Account
Your identity, plan and usage across this organization.
Plan & usage
Scan requests
Customize the HTTP requests every scan sends to your targets - add headers, set a User-Agent, attach a session cookie or token, route through a proxy, and throttle the rate. These apply org-wide as defaults to all new scans.
Custom headers
Sent on every request (e.g. X-API-Key, an Authorization bearer, a WAF-bypass header). Structural headers (Host, Content-Length…) are managed automatically and can't be set here.
Identity & session
Network & rate
Proxy routes all scan traffic (e.g. through Burp/ZAP). Rate limit caps requests per second across the whole scan. Redirect/TLS overrides apply globally - leave on default unless you know a scanner relies on them.
Notifications
Post a summary to Slack (or any webhook) when a scan finishes. Works with a Slack Incoming Webhook URL.
Integrations
Send verified findings to issue trackers, chat, SIEM and vuln-management tools. Ticketing connectors open one issue per new finding (deduped by fingerprint); chat/webhook connectors post a scan summary. Note: credentials are stored server-side (no encryption-at-rest layer yet).
Loading…
Scheduled scans
Run a target automatically on a cadence - continuous monitoring. Scheduled scans auto-approve scope and run end to end.
Team
Invite teammates and manage their roles across this organization.
Security
Two-factor authentication protects your account with an authenticator app (TOTP). Keep your backup codes somewhere safe.
Loading…
Recent sign-ins
The last 20 sign-in attempts on your account. Spot anything you don't recognize - an unfamiliar IP or device - and rotate your password + enable 2FA.
Loading…
Organizations
Every organization on the platform. Open one to manage its members, domains, scans and manual findings.
Loading…
Pending approvals
Loading…
Activity - who ran what
Every scan run across all organizations, attributed to the user who launched it.
Loading…
Analyze an API spec to preview the problems each endpoint could face, or select an asset to explore its discovered hosts and findings.
Loading…
Loading…
Add a domain, prove ownership, then scan it. Only verified domains can be scanned.
Target
Only verified domains can be scanned. Passive recon runs first - you approve scope before active testing.
Scan depth
Operator instructions optional
Steer the AI for this engagement - what to focus on, what to avoid, tech/stack hints, business logic to test. It shapes the AI test-plan and the exploitation agent.
Intensity
Authenticated testing optional ▶
The agent logs in with these to test the authenticated surface and IDOR across accounts.
Advanced optional
Which AI drives planning, exploitation, and reporting.
Documented API endpoints get seeded into the surface so the agent tests them.
Push a scan's findings into your system of record. Jira: one issue per NEW finding (deduplicated by fingerprint). DefectDojo: imports the SARIF bundle. Trigger a push from the Reports page or a scan's report view.
Loading…