Attacker's-eye security, validated by AI — inside-out & outside-in

The watchtower that proves what's exploitable

heimdallX probes your web, cloud and code from the outside, the way an attacker would — then shows which findings are actually exploitable, and proves it.

No credit card required · Real results in minutes · Cancel anytime

Or read a real report first →
EPSS · KEV
exploitability validation
TALON · ATOM
external-threat scoring
ATT&CK
adversary emulation
24/7
continuous monitoring
heimdallXheimdallx.ai/appYheimdallXBUSINESSAI credits2.1k/45kAI analystNew scan[email protected]EnglishSign outAWorkspaceAcme SecurityPProjectProductionCommand centerOperationsExternal ThreatsOverviewExecutive BriefFindings15Remediation6Assets3DiscoveryAttack SurfaceBreach SimThreat IntelIncidents12MonitoringCompliance9IntegrationsActivityExternal Threats38Threat FeedAI BriefingAll modulesWeb & AssetsDigital ExposureCode SecurityCloud (CSPM)↓ CSV↓ PDF reportNew Web Scan×Web & AssetsDigital ExposureCode SecurityCloud (CSPM)acme.comRun scanReal recon: DNS, subdomains, TLS, security headers, fingerprint + AI analysis.Active validation — I own this target and authorise non-destructive probes.C70/100Targetacme.comAI summaryThe acme.com scan found 7 items (3 medium, 2 low, 2 info). Prioritise the most severe first.PipelineScanning…DNS & Subdomains4 IPs, 0 subdomainsTLS / CertificateTLSv1.3, expires in 69dHTTP Security Headers7 header issuesTechnology Fingerprintcloudflare, Next.jsExposed ServicesSkipped (no active-scan consent)Breach ExposureSkipped (no breach API key)API Security (OpenAPI)No public OpenAPI spec foundActive Vulnerability ValidationSkipped (enable on an owned asset)AI Analysis2 AI findingsImprovement room2 assets haven't been scanned recently — re-scan to stay current.38 external threats awaiting triageRun scan ›B80Security posture80/100▲ +10Average of your assets' latest scoresvs industry benchmark80 / 72Open findings150 critical/highPriority actions6deduplicated, ranked by impactAssets323 scans runLast scan3h agocontinuous monitoring onExternal threats38›Compliance controls9›Scan coverage2/4›Risk trendPosture score across recent scans, oldest → newestbenchmark 7280Posture by moduleC74Web & Assets74A92Digital Exposure92Findings15totalSearch title, asset, category…All15Medium6Low4Info5All modulesAll categoriesMEDIUMMissing HSTS headeracme.com · Web & Assets · HTTP Headers▾MEDIUMMissing Content-Security-Policyacme.com · Web & Assets · HTTP Headers▾MEDIUMCookie missing Secure/HttpOnly flagsacme.com · Web & Assets · Session▾MEDIUMMissing HSTS headerapi.acme.io · Web & Assets · HTTP Headers▾MEDIUMMissing Content-Security-Policyapi.acme.io · Web & Assets · HTTP Headers▾MEDIUMLook-alike domain registered: acrne.example[email protected] · Digital Exposure · Brand Protection▾LOWMissing X-Frame-Options / frame-ancestorsacme.com · Web & Assets · HTTP Headers▾LOWMissing X-Content-Type-Optionsacme.com · Web & Assets · HTTP Headers▾LOWMissing X-Frame-Options / frame-ancestorsapi.acme.io · Web & Assets · HTTP Headers▾Fix-first priorityIdentical issues are grouped across assets and ranked by risk-reduction impact — fix once, resolve everywhere.Actions6Multi-asset4Total impact60Program reportMTTR (median)2dSLA compliance89%Started85%Exposure removed36Reopen rate5%Open item age0-78-3031-9090+619 resolved · 2 accepted · 2 false positiveConfidence calibrationaligned1MEDIUMMissing HSTS headerHTTP Headers · Web & AssetsAssets2impact16▾2MEDIUMMissing Content-Security-PolicyHTTP Headers · Web & AssetsAssets2impact16▾3MEDIUMCookie missing Secure/HttpOnly flagsSession · Web & AssetsAssets1impact8▾4MEDIUMLook-alike domain registered: acrne.exampleBrand Protection · Digital ExposureAssets1impact8▾5LOWMissing X-Frame-Options / frame-ancestorsHTTP Headers · Web & AssetsAssets2impact6▾6LOWMissing X-Content-Type-OptionsHTTP Headers · Web & AssetsAssets2impact6▾External ThreatsDRPDigital Risk Protection — leaks, dark-web and Telegram chatter, malicious/C2 IOCs, ransomware victim posts and brand abuse, cross-matched against your assets and ranked by TALON.Monitoring↻ Collect nowTotal39Matched4Critical2Allowed types6TotalLeaks4Dark web · Telegram5Brand1ATOMGraphCRITICAL203.0.113.66 · malicious infrastructureIOC · abuse.ch/ThreatFox · NightjarTALON 88▾CRITICAL[email protected] credential leak자격증명 유출 · Combolist (dark web)TALON 86▾HIGH198.51.100.7 · Cobalt Strike C2IOC · abuse.ch/ThreatFoxTALON 79▾HIGHLockBit victim post — acme-supplier.example랜섬웨어 · ransomware.live · LockBitTALON 74▾HIGHCollection #1 콤보리스트에 포함된 기업 자격증명자격증명 유출 · leaks · acme.comTALON 73▾HIGH다크웹 게시 — 제목에 프롬프트 인젝션 문구 포함 (방화벽 차단)다크웹 · Dark-web forum · exploit.inTALON 71▾HIGH[email protected] credential leak자격증명 유출 · Cracked.ioTALON 68▾MEDIUMacrne[.]example look-alike브랜드 사칭 · OpenPhishTALON 61▾

