Find real vulnerabilities in your web apps and APIs, ranked by live exploit intelligence, before they ship.
Passive checks, active exploitation probes, dependency analysis, and threat intelligence in one scan you run on demand or on a schedule.
Reflected and DOM XSS, injection, auth and access-control checks, TLS and security-header analysis, and port and service discovery, all crawl-aware and ranked by real-world risk.
Enriched from NVD, the CISA KEV catalog, and EPSS, so you fix what is exploited first.
Known ExploitedFind vulnerable and outdated dependencies, mapped to advisories with remediation guidance.
Schedule scans, set a baseline, and get alerted the moment a new vulnerability appears.
Fail the build on new criticals. Reports in JSON and SARIF for your review tooling.
Native MCP support lets AI agents run scans and read results. Push to Slack, Discord, or Jira.
No agents to install and no infrastructure to stand up. Point Vlume at a target you own and it does the rest.
Register the web app or API you own. Vlume verifies scope and refuses internal or unauthorized hosts by default.
Launch from the dashboard, wire the CLI into CI, or let an agent trigger it. Set a schedule for continuous coverage.
Review findings ranked by real-world risk, follow the remediation steps, and confirm the fix on the next scan.
$ vlume ci --target app.acme.io --fail-on high vlume starting authorized scan of app.acme.io -> passive checks, active probes, CVE intel, SCA ok crawled 128 routes in 41s Findings critical 1 reflected XSS /search?q= high 2 outdated dependency (KEV) medium 5 missing security headers FAIL new findings at or above high (threshold: high) report written to vlume-report.sarif exit code 1
Every plan includes the full scanner. Higher tiers add targets, scan volume, deeper crawls, and advanced modules.
Vlume is built to run safely against your own assets and to produce the evidence your compliance program needs.
Start scanningScope checks and an SSRF guard block internal and unauthorized hosts.
Every state change is recorded per account: who, what, when, and from where.
Owner, admin, member, and viewer roles with optional TOTP two-factor.
The who-did-what record maps directly to SOC 2 and ISO 27001 asks.
Run your first scan free in the next five minutes. No credit card, no sales call.
Tip: press / in the dashboard to jump straight to a scan.