Security findings that arrive with the proof attached

ScanSuite's AI agents review your code, attack your web applications and test your infrastructure, then report only what they can back up: the call path, the exact request, or an exploit that runs. Self-hosted, so your code stays with you.

  • On-premise, private cloud or air-gapped
  • Your model: hosted, gateway or local
  • Keeps the scanners you already license
ScanSuite Products page: every product ranked by open risk, with a Needs attention list and a 12-week trend of open findings
~130k
CVEs with real exploitation evidence, held locally
44
tools the pentest agent chooses from on its own
34
web attack techniques, from SQLi to request smuggling
30+
languages read by the AI code reviewer
30+
classic scanners orchestrated alongside the agents
Why teams switch

Scanners hand you a list. ScanSuite hands you conclusions.

The expensive part of application security is not finding candidates. It is deciding which of them are real. ScanSuite moves that work to the agents and shows you how they decided.

A typical scanner stack

  • Pattern matches, by the thousandSomeone on the security team triages each one by hand.
  • Every CVE in the lock fileIncluding packages the application never calls.
  • Blind to logic flawsBroken authorization has no signature, so no rule fires.
  • Three tools, three ticketsThe same issue arrives once per scanner, in three formats.
  • A pentest twice a yearThe report is out of date before remediation starts.

ScanSuite

  • Findings that were checkedTraced source to sink, reproduced by a confirmation pass, or proven by an exploit.
  • Only exploited, reachable CVEsFour gates, from exploit evidence to whether the vulnerable API is actually called.
  • Code read like a reviewer wouldA model reasons about each file, across files, in 30+ languages.
  • One record per issueDeduplicated across engines. If a closed issue comes back, the original record reopens.
  • A pentest whenever you need oneDescribe the scope in a sentence; the agent plans, tests and proves.
Built for both sides of the table

The overview leadership needs. The evidence engineers trust.

See which product is most exposed

Every product is ranked by open risk, with overdue findings, verified secrets and failed scans called out on one page, and a 12-week trend beside them.

risk = 40·critical + 10·high + 3·medium + 1·low

Remediation deadlines that are tracked

Owners and due dates are set by severity, and overdue findings are counted. Fix verification rescans close findings on evidence and reopen them if they return.

default deadlines: 7 / 30 / 90 / 180 days

AI cost you can see and cap

Token use is recorded for every scan and priced per model, so spend shows in money by scan and product. In Teams, each team can have a monthly budget.

incremental scans pay only for what changed
The platform

Four AI engines, one pipeline of findings

Run them separately or together against the same checkout, URL or network range. Everything they report lands in one deduplicated vulnerability record.

ENGINE 01

AI static analysis

Reads the code the way a reviewer does, so it finds broken authorization and business-logic flaws that no rule describes.

  • 30+ languages, with the application's architecture as context
  • Cross-file hunt for auth, data isolation, LLM and CI/CD flaws
  • Reachability verdict with the call path drawn out
  • Incremental scans and hourly branch monitoring
Static analysis
ENGINE 02

Dependency reachability

Cuts a dependency scan down to the advisories that have been exploited and that your code actually reaches.

  • Four gates, cheapest first
  • Local exploit database of ~130,000 CVEs
  • Entry point → import → vulnerable API diagram
  • Unreachable advisories removed from every report
The four gates
ENGINE 03

AI DAST

A web scanner that chooses the technique and writes the payload for each endpoint, then reproduces the result before it reports.

  • 34 techniques, including request smuggling and Web LLM attacks
  • Detects a WAF and adapts the payload encoding
  • Confirmation pass, with the HTTP exchange kept
  • Guard against destructive payloads
Web scanning
ENGINE 04

AI pentest

An agent that plans an engagement, runs the tools, revises the plan on what it learns, and reports what it demonstrated.

  • 44 tools, from OSINT to a single crafted request
  • Drives Nessus, OpenVAS and Acunetix by API
  • Holds authenticated sessions and diffs for IDOR
  • Attack chains and a sandbox-verified PoC
AI pentest

AI-verified secrets

Gitleaks, TruffleHog and Nosey Parker results checked by the model; leaked logins can be tested live.

Infrastructure & attack surface

Network discovery with change alerts, patch checks over SSH or WMI, and domain OSINT including leaked credentials.

30+ classic scanners

Semgrep, Snyk, Trivy, KICS, Nuclei, Nessus, Acunetix and more, run in parallel in isolated containers.

Product tour

What your team works with every day

Screens from the product, unedited. Click one to see it full size.

Products page ranked by open risk
Products ranked by open risk, with a Needs attention list and a 12-week trendDocs
AI pentest, up close

The whole configuration is one sentence

There is no scan profile to tune and no attack tree to draw in advance. Give the agent a scope and, if you like, priorities. It keeps a journal of what it tried, so no work is repeated.

Illustrative journal. Real engagements record every step with its evidence.

01

Plan

Works out what to try, in what order, against which targets, and what each step should show. You can read the plan before anything runs.

02

Execute & analyze

Runs scanners, probes and crafted requests, and turns the raw output into observations. The scanners you already license become its tools.

03

Ideate & replan

Drops dead ends and adds attacks the first plan missed. The engagement follows what the target turns out to be.

04

Prove & report

Reports only what it demonstrated, with attack chains where one weakness led to another, in Markdown and XLSX.

Scope enforced in code

Targets are locked to an allow-list. An action outside it is refused before it is sent.

No shell access

The agent calls allow-listed tools with checked arguments. It never gets a free-form shell.

Sandboxed exploits

Proofs of concept run in an isolated sandbox, and exploit code is only fetched from vetted sources.

