Vulnerability Assessment

Go beyond continuous monitoring. Identify real exploitable vulnerabilities with controlled, authorized scanning.

Six ways to look at the same target

Price per delivery, VAT excluded. Every assessment ends with a report, not a raw export.

Exposure Assessment · 99 EUR

Safe, non-intrusive. What is already in the open on your target: the exposed surface and leaked secrets.

  • Site crawl and inventory of the exposed surface
  • Security headers, cookies, mixed content, known component versions
  • API keys and tokens exposed in JavaScript bundles, source maps and HTTP responses
  • Live verification of each found token’s validity, where possible
  • No attack payloads, nothing written to your target
  • Every secret is masked in the report - we never send you the raw key

Active Assessment · 279 EUR

Real attack payloads (SQLi, XSS, path traversal) under controlled conditions.

  • The crawl and passive analysis from the Exposure Assessment
  • SQL injection, XSS, path traversal, file inclusion
  • Rate limited, run inside the window we agree with you
  • Every finding carries the request that produced it
  • Remediation steps, ordered by what gets exploited first

Authenticated Assessment · 379 EUR

Tests protected areas after login.

  • Everything in the active assessment
  • A real user session, on a test account you provide
  • The areas behind the login, where the data lives
  • Access control checks: what one account can reach and should not
  • A separate report for what is only visible once logged in

AI-Agent Pentest (METATRON) · 890 EUR

An AI agent drives the recon and attempts exploitation, like a tester who improvises.

  • An LLM-driven agent decides what to test, step by step, based on what it finds
  • Real tools in a sandbox: nmap, nikto, whatweb, sqlmap, DNS/WHOIS lookups, HTTP requests
  • Goes beyond fixed payloads: actively tries to confirm what it discovers
  • Every finding carries the tool evidence behind it, so you can check it yourself
  • The deepest level: requires full authorization (two proofs, one at server level, plus a signed document)

Autonomous AI Pentest (Strix) · 990 EUR

An autonomous AI agent attempts exploitation and proves each finding with a proof of concept.

  • Strix, an open-source pentest agent with its own isolated sandbox: HTTP proxy, browser and terminal
  • Does not just flag: tries to confirm every vulnerability with a proof of concept
  • Looks for what fixed-payload scanners miss: access control, business logic, chained injections
  • Every finding comes with the evidence from the run and the steps to reproduce it
  • The deepest level: requires full authorization (two proofs, one at server level, plus a signed document)

Full Package · 1890 EUR

All five assessments on the same target, plus an executive summary and a 30 min review call.

  • Exposure, active and authenticated assessment (on a test account you provide)
  • Both AI-agent pentests: METATRON and Strix
  • Executive summary, written without jargon
  • A 30 minute call to walk through the findings
  • False positives separated from what has to be fixed now
  • One verification re-run after you remediate

-15% with a Pro or Ultra subscription.

Exposed does not mean exploitable

Continuous monitoring shows you what is exposed. Vulnerability Assessment shows you what can be exploited.

  • Runs continuously, in the background / Runs on demand, once, against one target
  • Observes, never touches / Sends test requests, inside agreed limits
  • Tells you what changed and what is exposed / Tells you what can actually be exploited
  • Starts on its own, once the agent is installed / Starts only after proof of ownership and written authorization
  • Included in your subscription / Paid add-on, per delivery

They complete each other: monitoring catches tomorrow’s change, an assessment tells you how bad today’s exposure already is.

Authorization required

Active and authenticated assessments require verified ownership of the target and signed rules of engagement. We only scan systems you control. Passive assessments need a single proof of control.

  • A DNS TXT record on the target domain: proves the name
  • A file under /.well-known on the target server: proves the server
  • The Valinor agent enrolled on the server: proves the server
  • A hosting account inside a reseller package we manage
  1. Choose scan type and submit the target: Fill in the form with the address you care about and the type of assessment. Nothing starts at this point.
  2. Complete ownership verification: A DNS TXT record, a file under /.well-known, or the agent already enrolled on the server. We tell you exactly what to put where.
  3. Sign the Rules of Engagement: A document with the target, the run window, the intensity and the report retention. You sign it through a link, no account needed.
  4. Pay: The invoice goes out after signing. If you have been on Pro or Ultra for at least 3 months, the discount is already applied.
  5. We run the scan: In the agreed window, rate limited. If the target moved in the meantime, the scan stops and asks for re-approval.
  6. You receive the report: In your account and by email: findings with evidence, severity and the remediation steps.