The watchtower that proves what's exploitable
heimdallX probes your web, cloud and code from the outside, the way an attacker would — then shows which findings are actually exploitable, and proves it.
No credit card required · Real results in minutes · Cancel anytime
Or read a real report first →01AI agents probe your domain like a real attacker — first findings in minutes
02One benchmarked posture score — know exactly where you stand
03Every critical proven exploitable — EPSS, CISA KEV & safe active testing
04A fix-first queue ranked by what's actually exploitable, not just severity
05Now watching the outside too — leaks, dark web & ransomware, ranked by TALON
One platform, three watchtowers
Most teams juggle a scanner, a breach monitor and a code tool. heimdallX fuses all three into one attack-surface graph — every finding validated for exploitability, correlated inside-out and outside-in, and explained by the same AI analyst.
Web, Cloud & Asset Scanning
Point heimdallX at a domain and an orchestra of AI agents probes it like an attacker would — across web, cloud and exposed services — then proves what's actually exploitable and chains it into real attack paths.
- DNS, TLS, headers, tech & cloud posture (CSPM)
- Exploitability validation — EPSS · CISA KEV
- Safe active testing — proof, not guesses
- Attack-surface graph & breach simulation
- Continuous monitoring + AI-prioritized fixes
- Authenticated crawl behind your own login — read-only, via API
External Threats & Digital Risk Protection
Know what the internet knows about you — and what attackers are already doing outside your perimeter. Continuous DRP across leaks, dark-web & Telegram chatter, ransomware victim posts, brand abuse and malware IOCs, correlated to your assets and distilled into an AI briefing.
- Leaked-credential & breach alerts (HIBP)
- Dark-web, Telegram & ransomware-site monitoring
- Look-alike / phishing brand-abuse detection
- Malware & C2 IOCs correlated to your assets
- TALON scoring + ATOM account-takeover chains
Code Security
Connect a repository and let AI hunt the business-logic flaws scanners miss, scan your dependencies and secrets, and feed every code CVE into the same exploitability-ranked queue.
- Business-logic vulnerability detection
- Secret & credential scanning
- SCA / SBOM — OSV-matched dependency CVEs
- Code CVEs flow into the fix-first queue
- AI remediation — PR-ready fix prompts
Built to be believed
Made for the small security team that owns everything and is outnumbered. Every claim below is one you can check yourself — in a report, in the source, or in your first scan.
Every finding says how we know
Proven, inferred, reported or heuristic. "Proven" means the weakness is in a response the scan holds — and nothing is presented as proven when it was not.
Fix-first, not severity-first
Exploit maturity, confidence, EPSS and CISA KEV fold into one ordering, with a floor for known-exploited CVEs. Monday morning starts at the top of one list.
We say when we could not look
A source the scan could not reach is reported as a gap — in the UI, the PDF and the board brief — never as a cleaner result.
The AI cannot invent a finding
Model-authored findings that name anything absent from the recon are dropped before the report, and the count of what was dropped is shown.
One queue across four modules
Web, cloud, code and exposure share one findings model, one priority and one analyst — where the alternative is four products and four dashboards.
No SSO tax
SAML SSO, roles and the audit log are on every plan, Free included. Charging for a security control pushes teams onto shared passwords — the very thing this product exists to find.
Validation, adversary emulation & enterprise controls
Detection is table stakes. heimdallX proves what's exploitable, emulates the adversary, watches your surface around the clock, and ships the governance enterprises require — each with its own deep-dive page.
Exploitability Validation Core
Stop chasing severity. Rank by what's actually exploitable — EPSS probability, CISA KEV, and proven reachability.
- EPSS exploit-probability weighting
- CISA KEV known-exploited priority floor
- Version-aware CVE matching — zero invented CVEs
Proof-based Active Testing
Confirm vulnerabilities by safely triggering them — reflected XSS, error-based SQLi and open redirects, proven not guessed.
- Consent-gated, non-destructive GET probes
- Reflected-XSS, error-SQLi & open-redirect proof
- Same-origin, rate-limited, self-identifying agent
Attack Simulation & MITRE ATT&CK
See findings the way an adversary chains them — mapped to MITRE ATT&CK tactics and techniques.
- MITRE ATT&CK coverage matrix
- Tactic → technique mapping per scenario
- Severity-weighted kill-chain view
Continuous Attack-Surface Discovery
Watch your external footprint change over time — new hosts, shadow IT and disappearing assets, run after run.
- Snapshot + delta across every run
- New / gone host detection
- Shadow-IT (risky new host) flagging
Software Composition Analysis
Find vulnerable dependencies — most of your risk lives in code you didn't write.
