Solutions

What Vanguard is for

Authorized security testing, from a one-off assessment to a continuous cycle.

Engagements

Engagement types

Scoped, signed and auditable, whatever the surface.

  • 01

    External perimeter

    Map and test everything exposed to the internet, inside a signed scope.

  • 02

    Web application

    Authenticated scanning, dynamic testing and targeted exploitation checks.

  • 03

    Continuous

    Scheduled scans, KEV and EPSS watch, and retest cycles on every fix.

Coverage

What Vanguard covers

Recon, scanning and triage across web, network and code — one normalized findings model.

  • 01

    Recon

    Subdomains, URL archives, ports and services, mapped and kept in scope.

  • 02

    Scanning

    Vulnerabilities, misconfiguration, secrets and TLS, in ephemeral hardened containers.

  • 03

    Priority

    Severity, CVSS, EPSS, KEV and internet exposure on one 0-100 scale.

  • 04

    Retest and reports

    One-click targeted retest, and reports in HTML, Markdown, JSON and SARIF.

Process

How it works

Explore an example engagement. Choose a target, change priority signals and check the outcome of a fix.

Interactive example. Illustrative data; no scans are run.

Scope and authorization

Define the allow-list and record the signed authorization. Nothing runs outside it.

Signed authorization
RoE
In scope
api.example.com
In scope

Target allowed within the signed authorization.

Recon and scan pipeline

Open-source engines run as ephemeral, hardened containers, pinned by digest.

Ready to explore

Discover hosts and services inside the authorized scope. The result becomes input for scoped checks.

Normalized findings model
Target
api.example.com
Severity
High
CVSS
8.0

Recon, scanning and triage across web, network and code — one normalized findings model.

Explainable priority

Every finding scored 0-100, every point shown next to the reason it was given.

40%

CVSS stays at 8.0 in this example.

Priority

63/100

P2This cycle

Severity
+38
CVSS
+12
EPSS
+8
KEV
+0
Public-facing asset
+5

Retest and reports

For template-based nuclei findings, repeat the same check on the same asset. Its result determines whether the finding remains open or becomes fixed.

Retest
OPEN

The finding remains open. The original issue is still detected.

Audit trailfinding.retest-confirmed

Report preview

HTML

Illustrative report. Changes in the example appear here; no real scan results.

Target
api.example.com
Severity
High
Priority
P2 · 63/100
Retest
OPEN
See all capabilities
Engines

Best-of-breed, orchestrated

Vanguard drives established open-source engines and normalizes their output into one findings model.

  • subfinder
  • gau
  • naabu
  • nmap
  • httpx
  • katana
  • ffuf
  • arjun
  • nuclei
  • trivy
  • sqlmap
  • dalfox
  • sslscan
  • gitleaks
  • semgrep
  • radare2

No engine licences: all open source. You keep the source, the data and the audit trail.

Access

Quoted on scope

Engagement models

For one system, one release, one deadline

Assessment

On request

  • Scoped engagement with signed RoE
  • Recon, scan and manual triage
  • Prioritized report
  • Retest of fixed findings

For teams that ship every week

Continuous

On request

  • Recurring scheduled scans
  • KEV and EPSS watch on your findings
  • Webhook alerts to your chat
  • Retest cycles on every fix

For security teams, on invitation

Workbench

On request

  • Access to your engagements, on invitation
  • Findings, evidence and reports in one place
  • REST and MCP for your tools and agents
  • Org-scoped tokens and audit log
Help

FAQ

Do you scan anything without written authorization?

No. Every engagement carries a scope allow-list and a signed authorization. A job aimed outside the scope is refused before it starts, a kill-switch stops what is running, and every action lands in an append-only audit log.

Where do findings and evidence live?

On Altovar infrastructure in the EU. The AI assistance is optional, and in our deployment it runs only through Altovar’s own gateway: no finding reaches a third-party model service.

Which engines run the scans?

Established open-source engines for discovery, crawling, dynamic testing, TLS, secrets and code analysis, among them nmap, nuclei, httpx and trivy. Each runs in an ephemeral, hardened container, and public engine images are pinned by digest.

How is a finding prioritized?

With the Vanguard Priority Score: severity, CVSS, the probability of exploitation (EPSS), presence in the known-exploited catalog (KEV) and internet exposure add up to a 0-100 score. Every point is shown next to the reason it was given.

Can our tools or AI agents drive it?

Yes. A REST API described in OpenAPI and an MCP server expose the same operations, with tokens scoped to your organization. Stress testing is deliberately out of reach for agents.

Do you run denial-of-service tests?

Resilience testing is its own authorized, audited workflow with a kill-switch, run through an external legal provider you approve. Vanguard never generates flood traffic itself: no botnets, no amplification.