Attacker's-eye security, validated by AI — inside-out & outside-in

The watchtower that proves what's exploitable

heimdallX scans your web, cloud and code like a world-class hacker and proves what's actually exploitable with EPSS, CISA KEV and safe active testing — then watches the outside world, from leaked credentials and dark-web chatter to ransomware, ranked by TALON. Adversary emulation, continuous monitoring and board-ready governance, in one AI dashboard.

Scan your domain freeSee it in action

No credit card required · Real results in minutes · Cancel anytime

EPSS · KEV
exploitability validation
TALON · ATOM
external-threat scoring
ATT&CK
adversary emulation
24/7
continuous monitoring
heimdallXheimdallx.ai/appYheimdallXBUSINESSAI credits2.1k/45kAI analystNew scan[email protected]EnglishSign outAWorkspaceAcme SecurityPProjectProductionCommand centerOperationsExternal ThreatsOverviewExecutive BriefFindings15Remediation6Assets3DiscoveryAttack SurfaceBreach SimThreat IntelIncidents12MonitoringCompliance9IntegrationsActivityExternal Threats38Threat FeedAI BriefingAll modulesWeb & AssetsDigital ExposureCode SecurityCloud (CSPM)↓ CSVPDF reportNew Web Scan×Web & AssetsDigital ExposureCode SecurityCloud (CSPM)acme.comRun scanReal recon: DNS, subdomains, TLS, security headers, fingerprint + AI analysis.Active validation — I own this target and authorise non-destructive probes.C70/100Targetacme.comAI summaryThe acme.com scan found 7 items (3 medium, 2 low, 2 info). Prioritise the most severe first.PipelineScanning…DNS & Subdomains4 IPs, 0 subdomainsTLS / CertificateTLSv1.3, expires in 69dHTTP Security Headers7 header issuesTechnology Fingerprintcloudflare, Next.jsExposed ServicesSkipped (no active-scan consent)Breach ExposureSkipped (no breach API key)API Security (OpenAPI)No public OpenAPI spec foundActive Vulnerability ValidationSkipped (enable on an owned asset)AI Analysis2 AI findingsImprovement room2 assets haven't been scanned recently — re-scan to stay current.38 external threats awaiting triageRun scan ›B80Security posture80/100▲ +10Average of your assets' latest scoresvs industry benchmark80 / 72Open findings150 critical/highPriority actions6deduplicated, ranked by impactAssets323 scans runLast scan3h agocontinuous monitoring onExternal threats38Compliance controls9Scan coverage2/4Risk trendPosture score across recent scans, oldest → newestbenchmark 7280Posture by moduleC74Web & Assets74A92Digital Exposure92Findings15totalSearch title, asset, category…All15Medium6Low4Info5All modulesAll categoriesMEDIUMMissing HSTS headeracme.com · Web & Assets · HTTP HeadersMEDIUMMissing Content-Security-Policyacme.com · Web & Assets · HTTP HeadersMEDIUMCookie missing Secure/HttpOnly flagsacme.com · Web & Assets · SessionMEDIUMMissing HSTS headerapi.acme.io · Web & Assets · HTTP HeadersMEDIUMMissing Content-Security-Policyapi.acme.io · Web & Assets · HTTP HeadersMEDIUMLook-alike domain registered: acrne.example[email protected] · Digital Exposure · Brand ProtectionLOWMissing X-Frame-Options / frame-ancestorsacme.com · Web & Assets · HTTP HeadersLOWMissing X-Content-Type-Optionsacme.com · Web & Assets · HTTP HeadersLOWMissing X-Frame-Options / frame-ancestorsapi.acme.io · Web & Assets · HTTP HeadersFix-first priorityIdentical issues are grouped across assets and ranked by risk-reduction impact — fix once, resolve everywhere.Actions6Multi-asset4Total impact60Program reportMTTR (median)2dSLA compliance89%Started85%Exposure removed36Reopen rate5%Open item age0-78-3031-9090+619 resolved · 2 accepted · 2 false positiveConfidence calibrationaligned1MEDIUMMissing HSTS headerHTTP Headers · Web & AssetsAssets2impact162MEDIUMMissing Content-Security-PolicyHTTP Headers · Web & AssetsAssets2impact163MEDIUMCookie missing Secure/HttpOnly flagsSession · Web & AssetsAssets1impact84MEDIUMLook-alike domain registered: acrne.exampleBrand Protection · Digital ExposureAssets1impact85LOWMissing X-Frame-Options / frame-ancestorsHTTP Headers · Web & AssetsAssets2impact66LOWMissing X-Content-Type-OptionsHTTP Headers · Web & AssetsAssets2impact6External ThreatsDRPDigital Risk Protection — leaks, dark-web and Telegram chatter, malicious/C2 IOCs, ransomware victim posts and brand abuse, cross-matched against your assets and ranked by TALON.MonitoringCollect nowTotal39Matched4Critical2Allowed types6TotalLeaks4Dark web · Telegram5Brand1ATOMGraphCRITICAL203.0.113.66 · malicious infrastructureIOC · abuse.ch/ThreatFox · NightjarTALON 88CRITICAL[email protected] credential leak자격증명 유출 · Combolist (dark web)TALON 86HIGH198.51.100.7 · Cobalt Strike C2IOC · abuse.ch/ThreatFoxTALON 79HIGHLockBit victim post — acme-supplier.example랜섬웨어 · ransomware.live · LockBitTALON 74HIGHCollection #1 콤보리스트에 포함된 기업 자격증명자격증명 유출 · leaks · acme.comTALON 73HIGH다크웹 게시 — 제목에 프롬프트 인젝션 문구 포함 (방화벽 차단)다크웹 · Dark-web forum · exploit.inTALON 71HIGH[email protected] credential leak자격증명 유출 · Cracked.ioTALON 68MEDIUMacrne[.]example look-alike브랜드 사칭 · OpenPhishTALON 61