01AI agents probe your domain like a real attacker — first findings in minutes

02One benchmarked posture score — know exactly where you stand

03Every critical proven exploitable — EPSS, CISA KEV & safe active testing

04A fix-first queue ranked by what's actually exploitable, not just severity

05Now watching the outside too — leaks, dark web & ransomware, ranked by TALON

One platform, three watchtowers

Most teams juggle a scanner, a breach monitor and a code tool. heimdallX fuses all three into one attack-surface graph — every finding validated for exploitability, correlated inside-out and outside-in, and explained by the same AI analyst.

Web, Cloud & Asset Scanning

Point heimdallX at a domain and an orchestra of AI agents probes it like an attacker would — across web, cloud and exposed services — then proves what's actually exploitable and chains it into real attack paths.

  • DNS, TLS, headers, tech & cloud posture (CSPM)
  • Exploitability validation — EPSS · CISA KEV
  • Safe active testing — proof, not guesses
  • Attack-surface graph & breach simulation
  • Continuous monitoring + AI-prioritized fixes
  • Authenticated crawl behind your own login — read-only, via API

External Threats & Digital Risk Protection

Know what the internet knows about you — and what attackers are already doing outside your perimeter. Continuous DRP across leaks, dark-web & Telegram chatter, ransomware victim posts, brand abuse and malware IOCs, correlated to your assets and distilled into an AI briefing.

  • Leaked-credential & breach alerts (HIBP)
  • Dark-web, Telegram & ransomware-site monitoring
  • Look-alike / phishing brand-abuse detection
  • Malware & C2 IOCs correlated to your assets
  • TALON scoring + ATOM account-takeover chains

Code Security

Connect a repository and let AI hunt the business-logic flaws scanners miss, scan your dependencies and secrets, and feed every code CVE into the same exploitability-ranked queue.

