Professional Penetration Testing, On-Demand
Identify vulnerabilities in your infrastructure with automated scans. Receive digitally signed PDF reports with RFC 3161 timestamps.
The only Freemium vulnerability scanning service in the world
RFC 3161 signed reports
EITCA/EITC Certifications
GDPR Compliant
Mandatory target ownership verification
How it works
Sign up and use free credits
Create your free account and purchase a credit package. Pay only when you want.
Verify target ownership
Prove that you own the domain or IP via DNS TXT record or HTTP file. No scanning without authorization.
Launch the scan and receive your report
Start the scan and receive a digitally signed PDF report with RFC 3161 timestamp. Email notification upon completion.
Advanced features
Beyond scanning: tools built for managing many assets.
Multiscan
Scan dozens of targets in parallel from a single session, with aggregated status and reports.

Geographic map
Geolocate IPs and hosts on a map: see where your assets β and exposed ones β are hosted. Find bottlenecks along the route.

3D scan view
Explore results in 3D: ports, services and CVEs on interactive concentric rings.
Anti-WAF rescan
Verify fixes even behind Web Application Firewalls, with resilient rescan techniques.
Intrusive scan
Deep mode: uncovers hidden versions of daemons and services (SSH, FTP, mail) not exposed by default.
Presets
Save recurring configs and target lists and relaunch them in one click.
Dedicated Scans
Keep your infrastructure under control
WordPress
Targeted WordPress scan: core, themes and plugins. Detects vulnerable versions and known CVEs on installed plugins, even behind catch-all reverse proxies.
WooCommerce
Dedicated check for WooCommerce stores: REST endpoints, checkout flow and e-commerce plugins, to protect orders and customer data.
Magento
Specific audit for Magento and Adobe Commerce: version, missing security patches and exposed components of your store.
Joomla
Tailored scan for Joomla: core, extensions and templates, matching known CVEs against detected versions.
PrestaShop
Dedicated check for PrestaShop: CMS version, modules and themes, to surface known vulnerabilities in your store.
Targeted CVE
Targeted scan on one or more specific CVEs: precisely verify whether your asset is exposed to a vulnerability you care about.
AI Reports
Not just the list of vulnerabilities: a security analysis written by AI
The system can analyze complex scans and adds, alongside the usual list of vulnerabilities, a security analysis generated by AI: it puts the findings in context, highlights the real priorities and explains risks and fixes in plain language, even for non-experts.
Details βTargeted Rescan
Verify fixes without repeating the entire scan
After fixing a vulnerability, verify the fix with a Targeted Rescan. Only 5 credits per vulnerability. Batch rescan to verify multiple fixes in parallel.
Aruba legal timestamp
Legally valid proof, no notary needed
Certify your reports with a qualified Aruba timestamp (RFC 3161): the document's date and time become proof that holds up against third parties, with full legal value. A notary would charge β¬50β150 per deed for the same certainty. Useful for audits, compliance (ISO 27001, GDPR, NIS2) and disputes.
API + AI
Automate scans with a script or an AI agent
Everything you do from the dashboard is available via the REST API: launch scans, track their status, download reports. With our MCP server an AI agent (e.g. Claude) can run scans autonomously, authenticating with a personal API key.
Learn more βPlans
Recurring credits every cycle, with rollover. Cancel anytime.
Starter
For small sites and first tests
- All scan types (Network, Web, Vulnerability, Full)
- RFC 3161 signed PDF reports
- Targeted Rescan included
- Rollover credits (never expire)
- Email support
Medium
For professionals and SMBs
- Everything in Starter
- Real-time terminal log
- Priority scan queue
- Bulk multi-target multiscan
- Priority support
Maxi
For agencies and many domains
- Everything in Medium
- API access
- Dedicated scan satellite
- Dedicated account manager
- Guaranteed SLA
Enterprise
For special needs, get in touch
- High scan volume
- Enterprise service
- Tailored service
- Dedicated consulting
Don't hesitate to contact us for product upgrades or specific requirements for your company!
Latest CVE vulnerabilities
High-severity vulnerabilities published in the last 30 days
Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by connecting to the exposed H2 database web console using default shipped...
IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to view arbitrary...
IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data.