Hard budgets

Every engagement runs within a budget that guards against runaway cost, and stops once coverage is reached.

Vulnerability management

From finding to verified fix, in one place

Findings from every engine and every classic scanner follow the same path. A finding is closed when a rescan shows it is gone, and reopens if it comes back.

Deduplicated

One record per issue, however many tools report it.

Triaged

Every decision needs a reason. False positives can become suppression rules.

Owned

An owner and a due date set by severity, with overdue counts.

Fixed

A deep link to the line, the suggested fix and the evidence.

Verified

A targeted rescan closes it on evidence, or reopens it.

What a CISO gets from it

A defensible answer to "how exposed are we, and is it improving?"

Risk by product
Ranked, with a 12-week trend
Remediation
Deadlines by severity, overdue counts
Accountability
Owner, triage reason and full history per finding
Hand-off
DefectDojo (and Jira through it), ServiceNow XLSX, CSV
Products and risk

What a developer gets from it

A ticket that makes the case for itself.

Where
File and line, linked at the scanned commit
Why
Verdict, confidence and the model's rationale
How
Call-path diagram or the exact HTTP exchange
Proof
An editable proof of concept that runs
The finding record
Deployment & trust

Runs inside your perimeter. Including the AI, if you want.

For regulated teams this is usually the question that decides the evaluation, so it comes first: ScanSuite is self-hosted, and it can run with no outbound connection at all.

  • On-premise, private cloud or air-gapped

    Docker-based services on your hardware or cloud account. The offline bundle installs with no internet access.

  • One command to run it

    ./scansuite installs, updates in place with settings kept, checks health with doctor, and verifies releases by checksum.

  • Your choice of model

    Hosted OpenAI-compatible providers, Claude on Vertex AI, a gateway, or local models, with failover between them.

  • Modest to start

    4 CPU, 16 GB RAM and 100 GB of disk run 3–4 scans in parallel. Add workers as the estate grows.

Single sign-on

Entra ID and OIDC, AD/LDAP through a broker such as Keycloak, with group-to-role mapping.

Team isolation & roles

Each team's data and settings are separate. Team admin, Operator and Reader roles.

Audit logs

Separate logs for team activity and for installation administration.

Encrypted credentials

Stored scan credentials are encrypted per installation; Readers cannot see or export them.

Architecture and deployment models
Integrations

Keeps the tools you already pay for

Existing licences keep working. Their results are deduplicated with everything else, and the pentest agent can call several of them as tools.

Scanners orchestrated

  • Nessus
  • OpenVAS
  • Acunetix
  • Semgrep
  • Snyk
  • Trivy
  • KICS
  • Nuclei
  • Gitleaks
  • TruffleHog
  • Nosey Parker
  • Vuls
  • Nmap
  • + more

Code sources

  • GitHub
  • GitLab
  • Bitbucket Server
  • Any Git repository (SSH key)
  • Archive upload

Findings go to

  • DefectDojo
  • Jira (through DefectDojo)
  • ServiceNow (XLSX exchange)
  • Securitm
  • SARIF & JUnit
  • Email & Telegram alerts

AI providers

  • OpenAI-compatible APIs
  • Claude on Vertex AI
  • Ollama
  • LM Studio
  • Your own gateway
Editions

Start with one team. Grow into many.

Both editions include every scanning engine. Teams adds what an organisation with several teams needs, and an existing installation upgrades in one run.

ScanSuite

One shared installation for a security team.

  • All four AI engines and 30+ classic scanners
  • Vulnerability management, deadlines and proofs of concept
  • Local exploit database and custom rules
  • Reports, exports and DefectDojo
  • Scan scripts for CI and scheduling
  • Hosted or local models, cost per scan
Talk to us
Questions buyers ask

Before you book the demo

Does our source code leave the network?

Not with a local model: the platform, the exploit database and the model all run inside your perimeter. With a hosted provider, code is sent only to the provider you configure, under your own account.

Is it safe to point the pentest agent at our systems?

Scope is enforced in code, the agent only calls allow-listed tools, exploits run sandboxed, and every engagement has a budget. We still recommend starting against staging.

We already license Nessus, Acunetix and Snyk.

Keep them. ScanSuite runs them, deduplicates their output with the AI engines, and the pentest agent can drive Nessus, OpenVAS and Acunetix directly.

How do we keep AI cost under control?

Spend is recorded per scan and shown in money. Incremental scans re-analyse only changed files, and in Teams each team can have a monthly budget.

How are false positives handled?

AI findings can be verified before they are reported. What remains is triaged with a required reason, a false positive can become a suppression rule, and a closed issue that returns reopens its original record.

How does it fit our pipeline and ticketing?

Scan scripts run from any CI system. Teams adds a build gate with SARIF and JUnit output. Findings flow to DefectDojo and from there to Jira, or to ServiceNow by XLSX exchange.

What does it take to run?

A Docker host with 4 CPU, 16 GB RAM and 100 GB of disk handles 3–4 parallel scans. Installation and upgrades are one command, online or offline.

Which models does it work with?

Any OpenAI-compatible endpoint, Claude on Vertex AI, or local models through Ollama or LM Studio. For local use we recommend models of 30B parameters or more.

Request a demo

See it find, prove and explain on your own code

A working session on real findings, not a slide deck.

  1. 1
    A walkthrough on a sample applicationAI static analysis, dependency reachability and the pentest agent, end to end.
  2. 2
    Your deployment questions answeredAir-gapped installs, model choice, sizing and integrations.
  3. 3
    A trial installation, if it fitsRun it on your own repositories, inside your own network.

Tell us about your environment

We come back to you by email to arrange a time.

Protected by reCAPTCHA.