01AI agents probe your domain like a real attacker — first findings in minutes

02One benchmarked posture score — know exactly where you stand

03Every critical proven exploitable — EPSS, CISA KEV & safe active testing

04A fix-first queue ranked by what's actually exploitable, not just severity

05Now watching the outside too — leaks, dark web & ransomware, ranked by TALON

One platform, three watchtowers

Most teams juggle a scanner, a breach monitor and a code tool. heimdallX fuses all three into one attack-surface graph — every finding validated for exploitability, correlated inside-out and outside-in, and explained by the same AI analyst.

Web, Cloud & Asset Scanning

Point heimdallX at a domain and an orchestra of AI agents probes it like an attacker would — across web, cloud and exposed services — then proves what's actually exploitable and chains it into real attack paths.

  • DNS, TLS, headers, tech & cloud posture (CSPM)
  • Exploitability validation — EPSS · CISA KEV
  • Safe active testing — proof, not guesses
  • Attack-surface graph & breach simulation
  • Continuous monitoring + AI-prioritized fixes

External Threats & Digital Risk Protection

Know what the internet knows about you — and what attackers are already doing outside your perimeter. Continuous DRP across leaks, dark-web & Telegram chatter, ransomware victim posts, brand abuse and malware IOCs, correlated to your assets and distilled into an AI briefing.

  • Leaked-credential & breach alerts (HIBP)
  • Dark-web, Telegram & ransomware-site monitoring
  • Look-alike / phishing brand-abuse detection
  • Malware & C2 IOCs correlated to your assets
  • TALON scoring + ATOM account-takeover chains

Code Security

Connect a repository and let AI hunt the business-logic flaws scanners miss, scan your dependencies and secrets, and feed every code CVE into the same exploitability-ranked queue.

  • Business-logic vulnerability detection
  • Secret & credential scanning
  • SCA / SBOM — OSV-matched dependency CVEs
  • Code CVEs flow into the fix-first queue
  • AI remediation — PR-ready fix prompts
Beyond detection

Validation, adversary emulation & enterprise controls

Detection is table stakes. heimdallX proves what's exploitable, emulates the adversary, watches your surface around the clock, and ships the governance enterprises require — each with its own deep-dive page.

Exploit validation

Exploitability Validation Core

Stop chasing severity. Rank by what's actually exploitable — EPSS probability, CISA KEV, and proven reachability.

  • EPSS exploit-probability weighting
  • CISA KEV known-exploited priority floor
  • Version-aware CVE matching — zero invented CVEs
Learn more
Active validation

Proof-based Active Testing

Confirm vulnerabilities by safely triggering them — reflected XSS, error-based SQLi and open redirects, proven not guessed.

  • Consent-gated, non-destructive GET probes
  • Reflected-XSS, error-SQLi & open-redirect proof
  • Same-origin, rate-limited, self-identifying agent
Learn more
Adversary emulation

Attack Simulation & MITRE ATT&CK

See findings the way an adversary chains them — mapped to MITRE ATT&CK tactics and techniques.

