Autonomous continuous pentesting

Vallum continuously tests your applications, APIs, external attack surface, and source code. AI validates the risk that matters, coordinates the right remediation, and re-tests every resolved issue.

Authorized testing · Evidence-led findings · Human-controlled remediation

Vallum security command center showing connected-asset coverage, prioritized critical findings, assessment activity, and integration status.
Vallum’s unified security workspace for monitoring risk across connected assets.

Evaluate your external posture without creating an account

Free, no account. Public records and a normal page request — nothing intrusive.

  • Web applications
  • APIs
  • External attack surface
  • Source code
  • AI-led remediation
  • Continuous verification

AI pentesting for applications and APIs

Test the paths conventional scanners cannot reason about.

Vallum’s testing agents interact with application workflows, authorization boundaries, identities, and APIs. They adapt to what the system returns and follow evidence toward material impact.

The result is not a speculative alert. Each validated attack path carries the request, response, affected boundary, business impact, and remediation context required to act.

A Vallum finding showing a request made as one customer returning another customer's order data, with the plain-language impact and confirmation that it was reproduced.

Vallum operating model

Map continuously. Test autonomously. Defend with precision.

Vallum connects autonomous testing, evidence, remediation, and verification across the full application environment—without removing human approval from consequential changes.

Workflow simulation

Validated application attack path

Authorized estate

  1. Application estate

    Active

  2. AI pentesting

    Attack paths + scanners

  3. Vallum AI

    Risk validation

  4. Defensive action

    Controls + safe fixes

  5. Verification

    Outcome evidence

Explicit authorizationEvidence-led validationHuman-controlled changesContinuous re-testing

Continuous defense

Every validated risk moves into a defined response.

Vallum AI translates attack evidence into the smallest effective defensive action—from credential rotation and policy changes to configuration updates and reviewable code fixes.

Automation prepares the path; your controls authorize the change. Vallum then re-tests the original exposure and records the outcome.

Defense plan · VLM-1042

Unauthorized access to customer records

Critical
  1. 01

    Contain

    Revoke exposed access

    Provider-specific credential rotation and access-review steps

    Ready
  2. 02

    Correct

    Remove the root cause

    Configuration, policy, or code-level control selected from evidence

    Planned
  3. 03

    Deploy

    Apply through existing controls

    Human approval, change management, and rollback remain in place

    Approval
  4. 04

    Verify

    Re-test the original path

    Resolution is recorded only when the exposure is no longer reproducible

    Pending

Closure requires successful verification

Evidence retained end to end

External posture assessment

Immediate visibility into your public attack surface.

Run a non-invasive assessment using public DNS, certificate data, and a standard request to your homepage. No account, deployment agent, or privileged access is required.

Results are intentionally concise. If Vallum finds no actionable exposure, the assessment returns a clear result rather than a list of low-value observations.

A Vallum finding showing a subdomain of acme.com pointing at an Amazon S3 name that no longer exists, confirmed by two independent resolvers, with an explanation of what an attacker could do with it.
  • Subdomains someone else could claim

    A hostname still pointing at a service that was cancelled or deleted. Whoever registers that name next controls what your subdomain shows.

  • Email anyone can forge as you

    Not just a missing DMARC record — the ones that exist and are being ignored. Two SPF records cancel each other out; a record ending in +all authorises the entire internet.

  • Certificates about to lapse

    Expiry, trust, and what your visitors will see when it goes. This is reliably the line people act on the same afternoon.

  • Session cookies a script can read

    Cookies carrying a login with no HttpOnly, or no Secure. Not your analytics cookies — those are supposed to be readable.

  • Hostnames you may have forgotten

    Every certificate ever issued for your domain is published publicly. Staging, admin, and legacy names show up in that list, and it is where an attacker starts.

  • Mail servers that no longer exist

    An MX record pointing at a host that does not resolve. Not hypothetical — mail people send you is failing right now.

Product roadmap

A unified control plane, delivered in defined stages.

Application, API, and external-surface testing establish the foundation. Cloud posture, runtime defense, and broader attack simulation will be introduced as separately governed modules when they are production-ready.

  • AWS
  • Google Cloud
  • Azure
  • Kubernetes

Platform principles

Security operations designed for engineering execution.

  • Continuous control, not periodic evidence

    Scheduled testing keeps applications, APIs, external assets, and repositories under review between formal assessments and major releases.

  • Evidence retained with every finding

    Scanner evidence, affected locations, AI assessment, and remediation state remain connected throughout the finding lifecycle.

  • Prioritization bounded by policy

    Vallum AI focuses on a controlled set of critical findings, with secret exposures prioritized and scanner severity preserved.

  • Remediation built into delivery

    Each validated issue receives an actionable remediation path. Where a safe code change can be prepared, Vallum opens it as a pull request for review.

  • Durable security decisions

    Finding state and remediation history remain attached across scans, providing continuity for engineering and assurance teams.

