Scope and authorization
/01Scans that start before anyone signed off
Allow-list, signed authorization, kill-switch
0 Jobs outside the allow-list
Scope and authorization, the recon and scan pipeline, explainable priority, ATT&CK coverage, retest and reports.
Scans that start before anyone signed off
Allow-list, signed authorization, kill-switch
0 Jobs outside the allow-list
Every tool, its own output
Open-source engines in ephemeral, hardened containers
1 Normalized findings model
A CVSS list with no order of work
Severity, CVSS, EPSS, KEV and exposure in one score
0-100 Every point accounted for
Findings read one by one
A deterministic technique map for every finding
1 Heatmap per engagement, no AI needed
A fix nobody checked
One-click targeted retest, with audit trail
4 Report formats: HTML, Markdown, JSON, SARIF
Scans that start before anyone signed off
Allow-list, signed authorization, kill-switch
0 Jobs outside the allow-list
Every tool, its own output
Open-source engines in ephemeral, hardened containers
1 Normalized findings model
A CVSS list with no order of work
Severity, CVSS, EPSS, KEV and exposure in one score
0-100 Every point accounted for
Findings read one by one
A deterministic technique map for every finding
1 Heatmap per engagement, no AI needed
A fix nobody checked
One-click targeted retest, with audit trail
4 Report formats: HTML, Markdown, JSON, SARIF
Quoted on scope
For one system, one release, one deadline
On request
For teams that ship every week
On request
For security teams, on invitation
On request
No. Every engagement carries a scope allow-list and a signed authorization. A job aimed outside the scope is refused before it starts, a kill-switch stops what is running, and every action lands in an append-only audit log.
On Altovar infrastructure in the EU. The AI assistance is optional, and in our deployment it runs only through Altovar’s own gateway: no finding reaches a third-party model service.
Established open-source engines for discovery, crawling, dynamic testing, TLS, secrets and code analysis, among them nmap, nuclei, httpx and trivy. Each runs in an ephemeral, hardened container, and public engine images are pinned by digest.
With the Vanguard Priority Score: severity, CVSS, the probability of exploitation (EPSS), presence in the known-exploited catalog (KEV) and internet exposure add up to a 0-100 score. Every point is shown next to the reason it was given.
Yes. A REST API described in OpenAPI and an MCP server expose the same operations, with tokens scoped to your organization. Stress testing is deliberately out of reach for agents.
Resilience testing is its own authorized, audited workflow with a kill-switch, run through an external legal provider you approve. Vanguard never generates flood traffic itself: no botnets, no amplification.