  • MITRE ATT&CK coverage matrix
  • Tactic → technique mapping per scenario
  • Severity-weighted kill-chain view
Learn more
Continuous EASM

Continuous Attack-Surface Discovery

Watch your external footprint change over time — new hosts, shadow IT and disappearing assets, run after run.

  • Snapshot + delta across every run
  • New / gone host detection
  • Shadow-IT (risky new host) flagging
Learn more
SCA / SBOM

Software Composition Analysis

Find vulnerable dependencies — most of your risk lives in code you didn't write.

  • npm + PyPI manifest parsing
  • OSV-backed vulnerability matching
  • SBOM inventory · CVEs flow to Validation Core
Learn more
Threat intel

Live Threat Intelligence

Know what's being exploited in the wild today — KEV, EPSS and emerging-exploit signals wired straight into your queue.

  • Daily CISA KEV & EPSS feed sync
  • Emerging-exploit & public-PoC alerts
  • Auto re-prioritizes findings as threats move
Learn more
External threat intel · DRP

External Threats & Digital Risk Protection

Watch the outside-in too — leaked credentials, dark-web & Telegram chatter, malware/C2 IOCs, ransomware victim posts and look-alike domains, all correlated to your assets and ranked by TALON.

  • Leaks, dark web, ransomware, brand-abuse & IOCs in one feed
  • TALON composite scoring + ATOM account-takeover chains
  • AI briefing & threat-knowledge graph, gated to Pro / Business
Learn more
Attack-surface graph

Attack-Surface Graph

See your whole external footprint as one living graph — assets, services, exposures and how an attacker pivots between them.

  • Live asset ↔ service ↔ exposure graph
  • Shortest attacker path to crown-jewel assets
  • Blast-radius view for every finding
Learn more
Adversary emulation

Attack-Path & Breach Simulation

Chain individual findings into end-to-end attack paths — see how a breach actually unfolds, before it does.

  • Multi-step exploit-chain construction
  • Likelihood-weighted breach scenarios
  • Mapped to MITRE ATT&CK stages
Learn more
Cloud posture · CSPM

Cloud Security Posture (CSPM)

Catch the cloud misconfigurations attackers love — public buckets, open ports, over-broad IAM — mapped to the same fix-first queue.

  • Public storage & exposed-service checks
  • Over-permissive IAM & policy findings
  • CIS-benchmark aligned, one unified queue
Learn more
Continuous monitoring

Continuous Monitoring & Alerting

Set it and stay covered — scheduled re-scans, drift detection and alerts the moment your exposure changes.

  • Scheduled re-scans & DRP collection
  • Change/drift alerts on new exposure
  • Routed to Slack, webhook or email
Learn more
AI copilot

AI Security Analyst

An AI analyst on every finding — it explains the risk, drafts the fix, and answers 'so what?' in plain language.

  • Plain-language 'why it matters' per finding
  • One-click PR-ready fix prompts
  • Ask-anything copilot over your posture
Learn more
Board reporting

Executive & Board Reporting

Turn technical findings into a board-ready story — posture, business risk and a dated remediation roadmap, one click to PDF.

  • Auto-generated executive brief
  • 0–30 / 30–60 / 60–90-day roadmap
  • One-click PDF / CSV export
Learn more
Workflow & SIEM

Integrations & Workflow

heimdallX fits your stack — Slack, webhooks, SIEM and ticketing — with an API and audit trail behind every action.

  • Slack, webhook & email alert routing
  • SIEM / ticketing export via API
  • Append-only audit log on every action
Learn more
AI remediation

AI Remediation & Fix

Every finding ships with a clear, PR-ready fix — and a one-click prompt your AI coding agent can apply.

  • Per-finding fix steps & config snippets
  • Copy-ready Claude Code fix prompt
  • Owner routing in fix-first order
Learn more
Continuous compliance

Continuous Compliance Evidence

Map every finding to the frameworks auditors ask about — with a timestamped evidence trail.

  • OWASP / PCI-DSS / ISO 27001 / SOC 2 / CIS mapping
  • Per-control "last checked" freshness
  • Timestamped evidence trail
Learn more
AI cost & governance

AI Cost Governance & FinOps

Run AI-driven security at scale without runaway bills — per-workspace token tracking, hard budget caps and an admin operations console.

  • Per-workspace AI token & cost tracking
  • Hard budget caps, enforced not just alerted
  • Admin operations console + audit trail
Learn more
Enterprise

Enterprise Controls

SSO, SCIM, granular roles and an append-only audit log — the controls security teams must have.