- npm + PyPI manifest parsing
- OSV-backed vulnerability matching
- SBOM inventory · CVEs flow to Validation Core
Live Threat Intelligence
Know what's being exploited in the wild today — KEV, EPSS and emerging-exploit signals wired straight into your queue.
- Daily CISA KEV & EPSS feed sync
- Emerging-exploit & public-PoC alerts
- Auto re-prioritizes findings as threats move
External Threats & Digital Risk Protection
Watch the outside-in too — leaked credentials, dark-web & Telegram chatter, malware/C2 IOCs, ransomware victim posts and look-alike domains, all correlated to your assets and ranked by TALON.
- Leaks, dark web, ransomware, brand-abuse & IOCs in one feed
- TALON composite scoring + ATOM account-takeover chains
- AI briefing & threat-knowledge graph, gated to Pro / Business
Attack-Surface Graph
See your whole external footprint as one living graph — assets, services, exposures and how an attacker pivots between them.
- Live asset ↔ service ↔ exposure graph
- Shortest attacker path to crown-jewel assets
- Blast-radius view for every finding
Attack-Path & Breach Simulation
Chain individual findings into end-to-end attack paths — see how a breach actually unfolds, before it does.
- Multi-step exploit-chain construction
- Likelihood-weighted breach scenarios
- Mapped to MITRE ATT&CK stages
Cloud Security Posture (CSPM)
Catch the cloud misconfigurations attackers love — public buckets, open ports, over-broad IAM — mapped to the same fix-first queue.
- Public storage & exposed-service checks
- Over-permissive IAM & policy findings
- CIS-benchmark aligned, one unified queue
Continuous Monitoring & Alerting
Set it and stay covered — scheduled re-scans, drift detection and alerts the moment your exposure changes.
- Scheduled re-scans & DRP collection
- Change/drift alerts on new exposure
- Routed to Slack, webhook or email
SOC Console & Telemetry Ingestion
Ship your cloud, identity and VCS logs in — heimdallX normalises them, runs detections, and turns each one into an incident an analyst can work to closure.
- Metered log ingestion with an API key — cloud audit, identity, VCS, syslog
- Sigma-compatible detections mapped to MITRE ATT&CK
- AI triage, MTTA / MTTR targets and suppression rules
CI Gate, SARIF & Public API
Run heimdallX from your pipeline: a scan per build, SARIF into code scanning, an SBOM per release — and a gate that breaks the build only on what was demonstrated.
- Per-workspace CI keys, reference GitHub / GitLab workflows
- SARIF 2.1.0 + CycloneDX SBOM per scan
- Gate on the proven tier only — never on a model's guess
AI Security Analyst
An AI analyst on every finding — it explains the risk, drafts the fix, and answers 'so what?' in plain language.
- Plain-language 'why it matters' per finding
- One-click PR-ready fix prompts
- Ask-anything copilot over your posture
Executive & Board Reporting
Turn technical findings into a board-ready story — posture, business risk and a dated remediation roadmap, one click to PDF.
- Auto-generated executive brief
- 0–30 / 30–60 / 60–90-day roadmap
- One-click PDF / CSV export
Integrations & Workflow
heimdallX fits your stack — Slack, webhooks, SIEM and ticketing — with an API and audit trail behind every action.
- Slack, webhook & email alert routing
- SIEM / ticketing export via API
- Append-only audit log on every action
AI Remediation & Fix
Every finding ships with a clear, PR-ready fix — and a one-click prompt your AI coding agent can apply.
- Per-finding fix steps & config snippets
- Copy-ready Claude Code fix prompt
- Owner routing in fix-first order
Continuous Compliance Evidence
Map every finding to the frameworks auditors ask about — with a timestamped evidence trail.
- OWASP · PCI-DSS · ISO 27001 · SOC 2 · CIS · NIST CSF · GDPR · HIPAA · EU AI Act mapping
- Per-control "last checked" freshness
- Timestamped evidence trail
AI Cost Governance & FinOps
Run AI-driven security at scale without runaway bills — per-workspace token tracking, hard budget caps and an admin operations console.
- Per-workspace AI token & cost tracking
- Hard budget caps, enforced not just alerted
- Admin operations console + audit trail
Enterprise Controls
SSO, SCIM, granular roles and an append-only audit log — the controls security teams must have.
