Starter
€149/ month
For focused engineering teams establishing continuous security coverage.
- Application and API coverage
- External attack-surface monitoring
- Repository security monitoring
- Guided remediation workflows
- Finding and verification history
Vallum continuously tests your applications, APIs, external attack surface, and source code. AI validates the risk that matters, coordinates the right remediation, and re-tests every resolved issue.
Authorized testing · Evidence-led findings · Human-controlled remediation

Evaluate your external posture without creating an account
Free, no account. Public records and a normal page request — nothing intrusive.
AI pentesting for applications and APIs
Vallum’s testing agents interact with application workflows, authorization boundaries, identities, and APIs. They adapt to what the system returns and follow evidence toward material impact.
The result is not a speculative alert. Each validated attack path carries the request, response, affected boundary, business impact, and remediation context required to act.
Vallum operating model
Vallum connects autonomous testing, evidence, remediation, and verification across the full application environment—without removing human approval from consequential changes.
Workflow simulation
Validated application attack path
Authorized estate
Application estate
Active
AI pentesting
Attack paths + scanners
Vallum AI
Risk validation
Defensive action
Controls + safe fixes
Verification
Outcome evidence
Continuous defense
Vallum AI translates attack evidence into the smallest effective defensive action—from credential rotation and policy changes to configuration updates and reviewable code fixes.
Automation prepares the path; your controls authorize the change. Vallum then re-tests the original exposure and records the outcome.
Defense plan · VLM-1042
Unauthorized access to customer records
Contain
Provider-specific credential rotation and access-review steps
Correct
Configuration, policy, or code-level control selected from evidence
Deploy
Human approval, change management, and rollback remain in place
Verify
Resolution is recorded only when the exposure is no longer reproducible
Closure requires successful verification
Evidence retained end to end
External posture assessment
Run a non-invasive assessment using public DNS, certificate data, and a standard request to your homepage. No account, deployment agent, or privileged access is required.
Results are intentionally concise. If Vallum finds no actionable exposure, the assessment returns a clear result rather than a list of low-value observations.
A hostname still pointing at a service that was cancelled or deleted. Whoever registers that name next controls what your subdomain shows.
Not just a missing DMARC record — the ones that exist and are being ignored. Two SPF records cancel each other out; a record ending in +all authorises the entire internet.
Expiry, trust, and what your visitors will see when it goes. This is reliably the line people act on the same afternoon.
Cookies carrying a login with no HttpOnly, or no Secure. Not your analytics cookies — those are supposed to be readable.
Every certificate ever issued for your domain is published publicly. Staging, admin, and legacy names show up in that list, and it is where an attacker starts.
An MX record pointing at a host that does not resolve. Not hypothetical — mail people send you is failing right now.
Product roadmap
Application, API, and external-surface testing establish the foundation. Cloud posture, runtime defense, and broader attack simulation will be introduced as separately governed modules when they are production-ready.
Platform principles
Scheduled testing keeps applications, APIs, external assets, and repositories under review between formal assessments and major releases.
Scanner evidence, affected locations, AI assessment, and remediation state remain connected throughout the finding lifecycle.
Vallum AI focuses on a controlled set of critical findings, with secret exposures prioritized and scanner severity preserved.
Each validated issue receives an actionable remediation path. Where a safe code change can be prepared, Vallum opens it as a pull request for review.
Finding state and remediation history remain attached across scans, providing continuity for engineering and assurance teams.
Every assessment runs within defined time and cost boundaries, making consumption predictable and enforceable.
Signal governance
Security teams do not need another measure of scanner activity. They need a defensible view of material exposure, its supporting evidence, and the next action required from engineering.
Raw scanner workflow
Vallum
Coverage remains broad. Attention remains deliberately constrained to findings that warrant an engineering or risk decision.
Security architecture
Vallum operates inside sensitive engineering workflows. Its trust model is built around scoped access, isolation, data minimization, and verifiable control boundaries.
Repository analysis runs against an isolated working copy that is destroyed when processing completes. Vallum retains findings, not a persistent source-code mirror.
Domain and repository assessments require verified control. Authorization scope and timing are recorded before active testing begins.
Detected credentials are represented by one-way fingerprints for correlation. The original secret value is not persisted in Vallum's findings store.
Organization boundaries are enforced through database policies in addition to application authorization, reducing reliance on a single control layer.
Findings, decisions, pull requests, and verification outcomes form a durable record that supports internal review and customer assurance workflows.
Assessment duration and spend limits are explicit. Work that would exceed an approved boundary is refused rather than allowed to continue silently.
Pricing
Vallum provides continuous visibility between point-in-time assessments, with plans aligned to monitored scope and operational usage rather than report volume.
Formal penetration tests and compliance assessments remain distinct controls. Vallum complements them by keeping findings, remediation, and verification current throughout the year.
Starter
€149/ month
For focused engineering teams establishing continuous security coverage.
Growth
Most popular€499/ month
For growing organizations formalizing security and customer assurance workflows.
Enterprise
Talk to us
For complex application estates with defined governance requirements.
Platform questions
Conventional scanners primarily match known patterns. Vallum combines that evidence with autonomous testing that can reason across application behavior, identities, authorization boundaries, APIs, and exposed infrastructure. It then carries validated risk through remediation and verification instead of stopping at detection.
Vallum maintains a connected record of findings, assessment context, remediation activity, pull requests, and verification outcomes. This can support security questionnaires and internal review. Where a customer requires a signed report from an accredited assessor, that formal engagement remains necessary.
Access follows the assessment surface and is explicitly authorized. Applications and domains require verified control before active testing. Repository analysis uses scoped, short-lived installation credentials. Public external-surface checks use public records and an ordinary homepage request without privileged access.
Vallum provides the evidence, priority context, and remediation path. Engineering retains approval over code changes, while the credential owner remains responsible for revocation and rotation. The product is designed to make those responsibilities explicit rather than hide them behind automation.
No. The scanner's critical classification is preserved. Vallum AI prioritizes critical findings, explains impact, estimates fixability, and proposes remediation steps; it cannot downgrade the underlying severity or expand assessment to lower-severity findings.
No. Active assessment requires verified control of the target. Repository authorization comes from the GitHub installation, and domain ownership is verified before privileged testing. This boundary is enforced and recorded.
It reviews public certificate and DNS data plus the response headers and cookies returned by a standard homepage request. It does not attempt authentication, exploit application behavior, or send unusual traffic. The result is therefore immediate and non-invasive, but intentionally narrower than an authorized assessment.
Vallum does not use raw rule count as a proxy for security value. Coverage is evaluated through the monitored assets, evidence collected, critical findings requiring action, and whether remediation was subsequently verified.
Authorize an application, API, domain, or repository. Start with a scoped, evidence-led view of the risk that requires action.