  • Business-logic vulnerability detection
  • Secret & credential scanning
  • SCA / SBOM — OSV-matched dependency CVEs
  • Code CVEs flow into the fix-first queue
  • AI remediation — PR-ready fix prompts
Why heimdallX

Built to be believed

Made for the small security team that owns everything and is outnumbered. Every claim below is one you can check yourself — in a report, in the source, or in your first scan.

01

Every finding says how we know

Proven, inferred, reported or heuristic. "Proven" means the weakness is in a response the scan holds — and nothing is presented as proven when it was not.

02

Fix-first, not severity-first

Exploit maturity, confidence, EPSS and CISA KEV fold into one ordering, with a floor for known-exploited CVEs. Monday morning starts at the top of one list.

03

We say when we could not look

A source the scan could not reach is reported as a gap — in the UI, the PDF and the board brief — never as a cleaner result.

04

The AI cannot invent a finding

Model-authored findings that name anything absent from the recon are dropped before the report, and the count of what was dropped is shown.

05

One queue across four modules

Web, cloud, code and exposure share one findings model, one priority and one analyst — where the alternative is four products and four dashboards.

06

No SSO tax

SAML SSO, roles and the audit log are on every plan, Free included. Charging for a security control pushes teams onto shared passwords — the very thing this product exists to find.

Beyond detection

Validation, adversary emulation & enterprise controls

Detection is table stakes. heimdallX proves what's exploitable, emulates the adversary, watches your surface around the clock, and ships the governance enterprises require — each with its own deep-dive page.

Exploit validation

Exploitability Validation Core

Stop chasing severity. Rank by what's actually exploitable — EPSS probability, CISA KEV, and proven reachability.

  • EPSS exploit-probability weighting
  • CISA KEV known-exploited priority floor
  • Version-aware CVE matching — zero invented CVEs
Learn more →
Active validation

Proof-based Active Testing

Confirm vulnerabilities by safely triggering them — reflected XSS, error-based SQLi and open redirects, proven not guessed.

  • Consent-gated, non-destructive GET probes
  • Reflected-XSS, error-SQLi & open-redirect proof
  • Same-origin, rate-limited, self-identifying agent
Learn more →
Adversary emulation

Attack Simulation & MITRE ATT&CK

See findings the way an adversary chains them — mapped to MITRE ATT&CK tactics and techniques.

  • MITRE ATT&CK coverage matrix
  • Tactic → technique mapping per scenario
  • Severity-weighted kill-chain view
Learn more →
Continuous EASM

Continuous Attack-Surface Discovery

Watch your external footprint change over time — new hosts, shadow IT and disappearing assets, run after run.

  • Snapshot + delta across every run
  • New / gone host detection
  • Shadow-IT (risky new host) flagging
Learn more →
SCA / SBOM

Software Composition Analysis

Find vulnerable dependencies — most of your risk lives in code you didn't write.

  • npm + PyPI manifest parsing
  • OSV-backed vulnerability matching
  • SBOM inventory · CVEs flow to Validation Core
Learn more →
Threat intel

Live Threat Intelligence

Know what's being exploited in the wild today — KEV, EPSS and emerging-exploit signals wired straight into your queue.

  • Daily CISA KEV & EPSS feed sync
  • Emerging-exploit & public-PoC alerts
  • Auto re-prioritizes findings as threats move
Learn more →
External threat intel · DRP

External Threats & Digital Risk Protection

Watch the outside-in too — leaked credentials, dark-web & Telegram chatter, malware/C2 IOCs, ransomware victim posts and look-alike domains, all correlated to your assets and ranked by TALON.

  • Leaks, dark web, ransomware, brand-abuse & IOCs in one feed
  • TALON composite scoring + ATOM account-takeover chains
  • AI briefing & threat-knowledge graph, gated to Pro / Business
Learn more →
Attack-surface graph

Attack-Surface Graph

See your whole external footprint as one living graph — assets, services, exposures and how an attacker pivots between them.

