Web application security scanning

Ship secure.
Scan every release.

Find real vulnerabilities in your web apps and APIs, ranked by live exploit intelligence, before they ship.

Fits the tools your team already runs

0+
Detectors in the engine
0
OWASP Top 10 categories covered
0
Scans per month on Pro
KEV + EPSS
Live exploit intelligence
Capabilities

The depth of a pentest, at pipeline speed

Passive checks, active exploitation probes, dependency analysis, and threat intelligence in one scan you run on demand or on a schedule.

Active and passive testing

Reflected and DOM XSS, injection, auth and access-control checks, TLS and security-header analysis, and port and service discovery, all crawl-aware and ranked by real-world risk.

Live CVE intelligence

Enriched from NVD, the CISA KEV catalog, and EPSS, so you fix what is exploited first.

Known Exploited

Software composition

Find vulnerable and outdated dependencies, mapped to advisories with remediation guidance.

Continuous monitoring

Schedule scans, set a baseline, and get alerted the moment a new vulnerability appears.

CI/CD gating

Fail the build on new criticals. Reports in JSON and SARIF for your review tooling.

$ vlume ci --fail-on high
FAIL 1 new critical finding

Agent-ready

Native MCP support lets AI agents run scans and read results. Push to Slack, Discord, or Jira.

Running in minutes, not months

No agents to install and no infrastructure to stand up. Point Vlume at a target you own and it does the rest.

Add a target

Register the web app or API you own. Vlume verifies scope and refuses internal or unauthorized hosts by default.

Run or schedule a scan

Launch from the dashboard, wire the CLI into CI, or let an agent trigger it. Set a schedule for continuous coverage.

Triage and fix

Review findings ranked by real-world risk, follow the remediation steps, and confirm the fix on the next scan.

Security that fails the build, not the release

  • One command in any CI: GitHub Actions, GitLab, or Jenkins.
  • Threshold gates so a new critical or high stops the merge.
  • Report artifacts in JSON and SARIF for your review tooling.
  • Quota-aware, so billing state never breaks a build.
ci: vlume scan
$ vlume ci --target app.acme.io --fail-on high

vlume starting authorized scan of app.acme.io
  -> passive checks, active probes, CVE intel, SCA
  ok   crawled 128 routes in 41s

Findings
  critical  1   reflected XSS   /search?q=
  high      2   outdated dependency (KEV)
  medium    5   missing security headers

FAIL new findings at or above high (threshold: high)
report written to vlume-report.sarif
exit code 1
Pricing

Start free, scale when you are ready

Every plan includes the full scanner. Higher tiers add targets, scan volume, deeper crawls, and advanced modules.

Free
$0
For trying Vlume on a single app.
Get started
  • 1 target
  • 3 scans per month
  • Passive checks and reflected XSS
  • Findings dashboard
Starter
$49/mo
For small teams securing a few apps.
Choose Starter
  • 3 targets
  • 30 scans per month
  • Full web vulnerability suite
  • CVE intel and SCA
  • Email and webhook alerts
Most popular
Pro
$249/mo
For teams shipping continuously.
Choose Pro
  • 15 targets
  • 300 scans per month
  • DOM XSS, network, and auth modules
  • Deeper crawl and scheduled scans
  • CI/CD gating and integrations
Enterprise
Custom
For unlimited scale and compliance needs.
Book a demo
  • Unlimited targets and scans
  • All modules, deepest crawl
  • SSO, roles, and full audit trail
  • Priority support and onboarding
Pay by card, bank transfer, USSD, or mobile money, secured by Flutterwave. Cancel anytime.

Security you can put in front of an auditor

Vlume is built to run safely against your own assets and to produce the evidence your compliance program needs.

Start scanning

Authorized targets only

Scope checks and an SSRF guard block internal and unauthorized hosts.

Audit trail

Every state change is recorded per account: who, what, when, and from where.

Roles and MFA

Owner, admin, member, and viewer roles with optional TOTP two-factor.

Compliance evidence

The who-did-what record maps directly to SOC 2 and ISO 27001 asks.

Find your vulnerabilities before someone else does

Run your first scan free in the next five minutes. No credit card, no sales call.

Tip: press / in the dashboard to jump straight to a scan.