heimdallX scans your web, cloud and code like a world-class hacker and proves what's actually exploitable with EPSS, CISA KEV and safe active testing — then watches the outside world, from leaked credentials and dark-web chatter to ransomware, ranked by TALON. Adversary emulation, continuous monitoring and board-ready governance, in one AI dashboard.
No credit card required · Real results in minutes · Cancel anytime
01AI agents probe your domain like a real attacker — first findings in minutes
02One benchmarked posture score — know exactly where you stand
03Every critical proven exploitable — EPSS, CISA KEV & safe active testing
04A fix-first queue ranked by what's actually exploitable, not just severity
05Now watching the outside too — leaks, dark web & ransomware, ranked by TALON
Most teams juggle a scanner, a breach monitor and a code tool. heimdallX fuses all three into one attack-surface graph — every finding validated for exploitability, correlated inside-out and outside-in, and explained by the same AI analyst.
Point heimdallX at a domain and an orchestra of AI agents probes it like an attacker would — across web, cloud and exposed services — then proves what's actually exploitable and chains it into real attack paths.
Know what the internet knows about you — and what attackers are already doing outside your perimeter. Continuous DRP across leaks, dark-web & Telegram chatter, ransomware victim posts, brand abuse and malware IOCs, correlated to your assets and distilled into an AI briefing.
Connect a repository and let AI hunt the business-logic flaws scanners miss, scan your dependencies and secrets, and feed every code CVE into the same exploitability-ranked queue.
Detection is table stakes. heimdallX proves what's exploitable, emulates the adversary, watches your surface around the clock, and ships the governance enterprises require — each with its own deep-dive page.
Stop chasing severity. Rank by what's actually exploitable — EPSS probability, CISA KEV, and proven reachability.
Confirm vulnerabilities by safely triggering them — reflected XSS, error-based SQLi and open redirects, proven not guessed.
See findings the way an adversary chains them — mapped to MITRE ATT&CK tactics and techniques.
Watch your external footprint change over time — new hosts, shadow IT and disappearing assets, run after run.
Find vulnerable dependencies — most of your risk lives in code you didn't write.
Know what's being exploited in the wild today — KEV, EPSS and emerging-exploit signals wired straight into your queue.
Watch the outside-in too — leaked credentials, dark-web & Telegram chatter, malware/C2 IOCs, ransomware victim posts and look-alike domains, all correlated to your assets and ranked by TALON.
See your whole external footprint as one living graph — assets, services, exposures and how an attacker pivots between them.
Chain individual findings into end-to-end attack paths — see how a breach actually unfolds, before it does.
Catch the cloud misconfigurations attackers love — public buckets, open ports, over-broad IAM — mapped to the same fix-first queue.
Set it and stay covered — scheduled re-scans, drift detection and alerts the moment your exposure changes.
An AI analyst on every finding — it explains the risk, drafts the fix, and answers 'so what?' in plain language.
Turn technical findings into a board-ready story — posture, business risk and a dated remediation roadmap, one click to PDF.
heimdallX fits your stack — Slack, webhooks, SIEM and ticketing — with an API and audit trail behind every action.
Every finding ships with a clear, PR-ready fix — and a one-click prompt your AI coding agent can apply.
Map every finding to the frameworks auditors ask about — with a timestamped evidence trail.
Run AI-driven security at scale without runaway bills — per-workspace token tracking, hard budget caps and an admin operations console.
SSO, SCIM, granular roles and an append-only audit log — the controls security teams must have.
Not mockups — these are the actual heimdallX views: exploitability validation, adversary emulation and continuous compliance, rendered pixel-for-pixel.
Stop chasing severity. Rank by what's actually exploitable — EPSS probability, CISA KEV, and proven reachability.
Learn more →See findings the way an adversary chains them — mapped to MITRE ATT&CK tactics and techniques.
Learn more →Map every finding to the frameworks auditors ask about — with a timestamped evidence trail.
Learn more →Continuous Threat Exposure Management — the model Gartner calls essential for 2026. heimdallX runs the full loop for you, continuously.
Define the assets and surfaces that matter to your business.
Continuously find assets, subdomains, services and misconfigurations.
Rank risk by exploitability and real-world impact with AI.
Confirm findings are real, not scanner noise.
Ship clear, actionable remediation to the right people.
The platform is AGPL-3.0 on GitHub. Clone it, read every check it runs, and host it yourself for nothing. The cloud is the same product operated for you — with the external-threat feeds, the SOC ingestion pipeline and managed AI that are ours to run.
AGPL-3.0 · your infrastructure · no limits, no phone-home
From $0 · we operate it · everything above, plus
git clone https://github.com/021flow/heimdallx.gitcd heimdallx && cp .env.example .env # set SESSION_SECRETdocker compose up -d
Requires Docker. Set SESSION_SECRET, then open localhost:6000/app.
AGPL-3.0 — run it, change it, host it. If you offer a modified version as a service, publish your changes.
Start free. Upgrade when you're ready. Web checkout via Paddle, mobile via in-app purchase — entitlements synced everywhere.
🔒 Web payments are securely processed by Paddle.com.
↻ Subscription plans may renew automatically until cancelled.
By proceeding to checkout, you agree to our Terms of Service, Privacy Policy, Refund & Cancellation Policy.
Yes — the platform is published under AGPL-3.0 at github.com/021flow/heimdallx. You can read every check the scanner runs, change it, and host it yourself with no licence fee and no asset limit. The AGPL asks one thing in return: if you offer a modified version to others as a network service, publish your modifications.
The scanning platform is all there. What the cloud adds is the part that has to be operated: the external-threat (DRP) feeds and their subscriptions, metered log ingestion for the SOC pipeline, managed AI credits so you do not need your own Anthropic key, team workspaces, and updates, backups and support.
Yes. AGPL-3.0 does not restrict commercial use, including inside a company. The obligation is about distribution and network use of a MODIFIED version — if you change heimdallX and offer that changed version as a service to others, those users must be able to get your source.
Domains and URLs you own or are authorized to test. The web module runs real reconnaissance — DNS, subdomains, TLS, HTTP security headers, technology fingerprinting and exposed-service checks — and an AI layer turns the raw data into prioritized, fixable findings.
Yes. Passive checks are non-intrusive. Active port scanning only runs on assets you've verified you own and explicitly consent to — we never launch intrusive tests without permission.
On the web we use Paddle as the merchant of record (cards, taxes, invoices handled for you). In the mobile app, subscriptions go through native in-app purchases. Your plan and entitlements stay in sync across every device.
Yes — sign in with Google or Apple on web and mobile. Your workspace, assets and scan history follow you across platforms.
Traditional scanners drown you in false positives. heimdallX pairs deterministic checks with an AI analyst that explains why each issue matters and exactly how to fix it — modeled on how elite offensive-security teams work.
Run your first scan in under two minutes. Free, no credit card, real findings.
Launch heimdallX