  • Live asset ↔ service ↔ exposure graph
  • Shortest attacker path to crown-jewel assets
  • Blast-radius view for every finding
Learn more →
Adversary emulation

Attack-Path & Breach Simulation

Chain individual findings into end-to-end attack paths — see how a breach actually unfolds, before it does.

  • Multi-step exploit-chain construction
  • Likelihood-weighted breach scenarios
  • Mapped to MITRE ATT&CK stages
Learn more →
Cloud posture · CSPM

Cloud Security Posture (CSPM)

Catch the cloud misconfigurations attackers love — public buckets, open ports, over-broad IAM — mapped to the same fix-first queue.

  • Public storage & exposed-service checks
  • Over-permissive IAM & policy findings
  • CIS-benchmark aligned, one unified queue
Learn more →
Continuous monitoring

Continuous Monitoring & Alerting

Set it and stay covered — scheduled re-scans, drift detection and alerts the moment your exposure changes.

  • Scheduled re-scans & DRP collection
  • Change/drift alerts on new exposure
  • Routed to Slack, webhook or email
Learn more →
SOC · detection & response

SOC Console & Telemetry Ingestion

Ship your cloud, identity and VCS logs in — heimdallX normalises them, runs detections, and turns each one into an incident an analyst can work to closure.

  • Metered log ingestion with an API key — cloud audit, identity, VCS, syslog
  • Sigma-compatible detections mapped to MITRE ATT&CK
  • AI triage, MTTA / MTTR targets and suppression rules
Learn more →
Shift-left · CI/CD

CI Gate, SARIF & Public API

Run heimdallX from your pipeline: a scan per build, SARIF into code scanning, an SBOM per release — and a gate that breaks the build only on what was demonstrated.

  • Per-workspace CI keys, reference GitHub / GitLab workflows
  • SARIF 2.1.0 + CycloneDX SBOM per scan
  • Gate on the proven tier only — never on a model's guess
Learn more →
AI copilot

AI Security Analyst

An AI analyst on every finding — it explains the risk, drafts the fix, and answers 'so what?' in plain language.

  • Plain-language 'why it matters' per finding
  • One-click PR-ready fix prompts
  • Ask-anything copilot over your posture
Learn more →
Board reporting

Executive & Board Reporting

Turn technical findings into a board-ready story — posture, business risk and a dated remediation roadmap, one click to PDF.

  • Auto-generated executive brief
  • 0–30 / 30–60 / 60–90-day roadmap
  • One-click PDF / CSV export
Learn more →
Workflow & SIEM

Integrations & Workflow

heimdallX fits your stack — Slack, webhooks, SIEM and ticketing — with an API and audit trail behind every action.

  • Slack, webhook & email alert routing
  • SIEM / ticketing export via API
  • Append-only audit log on every action
Learn more →
AI remediation

AI Remediation & Fix

Every finding ships with a clear, PR-ready fix — and a one-click prompt your AI coding agent can apply.

  • Per-finding fix steps & config snippets
  • Copy-ready Claude Code fix prompt
  • Owner routing in fix-first order
Learn more →
Continuous compliance

Continuous Compliance Evidence

Map every finding to the frameworks auditors ask about — with a timestamped evidence trail.

  • OWASP · PCI-DSS · ISO 27001 · SOC 2 · CIS · NIST CSF · GDPR · HIPAA · EU AI Act mapping
  • Per-control "last checked" freshness
  • Timestamped evidence trail
Learn more →
AI cost & governance

AI Cost Governance & FinOps

Run AI-driven security at scale without runaway bills — per-workspace token tracking, hard budget caps and an admin operations console.

  • Per-workspace AI token & cost tracking
  • Hard budget caps, enforced not just alerted
  • Admin operations console + audit trail
Learn more →
Enterprise

Enterprise Controls

SSO, SCIM, granular roles and an append-only audit log — the controls security teams must have.