- SAML SSO on every plan · SCIM on Business
- Granular RBAC (owner / admin / analyst / viewer)
- Append-only audit log + team workspaces
The real dashboard, in action
Not mockups — these are the actual heimdallX views: exploitability validation, adversary emulation and continuous compliance, rendered pixel-for-pixel.
Exploitability Validation Core
Stop chasing severity. Rank by what's actually exploitable — EPSS probability, CISA KEV, and proven reachability.
Learn more →Attack Simulation & MITRE ATT&CK
See findings the way an adversary chains them — mapped to MITRE ATT&CK tactics and techniques.
Learn more →Continuous Compliance Evidence
Map every finding to the frameworks auditors ask about — with a timestamped evidence trail.
Learn more →Built on the CTEM loop
Continuous Threat Exposure Management — the model Gartner calls essential for 2026. heimdallX runs the full loop for you, continuously.
Scoping
Define the assets and surfaces that matter to your business.
Discovery
Continuously find assets, subdomains, services and misconfigurations.
Prioritization
Rank risk by exploitability and real-world impact with AI.
Validation
Confirm findings are real, not scanner noise.
Mobilization
Ship clear, actionable remediation to the right people.
What a security review asks for is already public
What we can and cannot check is written down, each answer points at the code that makes it true, and a test fails when a document and the product disagree.
A real report
The exact rows the scanner produces for a deliberately broken target — re-derived by a test on every build.
Learn more →What it cannot check
No JavaScript execution, GET only, a bounded crawl. The list a buyer finds in the first week, published first.
Learn more ↗The vendor questionnaire, answered
Access control, tenant isolation, secrets, backups, deletion, AI — each answer a path into the source.
Learn more ↗SOC 2 readiness
heimdallX itself against the Common Criteria, with MET, PARTIAL or GAP stated per control.
Learn more ↗Threat model
What is worth taking from us, and the test that enforces each mitigation.
Learn more ↗The integration contract
The public OpenAPI specification for CI, ingestion and exports — read it before writing a line.
Learn more ↗Report a flaw
A coordinated-disclosure policy and a monitored address, per RFC 9116.
Learn more →The source
AGPL-3.0 on GitHub. Every check the scanner runs is there to read.
Learn more ↗Open source, and a cloud that runs it for you
The platform is AGPL-3.0 on GitHub. Clone it, read every check it runs, and host it yourself for nothing. The cloud is the same product operated for you — with the external-threat feeds, the SOC ingestion pipeline and managed AI that are ours to run.
Self-hosted
AGPL-3.0 · your infrastructure · no limits, no phone-home
- Web & exposure scan modules — the whole engine
- Findings, fix-first queue, assets, attack surface
- EASM discovery, breach simulation, compliance mapping
- Integrations + CI gate (SARIF)
- Docker Compose and Kubernetes manifests
- Bring your own Anthropic key for the AI features
heimdallX Cloud
From $0 · we operate it · everything above, plus
- External threats (DRP): dark web, Telegram, ransomware, brand abuse
- SOC: metered log ingestion with AI triage
- Managed AI credits — no API key of your own
- ATOM account-takeover chains + threat knowledge graph
- Updates, backups, uptime and support
git clone https://github.com/021flow/heimdallx.gitcd heimdallx && cp .env.example .env # set SESSION_SECRETdocker compose up -d
Requires Docker. Set SESSION_SECRET, then open localhost:6000/app.
AGPL-3.0 — run it, change it, host it. If you offer a modified version as a service, publish your changes.
Pricing that scales with you
Start free. Upgrade when you're ready. Web checkout via Paddle, mobile via in-app purchase — entitlements synced everywhere. SAML SSO, roles and the audit log are on every plan — the tiers buy volume, feeds and support, not security controls.
- Unlimited assets and scans
- Web + Exposure modules
- Runs on your infrastructure
- Docker Compose / Kubernetes
- Community support
- 1 asset
- 3 scans / month
- Web security module
- AI security briefing
- Community support
- 10 assets
- 350 scans / month
- Web + Exposure modules
- SOC: 0.5 GB/day log ingestion + AI triage
- Continuous monitoring
- DRP: credential-leak & brand monitoring
- Email support
- 50 assets
- 1,600 scans / month
- All modules incl. Code & Cloud
- SOC: 3 GB/day log ingestion + AI triage
- Continuous monitoring + alerts
- DRP: leak, dark-web & brand + ATOM
- AI remediation guidance
- Email support
- 250 assets
- 10,000 scans / month
- All modules incl. Code & Cloud
- SOC: 15 GB/day log ingestion + AI triage
- Full DRP suite + threat graph
- SCIM provisioning (SSO on every plan)
- Priority support
🔒 Web payments are securely processed by Paddle.com.
