Vornin
Start free
Questions

Frequently asked questions
about Vornin.

Quick answers on setup, scanner coverage, compliance reporting, integrations, account security, plans, and billing.

Getting Started4 entries
What is Vornin?

Vornin is an enterprise vulnerability management platform: continuous security scanning, vulnerability tracking, compliance reporting, and team collaboration in one pane. It scans your websites, servers, networks, APIs, and code repositories and helps you manage the entire remediation lifecycle.

How do I get started?

Sign up for a free account, no credit card required. Add a target, run a scan, review the results. The onboarding wizard handles the rest. Your first results arrive in under five minutes.

Do I need to install anything?

No. Vornin runs in your browser. The only exception is scanning internal networks, which uses a lightweight .NET scan agent deployed on your network. The agent is a single executable that connects outbound to your Vornin account.

Is there a free trial?

Yes. 14 days of full Team or Business access, no credit card required. After the trial, continue on the Free plan (3 targets) or upgrade. Scale is request-based. Contact us for a Scale trial. No automatic charge, ever.

Scanning6 entries
What scan types does Vornin support?

Fifteen built-in scanner engines: Port Scanner, SSL/TLS, Web Vulnerability Scanner, API Security, Nuclei Templates (opt-in), DNS Security, Subdomain Discovery, Subdomain Takeover, SAST, Secret Scanning, Dependency Scanning, WordPress Scanner, Container Image Scanner, Kubernetes Posture, and Cloud Security Posture (AWS / Azure / GCP).

Plus import-only support for Nessus (.nessus), OpenVAS (.xml), CSV, and JSON. External reports land in the same tracking, evidence chain, and compliance pipeline.

How long does a scan take?

Depends on scope. SSL/TLS and DNS: under 30 seconds. Port scan: 1–3 minutes typical. Full web vulnerability scan with crawling: 5–15 minutes. Code scans depend on repo size.

Can I schedule recurring scans?

Yes, from Team onward. Up to 5 scheduled scans on Team, 15 on Business, unlimited on Scale. Save scan profiles to re-run identical configurations.

Can I scan internal networks?

Yes. Deploy a Vornin scan agent inside your network. The agent polls for tasks, executes scans locally, and reports back over HTTPS. Targets on private IPs (10/8, 172.16/12, 192.168/16) route to available agents automatically.

What IPs do your scanners use?

Cloud-originated scans run from our EU infrastructure. Contact support for the current IP list if you need to allow-list our scanners. Internal scans run from your agents, no firewall changes needed.

Will scanning affect production?

Baseline scans are designed not to modify target data. Port and TLS checks connect to inspect exposed services and configuration. Web scans use passive checks and controlled path probes by default. Opt-in active attack probes send intrusive test payloads and should be limited to non-production targets. Max Parallel and Crawler Depth controls let you throttle intensity.

Vulnerability Management5 entries
How does deduplication work?

Every finding gets a SHA-256 fingerprint based on host + scan type + title + URL. Subsequent scans match to the existing record instead of duplicating. When a later successful scan retests the finding and no longer detects it, the finding auto-closes as Resolved. Failed and partial-coverage scans close nothing.

What is an SLA policy?

Business and Scale include per-severity remediation deadlines. Example: Critical within 1 day, High within 7 days. When a deadline is missed the finding is flagged SLA Breached and escalation emails fire to the configured recipients (or tenant owners by default).

Can I suppress false positives?

Yes, from Team onward. Suppression rules match by fingerprint, title pattern, host pattern, or scanner type. Suppressed findings are tracked as Dismissed with a reason for audit.

Can I assign to team members?

Yes. One-click assignment with email notification. Comments, activity timeline, and assignment history are all tracked on the finding.

Can I export vulnerability data?

Yes. Team and above include CSV exports, PDF reports, and REST API access. Business adds custom PDF branding; Scale adds full white-label reports. Findings exports include evidence URLs.

Compliance & Reporting4 entries
Which frameworks are supported?