  • SAML SSO on every plan · SCIM on Business
  • Granular RBAC (owner / admin / analyst / viewer)
  • Append-only audit log + team workspaces
Learn more →
In action

The real dashboard, in action

Not mockups — these are the actual heimdallX views: exploitability validation, adversary emulation and continuous compliance, rendered pixel-for-pixel.

Exploit validation

Exploitability Validation Core

Stop chasing severity. Rank by what's actually exploitable — EPSS probability, CISA KEV, and proven reachability.

Learn more →
heimdallx.ai/appheimdallXPROUpgradeAI analystNew scanSign outAAcme Securityacme-prodCommand centerOverviewExecutive BriefFindings24Remediation7Assets18OperationsDiscoveryAttack Surface5Breach SimThreat IntelMonitoring3Compliance12IntegrationsActivityExternal ThreatsExternal Threats9Threat FeedAI BriefingFindings3 of 24Search title, asset, category…All 24Critical 2High 6Medium 9Low 7All modulesCRITICALApache httpd 2.4.49 — path traversal & RCE▴acme-corp.com · Web & Assets · CWE-22PRIORITY90CONFIDENCE92%EXPLOITActively exploitedReachableKNOWN CVESCVE-2021-41773KEVEPSS 97.5%CVE-2021-42013EPSS 94.2%⌘ PROOF OF CONCEPTGET /cgi-bin/.%2e/%2e%2e/etc/passwd200 · root:x:0:0:root:/root:/bin/bash✦ Fix prompt🎟 Create ticketFix-first re-rankEPSS × CISA KEVseverity-only21+ EPSS · KEV floor90
Adversary emulation

Attack Simulation & MITRE ATT&CK

See findings the way an adversary chains them — mapped to MITRE ATT&CK tactics and techniques.

Learn more →
heimdallx.ai/appheimdallXPROUpgradeAI analystNew scanSign outAAcme Securityacme-prodCommand centerOverviewExecutive BriefFindings24Remediation7Assets18OperationsDiscoveryAttack Surface5Breach SimThreat IntelMonitoring3Compliance12IntegrationsActivityExternal ThreatsExternal Threats9Threat FeedAI BriefingBreach & Attack SimulationAI RED TEAMRun simulation⌖ MITRE ATT&CK coverage6 tactics · 8 techniquesReconT1595Initial AccessT1190ExecutionT1059PersistenceT1505Cred. AccessT1110ImpactT1499CRITICALInternet-facing RCE → data-store impactLikelihood82%Entry: acme-corp.com/cgi-binINITIAL ACCESST1190Exploit public-facing Apache RCEEXECUTIONT1059Drop web shell, run commandsCRED. ACCESST1552Read .env — DB + cloud keysIMPACTT1486Encrypt / exfiltrate data store◆ CHOKEPOINT — patch Apache to 2.4.51+ breaks the whole chain
Continuous compliance

Continuous Compliance Evidence

Map every finding to the frameworks auditors ask about — with a timestamped evidence trail.

Learn more →
heimdallx.ai/appheimdallXPROUpgradeAI analystNew scanSign outAAcme Securityacme-prodCommand centerOverviewExecutive BriefFindings24Remediation7Assets18OperationsDiscoveryAttack Surface5Breach SimThreat IntelMonitoring3Compliance12IntegrationsActivityExternal ThreatsExternal Threats9Threat FeedAI BriefingCompliancefindings mapped to controls · evidence collected continuouslyPosture by frameworkavg 79%OWASP82%PCI-DSS76%ISO 2700188%SOC 271%CIS80%Top control gapscontinuousA06 Vulnerable Componentslast checked · 2h agoPASSPCI 6.3.3 Patch mgmtlast checked · 2h agoPASSISO A.8.8 Tech vulnslast checked · 1d agoGAPtimestamped evidence trail

Built on the CTEM loop

Continuous Threat Exposure Management — the model Gartner calls essential for 2026. heimdallX runs the full loop for you, continuously.

