Contact

Start here

Tell us about your surface and the engagement you need. We reply from the red team.

Request an assessment

Opens your mail app. Nothing is stored on this page.

Help

FAQ

Do you scan anything without written authorization?

No. Every engagement carries a scope allow-list and a signed authorization. A job aimed outside the scope is refused before it starts, a kill-switch stops what is running, and every action lands in an append-only audit log.

Where do findings and evidence live?

On Altovar infrastructure in the EU. The AI assistance is optional, and in our deployment it runs only through Altovar’s own gateway: no finding reaches a third-party model service.

Which engines run the scans?

Established open-source engines for discovery, crawling, dynamic testing, TLS, secrets and code analysis, among them nmap, nuclei, httpx and trivy. Each runs in an ephemeral, hardened container, and public engine images are pinned by digest.

How is a finding prioritized?

With the Vanguard Priority Score: severity, CVSS, the probability of exploitation (EPSS), presence in the known-exploited catalog (KEV) and internet exposure add up to a 0-100 score. Every point is shown next to the reason it was given.

Can our tools or AI agents drive it?

Yes. A REST API described in OpenAPI and an MCP server expose the same operations, with tokens scoped to your organization. Stress testing is deliberately out of reach for agents.

Do you run denial-of-service tests?

Resilience testing is its own authorized, audited workflow with a kill-switch, run through an external legal provider you approve. Vanguard never generates flood traffic itself: no botnets, no amplification.