Vornin
Start Free
Platform

Every attack surface.
Always watched.

Scanning, tracking, compliance, integrations, team collaboration — unified into a single operations console, so findings deduplicate and frameworks stay accurate.

Coverage

Every layer, one platform.

Fifteen engines across network, crypto, web, API, DNS, code, supply chain, CMS, containers, Kubernetes, and cloud posture — plus distributed agents for the bits behind your firewall.

Layer 01Network

Network & Ports

TCP + UDP port discovery with service fingerprinting. Optional Nmap depth. Finds exposed admin panels and forgotten dev services.

Layer 02Crypto

SSL / TLS

Certificate chain, expiry, cipher-suite strength, protocol versions, and known-vulnerability probes (Heartbleed, POODLE, ROBOT).

Layer 03Application

Web & API

OWASP Top 10 plus API-specific checks: CORS, auth bypass, error disclosure, GraphiQL, missing rate limits.

Layer 04DNS

DNS & Recon

SPF / DKIM / DMARC verification, zone transfers, DNSSEC, plus subdomain discovery via CT logs and DNS brute force.

Layer 05Code

Code & Supply Chain

Static analysis (Semgrep), secret scanning (Gitleaks), dependency scanning (Trivy). Runs on connected repositories.

Layer 06Internal

Internal Networks

Lightweight .NET agents run inside your perimeter. Private IPs route to available agents automatically — no firewall changes.

Layer 07Container

Container Images

Trivy-powered image scanning. Points at a registry tag or local Docker image and reports CVEs by layer with fix-version guidance.

Layer 08Attack surface

Continuous ASM

Daily subdomain discovery picks up forgotten hosts before attackers do. New subdomains get notifications; high-value ones auto-scan.

Lifecycle

Discovery to resolution.

Every finding moves through six stages. Each one is tracked, auditable, and tied to the same deduplication and compliance pipeline.

01Discover

Scan

Scheduled or on-demand. Native engines plus imported reports from Nessus, OpenVAS, or CSV/JSON feeds.

02Normalise

Deduplicate

SHA-256 fingerprinting ensures each finding is tracked exactly once — even across multiple scanners or successive scans.

03Rank

Prioritise

CVSS + EPSS + CISA KEV + CWE weakness class, mapped to your asset's criticality. SLA policies drive per-severity due dates.

04Assign

Collaborate

Assign, comment, attach evidence, push to Jira. Email + webhook notifications keep the loop closed.

05Resolve

Verify

Re-scan confirms the fix. Auto-resolve closes the ticket the next time it's not found. Scan comparison shows exactly what changed.

06Prove

Report

Branded PDFs, compliance packets, executive dashboards. Scheduled reports keep stakeholders informed without human work.

Governance

Enterprise by default.

Security and multi-tenancy aren't premium add-ons — they're foundational. Every tier gets the same isolation guarantees.

01Isolation

Multi-tenancy

Row-level tenant isolation at the PostgreSQL layer. Global query filters enforce scope across every service and job.

02Identity

SSO & MFA

Passwordless magic links, TOTP MFA, per-tenant SAML SSO. Tenant admins can enforce MFA for all members.

03Access

Role-based access

Owner · Admin · Member, plus platform admin. Granular control over who can scan, configure, and manage.

04Audit

Audit trail

Immutable log of every action — user, timestamp, IP, details. Exportable for incident investigation.

05Integrations

API & webhooks

OpenAPI-documented REST API. HMAC-signed webhooks to Slack, Teams, Jira, or any HTTP endpoint.

06Data

Data protection

AES-256-GCM at rest. Configurable retention per tenant. GDPR Article 17/20 support. IP allowlisting.

Get started

See the platform in action.

Start your free trial, or book a 20-minute walkthrough with the team.