1

Scoping

Define the assets and surfaces that matter to your business.

2

Discovery

Continuously find assets, subdomains, services and misconfigurations.

3

Prioritization

Rank risk by exploitability and real-world impact with AI.

4

Validation

Confirm findings are real, not scanner noise.

5

Mobilization

Ship clear, actionable remediation to the right people.

Evaluate without a sales call

What a security review asks for is already public

What we can and cannot check is written down, each answer points at the code that makes it true, and a test fails when a document and the product disagree.

AGPL-3.0

Open source, and a cloud that runs it for you

The platform is AGPL-3.0 on GitHub. Clone it, read every check it runs, and host it yourself for nothing. The cloud is the same product operated for you — with the external-threat feeds, the SOC ingestion pipeline and managed AI that are ours to run.

Self-hosted

AGPL-3.0 · your infrastructure · no limits, no phone-home

  • Web & exposure scan modules — the whole engine
  • Findings, fix-first queue, assets, attack surface
  • EASM discovery, breach simulation, compliance mapping
  • Integrations + CI gate (SARIF)
  • Docker Compose and Kubernetes manifests
  • Bring your own Anthropic key for the AI features

heimdallX Cloud

From $0 · we operate it · everything above, plus

  • External threats (DRP): dark web, Telegram, ransomware, brand abuse
  • SOC: metered log ingestion with AI triage
  • Managed AI credits — no API key of your own
  • ATOM account-takeover chains + threat knowledge graph
  • Updates, backups, uptime and support
Scan your domain free
Self-host in one command
git clone https://github.com/021flow/heimdallx.git
cd heimdallx && cp .env.example .env # set SESSION_SECRET
docker compose up -d

Requires Docker. Set SESSION_SECRET, then open localhost:6000/app.

AGPL-3.0 — run it, change it, host it. If you offer a modified version as a service, publish your changes.

Pricing that scales with you

Start free. Upgrade when you're ready. Web checkout via Paddle, mobile via in-app purchase — entitlements synced everywhere. SAML SSO, roles and the audit log are on every plan — the tiers buy volume, feeds and support, not security controls.

Self-hosted
$0 · AGPL-3.0
  • Unlimited assets and scans
  • Web + Exposure modules
  • Runs on your infrastructure
  • Docker Compose / Kubernetes
  • Community support
Get the source
Free
$0/forever
  • 1 asset
  • 3 scans / month
  • Web security module
  • AI security briefing
  • Community support
Start free
Starter
$79/month
or $790/year — 2 months free
  • 10 assets
  • 350 scans / month
  • Web + Exposure modules
  • SOC: 0.5 GB/day log ingestion + AI triage
  • Continuous monitoring
  • DRP: credential-leak & brand monitoring
  • Email support
Start Starter
Business
$999/month
or $9,990/year — 2 months free
  • 250 assets
  • 10,000 scans / month
  • All modules incl. Code & Cloud
  • SOC: 15 GB/day log ingestion + AI triage
  • Full DRP suite + threat graph
  • SCIM provisioning (SSO on every plan)
  • Priority support
Start Business

🔒 Web payments are securely processed by Paddle.com.

↻ Subscription plans may renew automatically until cancelled.

By proceeding to checkout, you agree to our Terms of Service, Privacy Policy, Refund & Cancellation Policy.

Frequently asked

Is heimdallX really open source?

Yes — the platform is published under AGPL-3.0 at github.com/021flow/heimdallx. You can read every check the scanner runs, change it, and host it yourself with no licence fee and no asset limit. The AGPL asks one thing in return: if you offer a modified version to others as a network service, publish your modifications.

What do I give up by self-hosting?

The scanning platform is all there. What the cloud adds is the part that has to be operated: the external-threat (DRP) feeds and their subscriptions, metered log ingestion for the SOC pipeline, managed AI credits so you do not need your own Anthropic key, and updates, backups and support. Members, roles, SSO and the audit log are in the open-source build too.