  • Explicit operational limits

    Every assessment runs within defined time and cost boundaries, making consumption predictable and enforceable.

Signal governance

Signal quality is a security control.

Security teams do not need another measure of scanner activity. They need a defensible view of material exposure, its supporting evidence, and the next action required from engineering.

Raw scanner workflow

  1. Measures coverage by the number of rules executed.
  2. Elevates configuration observations without business context.
  3. Creates separate records for closely related symptoms.
  4. Transfers prioritization and ownership to the customer.

Vallum

  1. Measures coverage by actionable risk and verified outcomes.
  2. Preserves technical severity while adding decision context.
  3. Correlates evidence into a durable finding lifecycle.
  4. Provides prioritization and a defined remediation path.

Coverage remains broad. Attention remains deliberately constrained to findings that warrant an engineering or risk decision.

Security architecture

Controls designed for enterprise review.

Vallum operates inside sensitive engineering workflows. Its trust model is built around scoped access, isolation, data minimization, and verifiable control boundaries.

  • Ephemeral assessment environments

    Repository analysis runs against an isolated working copy that is destroyed when processing completes. Vallum retains findings, not a persistent source-code mirror.

  • Explicit authorization boundaries

    Domain and repository assessments require verified control. Authorization scope and timing are recorded before active testing begins.

  • Secret values are not retained

    Detected credentials are represented by one-way fingerprints for correlation. The original secret value is not persisted in Vallum's findings store.

  • Database-enforced tenant isolation

    Organization boundaries are enforced through database policies in addition to application authorization, reducing reliance on a single control layer.

  • Traceable remediation history

    Findings, decisions, pull requests, and verification outcomes form a durable record that supports internal review and customer assurance workflows.

  • Enforced resource governance

    Assessment duration and spend limits are explicit. Work that would exceed an approved boundary is refused rather than allowed to continue silently.

Pricing

Predictable security operations across the delivery lifecycle.

Vallum provides continuous visibility between point-in-time assessments, with plans aligned to monitored scope and operational usage rather than report volume.

Formal penetration tests and compliance assessments remain distinct controls. Vallum complements them by keeping findings, remediation, and verification current throughout the year.

Starter

€149/ month

For focused engineering teams establishing continuous security coverage.

  • Application and API coverage
  • External attack-surface monitoring
  • Repository security monitoring
  • Guided remediation workflows
  • Finding and verification history

Growth

Most popular

€499/ month

For growing organizations formalizing security and customer assurance workflows.

  • Expanded application and API estate
  • AI-led attack-path testing
  • Defined spend and execution limits
  • Assurance-ready evidence history
  • Priority support

Enterprise

Talk to us

For complex application estates with defined governance requirements.

  • Application, API, cloud, and code estate
  • Custom assessment policies
  • Single sign-on and role mapping
  • Data residency and retention terms
  • Named contact and response times

Platform questions

Scope, control, and operating boundaries.

How does Vallum differ from a conventional scanner?

Conventional scanners primarily match known patterns. Vallum combines that evidence with autonomous testing that can reason across application behavior, identities, authorization boundaries, APIs, and exposed infrastructure. It then carries validated risk through remediation and verification instead of stopping at detection.

Can Vallum support customer assurance and audit workflows?

Vallum maintains a connected record of findings, assessment context, remediation activity, pull requests, and verification outcomes. This can support security questionnaires and internal review. Where a customer requires a signed report from an accredited assessor, that formal engagement remains necessary.

What access does Vallum require?

Access follows the assessment surface and is explicitly authorized. Applications and domains require verified control before active testing. Repository analysis uses scoped, short-lived installation credentials. Public external-surface checks use public records and an ordinary homepage request without privileged access.

Who owns the workflow after Vallum identifies an issue?

Vallum provides the evidence, priority context, and remediation path. Engineering retains approval over code changes, while the credential owner remains responsible for revocation and rotation. The product is designed to make those responsibilities explicit rather than hide them behind automation.

Does AI determine technical severity?

No. The scanner's critical classification is preserved. Vallum AI prioritizes critical findings, explains impact, estimates fixability, and proposes remediation steps; it cannot downgrade the underlying severity or expand assessment to lower-severity findings.

Can Vallum assess assets we do not own?

No. Active assessment requires verified control of the target. Repository authorization comes from the GitHub installation, and domain ownership is verified before privileged testing. This boundary is enforced and recorded.

What does the public domain check evaluate?

It reviews public certificate and DNS data plus the response headers and cookies returned by a standard homepage request. It does not attempt authentication, exploit application behavior, or send unusual traffic. The result is therefore immediate and non-invasive, but intentionally narrower than an authorized assessment.

How does Vallum measure coverage?

Vallum does not use raw rule count as a proxy for security value. Coverage is evaluated through the monitored assets, evidence collected, critical findings requiring action, and whether remediation was subsequently verified.

Establish a continuous path from detection to verified remediation.

Authorize an application, API, domain, or repository. Start with a scoped, evidence-led view of the risk that requires action.