See which product is most exposed
Every product is ranked by open risk, with overdue findings, verified secrets and failed scans called out on one page, and a 12-week trend beside them.
ScanSuite's AI agents review your code, attack your web applications and test your infrastructure, then report only what they can back up: the call path, the exact request, or an exploit that runs. Self-hosted, so your code stays with you.

The expensive part of application security is not finding candidates. It is deciding which of them are real. ScanSuite moves that work to the agents and shows you how they decided.
Every product is ranked by open risk, with overdue findings, verified secrets and failed scans called out on one page, and a 12-week trend beside them.
Owners and due dates are set by severity, and overdue findings are counted. Fix verification rescans close findings on evidence and reopen them if they return.
Token use is recorded for every scan and priced per model, so spend shows in money by scan and product. In Teams, each team can have a monthly budget.
Each AI finding carries its verdict, confidence and rationale, a call-path diagram with file:line evidence, and a link to the exact line at the scanned commit.
Generate an exploit from the finding, read it, edit it, and run it against the target in a sandbox. If it fails, the model reworks it and tries again.
Scan from CI and, in Teams, gate the build on severity or secrets. Write your own Semgrep and Nuclei rules and run them in the same scans.
Run them separately or together against the same checkout, URL or network range. Everything they report lands in one deduplicated vulnerability record.
Reads the code the way a reviewer does, so it finds broken authorization and business-logic flaws that no rule describes.
Cuts a dependency scan down to the advisories that have been exploited and that your code actually reaches.
A web scanner that chooses the technique and writes the payload for each endpoint, then reproduces the result before it reports.
An agent that plans an engagement, runs the tools, revises the plan on what it learns, and reports what it demonstrated.
Gitleaks, TruffleHog and Nosey Parker results checked by the model; leaked logins can be tested live.
Network discovery with change alerts, patch checks over SSH or WMI, and domain OSINT including leaked credentials.
Semgrep, Snyk, Trivy, KICS, Nuclei, Nessus, Acunetix and more, run in parallel in isolated containers.
Screens from the product, unedited. Click one to see it full size.






There is no scan profile to tune and no attack tree to draw in advance. Give the agent a scope and, if you like, priorities. It keeps a journal of what it tried, so no work is repeated.
Illustrative journal. Real engagements record every step with its evidence.
Works out what to try, in what order, against which targets, and what each step should show. You can read the plan before anything runs.
Runs scanners, probes and crafted requests, and turns the raw output into observations. The scanners you already license become its tools.
Drops dead ends and adds attacks the first plan missed. The engagement follows what the target turns out to be.
Reports only what it demonstrated, with attack chains where one weakness led to another, in Markdown and XLSX.
Targets are locked to an allow-list. An action outside it is refused before it is sent.
The agent calls allow-listed tools with checked arguments. It never gets a free-form shell.
Proofs of concept run in an isolated sandbox, and exploit code is only fetched from vetted sources.
Every engagement runs within a budget that guards against runaway cost, and stops once coverage is reached.
Findings from every engine and every classic scanner follow the same path. A finding is closed when a rescan shows it is gone, and reopens if it comes back.
One record per issue, however many tools report it.
Every decision needs a reason. False positives can become suppression rules.
An owner and a due date set by severity, with overdue counts.
A deep link to the line, the suggested fix and the evidence.
A targeted rescan closes it on evidence, or reopens it.
A defensible answer to "how exposed are we, and is it improving?"
A ticket that makes the case for itself.
For regulated teams this is usually the question that decides the evaluation, so it comes first: ScanSuite is self-hosted, and it can run with no outbound connection at all.
Docker-based services on your hardware or cloud account. The offline bundle installs with no internet access.
./scansuite installs, updates in place with settings kept, checks health with doctor, and verifies releases by checksum.
Hosted OpenAI-compatible providers, Claude on Vertex AI, a gateway, or local models, with failover between them.
4 CPU, 16 GB RAM and 100 GB of disk run 3–4 scans in parallel. Add workers as the estate grows.
Entra ID and OIDC, AD/LDAP through a broker such as Keycloak, with group-to-role mapping.
Each team's data and settings are separate. Team admin, Operator and Reader roles.
Separate logs for team activity and for installation administration.
Stored scan credentials are encrypted per installation; Readers cannot see or export them.
Existing licences keep working. Their results are deduplicated with everything else, and the pentest agent can call several of them as tools.
Both editions include every scanning engine. Teams adds what an organisation with several teams needs, and an existing installation upgrades in one run.
One shared installation for a security team.
For organisations where several teams share one platform.
Not with a local model: the platform, the exploit database and the model all run inside your perimeter. With a hosted provider, code is sent only to the provider you configure, under your own account.
Scope is enforced in code, the agent only calls allow-listed tools, exploits run sandboxed, and every engagement has a budget. We still recommend starting against staging.
Keep them. ScanSuite runs them, deduplicates their output with the AI engines, and the pentest agent can drive Nessus, OpenVAS and Acunetix directly.
Spend is recorded per scan and shown in money. Incremental scans re-analyse only changed files, and in Teams each team can have a monthly budget.
AI findings can be verified before they are reported. What remains is triaged with a required reason, a false positive can become a suppression rule, and a closed issue that returns reopens its original record.
Scan scripts run from any CI system. Teams adds a build gate with SARIF and JUnit output. Findings flow to DefectDojo and from there to Jira, or to ServiceNow by XLSX exchange.
A Docker host with 4 CPU, 16 GB RAM and 100 GB of disk handles 3–4 parallel scans. Installation and upgrades are one command, online or offline.
Any OpenAI-compatible endpoint, Claude on Vertex AI, or local models through Ollama or LM Studio. For local use we recommend models of 30B parameters or more.
A working session on real findings, not a slide deck.