Can I use the self-hosted edition commercially?

Yes. AGPL-3.0 does not restrict commercial use, including inside a company. The obligation is about distribution and network use of a MODIFIED version — if you change heimdallX and offer that changed version as a service to others, those users must be able to get your source.

What can heimdallX scan?

Domains and URLs you own or are authorized to test. The web module runs real reconnaissance — DNS, subdomains, TLS, HTTP security headers, technology fingerprinting and exposed-service checks — and an AI layer turns the raw data into prioritized, fixable findings.

Is it safe to run against my production site?

Yes. Passive checks are non-intrusive. Active port scanning only runs on assets you've verified you own and explicitly consent to — we never launch intrusive tests without permission.

How is billing handled?

On the web we use Paddle as the merchant of record (cards, taxes, invoices handled for you). In the mobile app, subscriptions go through native in-app purchases. Your plan and entitlements stay in sync across every device.

Do you support Google and Apple sign-in?

Yes — sign in with Google or Apple on web and mobile. Your workspace, assets and scan history follow you across platforms.

What makes the findings different?

Every finding carries how it was established — proven, inferred, reported or heuristic — separately from its severity and its confidence. "Proven" means the weakness is in a response the scan holds, and one click filters the list to that tier alone. A scanner that reports a version-matched CVE, a regex hit and a reflected payload with the same authority is the reason nobody trusts scanner output; the tiers are what let you break a build on the demonstrated tier only and still read the rest.

Do I still need a penetration test?

Yes. heimdallX runs unauthenticated checks from the outside, plus a read-only authenticated crawl via the API — it does not execute JavaScript, fuzz POST bodies or think laterally the way a human tester does. What it gives you is continuous coverage between engagements, and a fix-first list that lets the next engagement start from what is already known. Everything it cannot check is written down in LIMITS.md.

What can't heimdallX check?

The scanner does not execute JavaScript, reads only GET parameters against your site, crawls a bounded number of pages, and cannot log in through SSO, MFA or JavaScript-driven forms. The cloud module is agentless, with a native read-only AWS connector on self-hosted installs. Every one of these limits is in LIMITS.md next to the code that makes it true, and a scan says how many pages and scripts it actually read.

Can the AI make findings up?

No. Model-authored findings are grounded against the reconnaissance the scan actually holds — anything naming a host, header or version absent from it is dropped before the report, and the number dropped is shown. Board-brief risks must correspond to findings we hold, and a page that tries to instruct the scanner is fenced off from the model and becomes a finding of its own.

Which compliance frameworks are mapped?

Findings map to controls in OWASP Top 10, OWASP API, OWASP LLM, OWASP Agentic, PCI-DSS 4.0, ISO/IEC 27001:2022, SOC 2, CIS Controls v8, NIST CSF, GDPR Art. 32/33, the HIPAA Security Rule, ISO/IEC 42001, NIST AI RMF and the EU AI Act. The mapping is curated by hand and shows which control an auditor would flag a finding under — it is not an audit, and a clean scan is not a passed control.

Is SSO extra? What about SCIM?

SAML SSO, granular roles and the append-only audit log are on every plan, including Free — charging for a security control pushes the customers with the most users onto shared passwords. SCIM 2.0 provisioning is on Business, because automated provisioning is an operations convenience rather than a security floor: every plan can invite members by hand.

Can I take my data out?

One call — the workspace export — returns assets, scans, findings, remediation history, suppression rules, incidents, audit log and integration configuration, with secrets stripped. Coming in is one paste: the asset import takes the host list any scanner exports. Nothing is reachable only through the UI.

See what attackers see — before they do

Run your first scan in under two minutes. Free, no credit card, real findings.

Launch heimdallX
heimdallX — AI Security Platform for Web, Cloud, Code & Exposure