The platform, in depth

Beyond detection

Finding issues is table stakes. heimdallX proves what's exploitable, emulates the adversary, watches your surface around the clock, and ships the controls enterprises require. Explore each capability below.

Exploit validation

Exploitability Validation Core

Stop chasing severity. Rank by what's actually exploitable — EPSS probability, CISA KEV, and proven reachability.

  • EPSS exploit-probability weighting
  • CISA KEV known-exploited priority floor
  • Version-aware CVE matching — zero invented CVEs
Learn more →
Active validation

Proof-based Active Testing

Confirm vulnerabilities by safely triggering them — reflected XSS, error-based SQLi and open redirects, proven not guessed.

  • Consent-gated, non-destructive GET probes
  • Reflected-XSS, error-SQLi & open-redirect proof
  • Same-origin, rate-limited, self-identifying agent
Learn more →
Adversary emulation

Attack Simulation & MITRE ATT&CK

See findings the way an adversary chains them — mapped to MITRE ATT&CK tactics and techniques.

  • MITRE ATT&CK coverage matrix
  • Tactic → technique mapping per scenario
  • Severity-weighted kill-chain view
Learn more →
Continuous EASM

Continuous Attack-Surface Discovery

Watch your external footprint change over time — new hosts, shadow IT and disappearing assets, run after run.

  • Snapshot + delta across every run
  • New / gone host detection
  • Shadow-IT (risky new host) flagging
Learn more →
SCA / SBOM

Software Composition Analysis

Find vulnerable dependencies — most of your risk lives in code you didn't write.

  • npm + PyPI manifest parsing
  • OSV-backed vulnerability matching
  • SBOM inventory · CVEs flow to Validation Core
Learn more →
Threat intel

Live Threat Intelligence

Know what's being exploited in the wild today — KEV, EPSS and emerging-exploit signals wired straight into your queue.

  • Daily CISA KEV & EPSS feed sync
  • Emerging-exploit & public-PoC alerts
  • Auto re-prioritizes findings as threats move
Learn more →
External threat intel · DRP

External Threats & Digital Risk Protection

Watch the outside-in too — leaked credentials, dark-web & Telegram chatter, malware/C2 IOCs, ransomware victim posts and look-alike domains, all correlated to your assets and ranked by TALON.

  • Leaks, dark web, ransomware, brand-abuse & IOCs in one feed
  • TALON composite scoring + ATOM account-takeover chains
  • AI briefing & threat-knowledge graph, gated to Pro / Business
Learn more →
Attack-surface graph

Attack-Surface Graph

See your whole external footprint as one living graph — assets, services, exposures and how an attacker pivots between them.

  • Live asset ↔ service ↔ exposure graph
  • Shortest attacker path to crown-jewel assets
  • Blast-radius view for every finding
Learn more →
Adversary emulation

Attack-Path & Breach Simulation

Chain individual findings into end-to-end attack paths — see how a breach actually unfolds, before it does.

  • Multi-step exploit-chain construction
  • Likelihood-weighted breach scenarios
  • Mapped to MITRE ATT&CK stages
Learn more →
Cloud posture · CSPM

Cloud Security Posture (CSPM)

Catch the cloud misconfigurations attackers love — public buckets, open ports, over-broad IAM — mapped to the same fix-first queue.

  • Public storage & exposed-service checks
  • Over-permissive IAM & policy findings
  • CIS-benchmark aligned, one unified queue
Learn more →
Continuous monitoring

Continuous Monitoring & Alerting

Set it and stay covered — scheduled re-scans, drift detection and alerts the moment your exposure changes.

  • Scheduled re-scans & DRP collection
  • Change/drift alerts on new exposure
  • Routed to Slack, webhook or email
Learn more →
SOC · detection & response

SOC Console & Telemetry Ingestion

Ship your cloud, identity and VCS logs in — heimdallX normalises them, runs detections, and turns each one into an incident an analyst can work to closure.

  • Metered log ingestion with an API key — cloud audit, identity, VCS, syslog
  • Sigma-compatible detections mapped to MITRE ATT&CK
  • AI triage, MTTA / MTTR targets and suppression rules
Learn more →
Shift-left · CI/CD

CI Gate, SARIF & Public API

Run heimdallX from your pipeline: a scan per build, SARIF into code scanning, an SBOM per release — and a gate that breaks the build only on what was demonstrated.

  • Per-workspace CI keys, reference GitHub / GitLab workflows
  • SARIF 2.1.0 + CycloneDX SBOM per scan
  • Gate on the proven tier only — never on a model's guess
Learn more →
AI copilot

AI Security Analyst

An AI analyst on every finding — it explains the risk, drafts the fix, and answers 'so what?' in plain language.

  • Plain-language 'why it matters' per finding
  • One-click PR-ready fix prompts
  • Ask-anything copilot over your posture
Learn more →
Board reporting

Executive & Board Reporting

Turn technical findings into a board-ready story — posture, business risk and a dated remediation roadmap, one click to PDF.

  • Auto-generated executive brief
  • 0–30 / 30–60 / 60–90-day roadmap
  • One-click PDF / CSV export
Learn more →
Workflow & SIEM

Integrations & Workflow

heimdallX fits your stack — Slack, webhooks, SIEM and ticketing — with an API and audit trail behind every action.

  • Slack, webhook & email alert routing
  • SIEM / ticketing export via API
  • Append-only audit log on every action
Learn more →
AI remediation

AI Remediation & Fix

Every finding ships with a clear, PR-ready fix — and a one-click prompt your AI coding agent can apply.

  • Per-finding fix steps & config snippets
  • Copy-ready Claude Code fix prompt
  • Owner routing in fix-first order
Learn more →
Continuous compliance

Continuous Compliance Evidence

Map every finding to the frameworks auditors ask about — with a timestamped evidence trail.

  • OWASP · PCI-DSS · ISO 27001 · SOC 2 · CIS · NIST CSF · GDPR · HIPAA · EU AI Act mapping
  • Per-control "last checked" freshness
  • Timestamped evidence trail
Learn more →
AI cost & governance

AI Cost Governance & FinOps

Run AI-driven security at scale without runaway bills — per-workspace token tracking, hard budget caps and an admin operations console.

  • Per-workspace AI token & cost tracking
  • Hard budget caps, enforced not just alerted
  • Admin operations console + audit trail
Learn more →
Enterprise

Enterprise Controls

SSO, SCIM, granular roles and an append-only audit log — the controls security teams must have.

  • SAML SSO on every plan · SCIM on Business
  • Granular RBAC (owner / admin / analyst / viewer)
  • Append-only audit log + team workspaces
Learn more →

See what attackers see — before they do

Run your first scan in under two minutes. Free, no credit card, real findings.

Launch heimdallX
Beyond detection — heimdallX