Who we are
Vanguard is the red-team workbench Altovar built for authorized offense: self-hosted, precise, cold.
The workbench, not the scanner
Competitors sell a scanner with a dashboard. Vanguard is a workbench: recon, scan, prioritize, retest — self-hosted, auditable, agent-drivable. The operator stays in the loop and the evidence stays on the record.
Why teams choose it
- 01
Self-hosted, EU-native
Findings and evidence stay on your infrastructure, not a third party’s cloud.
- 02
Explainable priority
A 0-100 score you can defend line by line, not a proprietary black box.
- 03
Auditable by design
Append-only audit log, signed authorization, kill-switch on every engagement.
- 04
No lock-in
Open-source engines, Postgres, an OpenAPI surface. Leave whenever you want.
Built to be audited
- 0
- Jobs outside the allow-list, enforced before every scan
- 0-100
- Priority scale, every point accounted for
- 4
- Report formats: HTML, Markdown, JSON, SARIF
What Vanguard will not do
-
No surveillance
No human or mass surveillance. This is a testing workbench, not a spying tool.
-
No weaponry
No botnets, no amplification, no denial-of-service weapons. Only controlled, authorized resilience testing.
-
In scope only
Every action inside a signed authorization, on the record, or it does not run.
Quoted on scope
Engagement models
For one system, one release, one deadline
Assessment
On request
- Scoped engagement with signed RoE
- Recon, scan and manual triage
- Prioritized report
- Retest of fixed findings
For teams that ship every week
Continuous
On request
- Recurring scheduled scans
- KEV and EPSS watch on your findings
- Webhook alerts to your chat
- Retest cycles on every fix
For security teams, on invitation
Workbench
On request
- Access to your engagements, on invitation
- Findings, evidence and reports in one place
- REST and MCP for your tools and agents
- Org-scoped tokens and audit log
FAQ
Do you scan anything without written authorization?
No. Every engagement carries a scope allow-list and a signed authorization. A job aimed outside the scope is refused before it starts, a kill-switch stops what is running, and every action lands in an append-only audit log.
Where do findings and evidence live?
On Altovar infrastructure in the EU. The AI assistance is optional, and in our deployment it runs only through Altovar’s own gateway: no finding reaches a third-party model service.
Which engines run the scans?
Established open-source engines for discovery, crawling, dynamic testing, TLS, secrets and code analysis, among them nmap, nuclei, httpx and trivy. Each runs in an ephemeral, hardened container, and public engine images are pinned by digest.
How is a finding prioritized?
With the Vanguard Priority Score: severity, CVSS, the probability of exploitation (EPSS), presence in the known-exploited catalog (KEV) and internet exposure add up to a 0-100 score. Every point is shown next to the reason it was given.
Can our tools or AI agents drive it?
Yes. A REST API described in OpenAPI and an MCP server expose the same operations, with tokens scoped to your organization. Stress testing is deliberately out of reach for agents.
Do you run denial-of-service tests?
Resilience testing is its own authorized, audited workflow with a kill-switch, run through an external legal provider you approve. Vanguard never generates flood traffic itself: no botnets, no amplification.