↻ Subscription plans may renew automatically until cancelled.
By proceeding to checkout, you agree to our Terms of Service, Privacy Policy, Refund & Cancellation Policy.
Frequently asked
Is heimdallX really open source?
Yes — the platform is published under AGPL-3.0 at github.com/021flow/heimdallx. You can read every check the scanner runs, change it, and host it yourself with no licence fee and no asset limit. The AGPL asks one thing in return: if you offer a modified version to others as a network service, publish your modifications.
What do I give up by self-hosting?
The scanning platform is all there. What the cloud adds is the part that has to be operated: the external-threat (DRP) feeds and their subscriptions, metered log ingestion for the SOC pipeline, managed AI credits so you do not need your own Anthropic key, and updates, backups and support. Members, roles, SSO and the audit log are in the open-source build too.
Can I use the self-hosted edition commercially?
Yes. AGPL-3.0 does not restrict commercial use, including inside a company. The obligation is about distribution and network use of a MODIFIED version — if you change heimdallX and offer that changed version as a service to others, those users must be able to get your source.
What can heimdallX scan?
Domains and URLs you own or are authorized to test. The web module runs real reconnaissance — DNS, subdomains, TLS, HTTP security headers, technology fingerprinting and exposed-service checks — and an AI layer turns the raw data into prioritized, fixable findings.
Is it safe to run against my production site?
Yes. Passive checks are non-intrusive. Active port scanning only runs on assets you've verified you own and explicitly consent to — we never launch intrusive tests without permission.
How is billing handled?
On the web we use Paddle as the merchant of record (cards, taxes, invoices handled for you). In the mobile app, subscriptions go through native in-app purchases. Your plan and entitlements stay in sync across every device.
Do you support Google and Apple sign-in?
Yes — sign in with Google or Apple on web and mobile. Your workspace, assets and scan history follow you across platforms.
What makes the findings different?
Every finding carries how it was established — proven, inferred, reported or heuristic — separately from its severity and its confidence. "Proven" means the weakness is in a response the scan holds, and one click filters the list to that tier alone. A scanner that reports a version-matched CVE, a regex hit and a reflected payload with the same authority is the reason nobody trusts scanner output; the tiers are what let you break a build on the demonstrated tier only and still read the rest.
Do I still need a penetration test?
Yes. heimdallX runs unauthenticated checks from the outside, plus a read-only authenticated crawl via the API — it does not execute JavaScript, fuzz POST bodies or think laterally the way a human tester does. What it gives you is continuous coverage between engagements, and a fix-first list that lets the next engagement start from what is already known. Everything it cannot check is written down in LIMITS.md.
What can't heimdallX check?
The scanner does not execute JavaScript, reads only GET parameters against your site, crawls a bounded number of pages, and cannot log in through SSO, MFA or JavaScript-driven forms. The cloud module is agentless, with a native read-only AWS connector on self-hosted installs. Every one of these limits is in LIMITS.md next to the code that makes it true, and a scan says how many pages and scripts it actually read.
Can the AI make findings up?
No. Model-authored findings are grounded against the reconnaissance the scan actually holds — anything naming a host, header or version absent from it is dropped before the report, and the number dropped is shown. Board-brief risks must correspond to findings we hold, and a page that tries to instruct the scanner is fenced off from the model and becomes a finding of its own.
Which compliance frameworks are mapped?
Findings map to controls in OWASP Top 10, OWASP API, OWASP LLM, OWASP Agentic, PCI-DSS 4.0, ISO/IEC 27001:2022, SOC 2, CIS Controls v8, NIST CSF, GDPR Art. 32/33, the HIPAA Security Rule, ISO/IEC 42001, NIST AI RMF and the EU AI Act. The mapping is curated by hand and shows which control an auditor would flag a finding under — it is not an audit, and a clean scan is not a passed control.
Is SSO extra? What about SCIM?
SAML SSO, granular roles and the append-only audit log are on every plan, including Free — charging for a security control pushes the customers with the most users onto shared passwords. SCIM 2.0 provisioning is on Business, because automated provisioning is an operations convenience rather than a security floor: every plan can invite members by hand.
Can I take my data out?
One call — the workspace export — returns assets, scans, findings, remediation history, suppression rules, incidents, audit log and integration configuration, with secrets stripped. Coming in is one paste: the asset import takes the host list any scanner exports. Nothing is reachable only through the UI.
See what attackers see — before they do
Run your first scan in under two minutes. Free, no credit card, real findings.
Launch heimdallX