TPRM, EASM, CTEM, cyber insurance scoring, government oversight — every use case on this site runs on the same core vulnerability management engine.
Network scanning, SBOM analysis, and exploit-aware prioritization, feeding one consistent grade.
Passive by default. Deeper, active scanning — network and vulnerability — runs only once an organization authorizes it.
Finds open ports and live services across an organization's full external footprint.
Not a sample — the full discovered attack surface.
Parses CycloneDX and SPDX bills of material, matching every declared component against known vulnerabilities.
Supply chain risk, not just network risk.
Findings ranked by EPSS, VEDAS, and CISA KEV — not raw CVSS alone — so what's actually exploitable surfaces first.
Every in-scope organization is rescanned on a recurring cadence.
Exposure is tracked as it changes, not audited once.
Grant the team that owns a finding a login restricted to exactly their own organization.
They fix it, the next scan confirms it.
Everything is backed by a REST API — findings, scores, and SBOM data are scriptable into the tools your team already runs.
Yes — upload or connect an SBOM and every declared component is matched against known vulnerabilities, not just what's visible on the network.
By severity first, then by real exploit likelihood — EPSS, VEDAS, and CISA KEV — so the queue reflects what's actually urgent.
Yes — the REST API exposes findings, scores, and SBOM data, so they can be scripted into a ticketing system, SIEM, or internal dashboard.
Always. Passive reconnaissance runs by default; network and vulnerability scanning only run once an organization explicitly authorizes it.
Network, software supply chain, and exploit intelligence — scored on one consistent scale.