Vornin
Start free

European vulnerability management your auditor can verify

Scan your attack surface, resolve findings with SLA tracking, and export audit-grade evidence for NIS2, DORA, ISO 27001 and more. EU data residency.

No credit card required Full scan coverage, every tier EU-hosted

Preview of Vornin web app with representative scan data

How it works

Scan. Resolve. Prove.

Use Vornin to run the whole vulnerability management lifecycle on one record: find exposure, drive remediation to a verified fix, and keep the evidence attached.

  1. 01

    Scan for vulnerabilities

    Fifteen scanner engines cover your attack surface, web apps, infrastructure, code and cloud. Every finding dedupes to one record.

  2. 02

    Resolve what matters

    Get real-world risk ranking, remediation guidance, SLA tracking and automatic escalation for missed deadlines. Rescans close findings only when the issue no longer appears.

  3. 03

    Prove the work

    Each finding maps to the controls it touches and carries a tamper-evident history for your auditor.

Workflows

Prioritise findings, move fixes forward and prove the work

Discover assets, assign owners, track SLAs, verify fixes and report from the same finding record.

See what is exposed

Track known assets and catch new external exposure as it appears, down to forgotten subdomains and services.

Vornin target inventory with per-asset health scores and open findings

Know what needs attention

Rank persistent findings by real-world risk, affected assets and exploitability, on one record that survives every rescan.

Vornin vulnerability queue showing prioritised findings

Know when exposure changes

Daily sweeps flag new assets and alert you when known-exploited vulnerabilities (CISA KEV) match your confirmed stack.

Vornin attack surface: hosts tracked, open services and newly discovered assets

Turn security work into evidence

Findings map to their controls as you work, so remediation becomes audit evidence, not a separate write-up.

Vornin compliance overview: controls continuously tested and tamper-evident export Vornin compliance framework health across CIS Controls, DORA, GDPR, ISO 27001, NIS2 and other frameworks

Keep remediation moving

Give engineers plain-language remediation guidance, create issues in Jira, GitHub, GitLab or Azure DevOps, and keep status tied to the original finding.

Vornin AI remediation guidance: numbered upgrade steps Critical vulnerability

Keep stakeholders informed

Generate executive, technical and compliance reports from the same data, with no spreadsheet rebuild.

Vornin report configuration: type, scope and severity Generated Vornin vulnerability assessment report cover
Coverage

Scan web, infrastructure,
cloud and code
from one platform

Every finding enters the same queue, risk model and reporting workflow, regardless of where it was found.

Code / supply chain

Catch risk before release

Run static analysis, secret scanning, dependency checks and SBOM analysis before release.

Audit evidence

Prove how each finding was handled

Show auditors the recorded lifecycle, relevant control mappings, supporting evidence and chain-verification result.

  1. Each finding maps to the framework controls it touches, automatically.

  2. Every status change writes to a per-tenant, tamper-evident chain sealed with SHA-256. Change a record after the fact and the chain breaks.

  3. Export any finding as an auditor pack: lifecycle, evidence and chain verification in one file.

Finding CVE-2025-31146
  1. Detected
  2. Triaged
  3. Assigned
  4. Fixed
  5. Verified
Chain verificationsha256:8f3a...b912 Verified
Mapped controlsNIS2DORAISO 27001
Exportauditor-pack-q2.zipLifecycle · evidence · verification

NIS2DORAISO 27001SOC 2PCI DSSHIPAAGDPRNIST 800-53CIS Controls

See all compliance mappings
Why Vornin

Vulnerability management
built for evidence, not just detection

Vornin combines deterministic detection, EU data residency and persistent finding history, turning scan findings into evidence for the compliance controls they affect.

A deterministic scanning core

Defined scan checks produce each finding, and rules score its priority from CVSS, EPSS and CISA KEV, so the same inputs produce the same priority. AI supports the process, adding context, remediation guidance and triage; it does not create findings.

  • 15 scanner engines
  • 0 AI-generated findings
European by design

Vornin is a European company under EU jurisdiction, not the US CLOUD Act. Your scan data, findings, and audit evidence are stored in the EU. No US data region toggle, and every sub-processor is published.

  • EU data residency
  • 9 compliance frameworks mapped
History that never resets

Rescans update the same record. Ownership, remediation, verification and evidence remain attached from detection to closure.

  • 1 record across rescans
  • SHA-256 evidence chain
Start without a sales call

Run a free scan and check transparent pricing before committing. Full scan coverage across all plans; Free, Team and Business self-onboard today.

  • €0 to start
  • 3 self-serve plans
FAQ

Get clear answers before you start

Understand scanning coverage, compliance scope, EU hosting, integrations and how signup works.

What is Vornin?Overview

Vornin is a European vulnerability management platform. It scans your external attack surface, web apps, infrastructure, code and cloud with 15 engines, drives every finding to a confirmed fix, and turns that work into tamper-evident audit evidence.

How is Vornin different from a vulnerability scanner?Model

A scanner finds issues and hands you a report. Vornin runs vulnerability management: it keeps one record per finding across scans, ranks it by real-world risk, tracks it to a confirmed fix, and maps it to the compliance controls it touches. Detection is the start, not the deliverable.

What can Vornin scan?Coverage

Web apps and APIs, your external attack surface, network and infrastructure, cloud posture across AWS, Azure and GCP, containers and Kubernetes, plus source code, secrets and dependencies. Fifteen engines across every scan type, one platform.

Does Vornin make us NIS2, DORA or ISO 27001 compliant?Compliance

No tool can. Vornin maps findings to the technical controls it can test and gives you tamper-evident evidence of the work. It reports control health honestly and never fakes a score for controls a scanner cannot check. Certifying your organisation stays your auditor's job.

Where is Vornin hosted?EU hosting

Vornin is a European company, a Danish ApS, with no US parent, and is not subject to the US CLOUD Act. Your vulnerability data, findings and audit evidence are stored in the EU under EU law.

Does Vornin keep a copy of our source code?Code access

No. Code scanning uses read-only access. Vornin reads what it needs to scan, then deletes the local copy. No retained code, no silent writes.

Can Vornin work alongside our existing security tools?Integrations

Yes. Vornin's integrations import findings from other scanners, create issues in GitHub, GitLab, Azure DevOps and Jira, add PR comments in GitHub, GitLab and Azure DevOps, and export to CSV, SARIF and SBOM. Vornin does not need to replace your stack to run the lifecycle on top of it.

Do I need to talk to sales?Signup

No. Add your first target and scan in minutes. Free, Team and Business are self-serve with published pricing. Only Scale adds a short setup conversation.

Scan, resolve and prove.
Free to start.

Add a target and see Vornin turn scan findings into evidence.

No credit card required Read-only access EU-hosted