized findings model.
See the capabilitiesSubdomains, URL archives, ports and services, mapped and kept in scope.
Vulnerabilities, misconfiguration, secrets and TLS, in ephemeral hardened containers.
Severity, CVSS, EPSS, KEV and internet exposure on one 0-100 scale.
One-click targeted retest, and reports in HTML, Markdown, JSON and SARIF.
Explore an example engagement. Choose a target, change priority signals and check the outcome of a fix.
Interactive example. Illustrative data; no scans are run.
Define the allow-list and record the signed authorization. Nothing runs outside it.
api.example.comTarget allowed within the signed authorization.
Open-source engines run as ephemeral, hardened containers, pinned by digest.
Discover hosts and services inside the authorized scope. The result becomes input for scoped checks.
api.example.comRecon, scanning and triage across web, network and code — one normalized findings model.
Every finding scored 0-100, every point shown next to the reason it was given.
CVSS stays at 8.0 in this example.
63/100
P2This cycle
For template-based nuclei findings, repeat the same check on the same asset. Its result determines whether the finding remains open or becomes fixed.
The finding remains open. The original issue is still detected.
finding.retest-confirmedIllustrative report. Changes in the example appear here; no real scan results.
api.example.comOPEN Scope and authorization, the recon and scan pipeline, explainable priority, ATT&CK coverage, retest and reports.
Vanguard drives established open-source engines and normalizes their output into one findings model.
No engine licences: all open source. You keep the source, the data and the audit trail.
Findings and evidence stay on your infrastructure, not a third party’s cloud.
A 0-100 score you can defend line by line, not a proprietary black box.
Append-only audit log, signed authorization, kill-switch on every engagement.
Open-source engines, Postgres, an OpenAPI surface. Leave whenever you want.
Quoted on scope
For one system, one release, one deadline
On request
For teams that ship every week
On request
For security teams, on invitation
On request
No. Every engagement carries a scope allow-list and a signed authorization. A job aimed outside the scope is refused before it starts, a kill-switch stops what is running, and every action lands in an append-only audit log.
On Altovar infrastructure in the EU. The AI assistance is optional, and in our deployment it runs only through Altovar’s own gateway: no finding reaches a third-party model service.
Established open-source engines for discovery, crawling, dynamic testing, TLS, secrets and code analysis, among them nmap, nuclei, httpx and trivy. Each runs in an ephemeral, hardened container, and public engine images are pinned by digest.
With the Vanguard Priority Score: severity, CVSS, the probability of exploitation (EPSS), presence in the known-exploited catalog (KEV) and internet exposure add up to a 0-100 score. Every point is shown next to the reason it was given.
Yes. A REST API described in OpenAPI and an MCP server expose the same operations, with tokens scoped to your organization. Stress testing is deliberately out of reach for agents.
Resilience testing is its own authorized, audited workflow with a kill-switch, run through an external legal provider you approve. Vanguard never generates flood traffic itself: no botnets, no amplification.