  • SAML SSO + SCIM provisioning
  • Granular RBAC (owner / admin / analyst / viewer)
  • Append-only audit log + team workspaces
Learn more
Explore all capabilities
In action

The real dashboard, in action

Not mockups — these are the actual heimdallX views: exploitability validation, adversary emulation and continuous compliance, rendered pixel-for-pixel.

Exploit validation

Exploitability Validation Core

Stop chasing severity. Rank by what's actually exploitable — EPSS probability, CISA KEV, and proven reachability.

Learn more
heimdallx.ai/appheimdallXPROUpgradeAI analystNew scanSign outAAcme Securityacme-prodCommand centerOverviewExecutive BriefFindings24Remediation7Assets18OperationsDiscoveryAttack Surface5Breach SimThreat IntelMonitoring3Compliance12IntegrationsActivityExternal ThreatsExternal Threats9Threat FeedAI BriefingFindings3 of 24Search title, asset, category…All 24Critical 2High 6Medium 9Low 7All modulesCRITICALApache httpd 2.4.49 — path traversal & RCEacme-corp.com · Web & Assets · CWE-22PRIORITY90CONFIDENCE92%EXPLOITActively exploitedReachableKNOWN CVESCVE-2021-41773KEVEPSS 97.5%CVE-2021-42013EPSS 94.2%⌘ PROOF OF CONCEPTGET /cgi-bin/.%2e/%2e%2e/etc/passwd200 · root:x:0:0:root:/root:/bin/bash✦ Fix prompt🎟 Create ticketFix-first re-rankEPSS × CISA KEVseverity-only21+ EPSS · KEV floor90
Adversary emulation

Attack Simulation & MITRE ATT&CK

See findings the way an adversary chains them — mapped to MITRE ATT&CK tactics and techniques.

Learn more
heimdallx.ai/appheimdallXPROUpgradeAI analystNew scanSign outAAcme Securityacme-prodCommand centerOverviewExecutive BriefFindings24Remediation7Assets18OperationsDiscoveryAttack Surface5Breach SimThreat IntelMonitoring3Compliance12IntegrationsActivityExternal ThreatsExternal Threats9Threat FeedAI BriefingBreach & Attack SimulationAI RED TEAMRun simulation⌖ MITRE ATT&CK coverage6 tactics · 8 techniquesReconT1595Initial AccessT1190ExecutionT1059PersistenceT1505Cred. AccessT1110ImpactT1499CRITICALInternet-facing RCE → data-store impactLikelihood82%Entry: acme-corp.com/cgi-binINITIAL ACCESST1190Exploit public-facing Apache RCEEXECUTIONT1059Drop web shell, run commandsCRED. ACCESST1552Read .env — DB + cloud keysIMPACTT1486Encrypt / exfiltrate data store◆ CHOKEPOINT — patch Apache to 2.4.51+ breaks the whole chain
Continuous compliance

Continuous Compliance Evidence

Map every finding to the frameworks auditors ask about — with a timestamped evidence trail.

Learn more
heimdallx.ai/appheimdallXPROUpgradeAI analystNew scanSign outAAcme Securityacme-prodCommand centerOverviewExecutive BriefFindings24Remediation7Assets18OperationsDiscoveryAttack Surface5Breach SimThreat IntelMonitoring3Compliance12IntegrationsActivityExternal ThreatsExternal Threats9Threat FeedAI BriefingCompliancefindings mapped to controls · evidence collected continuouslyPosture by frameworkavg 79%OWASP82%PCI-DSS76%ISO 2700188%SOC 271%CIS80%Top control gapscontinuousA06 Vulnerable Componentslast checked · 2h agoPASSPCI 6.3.3 Patch mgmtlast checked · 2h agoPASSISO A.8.8 Tech vulnslast checked · 1d agoGAPtimestamped evidence trail

Built on the CTEM loop

Continuous Threat Exposure Management — the model Gartner calls essential for 2026. heimdallX runs the full loop for you, continuously.

1

Scoping

Define the assets and surfaces that matter to your business.

2

Discovery

Continuously find assets, subdomains, services and misconfigurations.

3

Prioritization

Rank risk by exploitability and real-world impact with AI.

4

Validation

Confirm findings are real, not scanner noise.

5

Mobilization

Ship clear, actionable remediation to the right people.