Nine frameworks with auto-mapping: CIS Controls v8, NIST 800-53 Rev 5, ISO 27001:2022, SOC 2, PCI DSS, HIPAA, GDPR, DORA (EU 2022/2554), and NIS2 (EU 2022/2555). Each framework maps relevant controls to vulnerability findings. Tenant-wide auditor pack PDF available from Business onward.

Can I generate branded reports?

Yes, from the Business plan. Configure company name, logo, brand colors, report title, contact email, confidentiality label, and footer in Settings — all PDF reports (scan, compliance, auditor pack, scheduled) carry your branding with a small “Powered by Vornin” byline. The Scale plan adds full white-label: Vornin branding removed from the PDFs entirely.

Can I schedule automatic reports?

Yes. Report schedules email PDFs to specified recipients at configurable intervals (weekly summary, monthly compliance, etc.).

Does Vornin help with SOC 2 / ISO 27001 audits?

Yes. Continuous scanning, documented remediation timelines, SLA tracking, audit logs, and compliance reports produce evidence auditors commonly request. The compliance dashboard shows real-time posture across supported frameworks. Vornin supports audit preparation; it does not certify compliance or guarantee an audit outcome.

Integrations & API3 entries
What integrations are available?

Team includes Slack, Microsoft Teams, Jira, Discord, generic HMAC-signed webhooks, and GitHub, GitLab, or Azure DevOps connections for code scanning. Business adds issue and pull-request fix-plan write-back. More on the roadmap. Request one.

Is there a REST API?

Yes, from Team onward. Create scans, list findings, query targets, retrieve status. Authenticate with scoped API keys (Bearer token). Full OpenAPI docs at /api-docs in your Vornin instance.

Can I use Vornin in CI/CD?

Yes. Trigger scans via API from GitHub Actions, Azure Pipelines, Jenkins, or any CI tool. Build gates that block a deployment on scan results are available on Scale.

Security & Privacy5 entries
How is my data protected?

Encrypted PostgreSQL with tenant-level row isolation. Sensitive fields (tokens, credentials) encrypted at rest with AES-256-GCM. All connections TLS 1.2+. Security-relevant actions are written to an audit log, and vulnerability lifecycle events carry a tamper-evident hash chain.

Is multi-tenancy secure?

Yes. Every query is automatically scoped by tenant ID, enforced centrally in the data layer rather than per feature, and backed by tenant-scoped database constraints. No tenant can see another tenant's data.

What authentication is supported?

Passwordless magic links by default, TOTP MFA (Google Authenticator, Authy, etc.), per-tenant SAML SSO and SCIM 2.0 from Business onward (no SSO tax). Tenant admins can enforce MFA for all members.

Is Vornin GDPR compliant?

Vornin supports GDPR requirements with EU hosting, Article 20 data export, Article 17 account deletion, and configurable retention. The authenticated app uses essential cookies only, with no advertising trackers. The public marketing site uses consent-gated analytics and advertising services detailed in our privacy policy.

Can I restrict access by IP?

Yes, from Business onward. Allow-list specific IPs or CIDR ranges per tenant. Access from any other IP is blocked.

Account & Billing4 entries
How does pricing work?

Four tiers in EUR: Free (€0, 3 targets), Team (€129/mo), Business (€299/mo), and Scale (€699/mo). Paid tiers include 5 base targets plus a slider for more, with volume discounts after 50 and 100 targets. Annual billing saves 20%. See the pricing page.

Can I cancel any time?

Yes. Cancel from account settings. Data stays available for 30 days post-cancellation for export, then it's deleted.

What if I exceed my target limit?

Free has a 3-target hard cap. Paid plans have no fixed target ceiling: choose additional target allowance with the pricing slider, and review the updated price before confirming. No automatic overage billing.

Volume or MSP discounts?

Volume discounts apply automatically after 50 and 100 targets. Annual billing is self-serve at 20% off. Contact us for MSP and reseller terms.

Get in touch

Still have questions?

We reply personally. No ticket queues.