AGPL-3.0

Open source, and a cloud that runs it for you

The platform is AGPL-3.0 on GitHub. Clone it, read every check it runs, and host it yourself for nothing. The cloud is the same product operated for you — with the external-threat feeds, the SOC ingestion pipeline and managed AI that are ours to run.

Self-hosted

AGPL-3.0 · your infrastructure · no limits, no phone-home

  • Web & exposure scan modules — the whole engine
  • Findings, fix-first queue, assets, attack surface
  • EASM discovery, breach simulation, compliance mapping
  • Integrations + CI gate (SARIF)
  • Docker Compose and Kubernetes manifests
  • Bring your own Anthropic key for the AI features

heimdallX Cloud

From $0 · we operate it · everything above, plus

  • External threats (DRP): dark web, Telegram, ransomware, brand abuse
  • SOC: metered log ingestion with AI triage
  • Managed AI credits — no API key of your own
  • Team workspaces and roles
  • Updates, backups, uptime and support
Scan your domain free
Self-host in one command
git clone https://github.com/021flow/heimdallx.git
cd heimdallx && cp .env.example .env # set SESSION_SECRET
docker compose up -d

Requires Docker. Set SESSION_SECRET, then open localhost:6000/app.

AGPL-3.0run it, change it, host it. If you offer a modified version as a service, publish your changes.

Pricing that scales with you

Start free. Upgrade when you're ready. Web checkout via Paddle, mobile via in-app purchase — entitlements synced everywhere.

Self-hosted
$0 · AGPL-3.0
  • Unlimited assets and scans
  • Web + Exposure modules
  • Runs on your infrastructure
  • Docker Compose / Kubernetes
  • Community support
Get the source
Free
$0/forever
  • 1 asset
  • 3 scans / month
  • Web security module
  • Community support
Start free
Starter
$79/month
  • 10 assets
  • 200 scans / month
  • Web + Exposure modules
  • SOC: 0.5 GB/day log ingestion
  • Continuous monitoring
  • Email support
Start Starter
Business
$999/month
  • 250 assets
  • 10,000 scans / month
  • All modules incl. Code & Cloud
  • SOC: 15 GB/day log ingestion + AI triage
  • Full DRP suite + threat graph
  • Team workspaces
  • Priority support
Start Business

🔒 Web payments are securely processed by Paddle.com.

Subscription plans may renew automatically until cancelled.

By proceeding to checkout, you agree to our Terms of Service, Privacy Policy, Refund & Cancellation Policy.

Frequently asked

Is heimdallX really open source?

Yes — the platform is published under AGPL-3.0 at github.com/021flow/heimdallx. You can read every check the scanner runs, change it, and host it yourself with no licence fee and no asset limit. The AGPL asks one thing in return: if you offer a modified version to others as a network service, publish your modifications.

What do I give up by self-hosting?

The scanning platform is all there. What the cloud adds is the part that has to be operated: the external-threat (DRP) feeds and their subscriptions, metered log ingestion for the SOC pipeline, managed AI credits so you do not need your own Anthropic key, team workspaces, and updates, backups and support.

Can I use the self-hosted edition commercially?

Yes. AGPL-3.0 does not restrict commercial use, including inside a company. The obligation is about distribution and network use of a MODIFIED version — if you change heimdallX and offer that changed version as a service to others, those users must be able to get your source.

What can heimdallX scan?

Domains and URLs you own or are authorized to test. The web module runs real reconnaissance — DNS, subdomains, TLS, HTTP security headers, technology fingerprinting and exposed-service checks — and an AI layer turns the raw data into prioritized, fixable findings.

Is it safe to run against my production site?

Yes. Passive checks are non-intrusive. Active port scanning only runs on assets you've verified you own and explicitly consent to — we never launch intrusive tests without permission.

How is billing handled?

On the web we use Paddle as the merchant of record (cards, taxes, invoices handled for you). In the mobile app, subscriptions go through native in-app purchases. Your plan and entitlements stay in sync across every device.

Do you support Google and Apple sign-in?

Yes — sign in with Google or Apple on web and mobile. Your workspace, assets and scan history follow you across platforms.

What makes the findings different?

Traditional scanners drown you in false positives. heimdallX pairs deterministic checks with an AI analyst that explains why each issue matters and exactly how to fix it — modeled on how elite offensive-security teams work.

See what attackers see — before they do

Run your first scan in under two minutes. Free, no credit card, real findings.

Launch heimdallX
heimdallX — AI Security Platform for Domains, Exposure & Code