See what's actually exposed.
One scan. Real findings. No account needed.
Only scan sites you own or are authorized to test. Reports are stored and accessible via link — see how we handle scan data on the Trust page.
See what a PatchVex report looks like
Example scan report · illustrative findings, not a live result
What's included
Two tools. One mission.
Instant security checks for any web application.
Paste a URL, get a full report in seconds.
- TLS certificate & protocol version
- Security headers & CSP validation
- Exposed OpenAI, Anthropic & cloud keys
- Cookie security flags
Rank vulnerabilities by exploitation, not severity.
5,000 findings. 19 actually exploited right now. VulnPilot tells you which.
- CISA KEV + FIRST EPSS + CVSS + severity composite scoring
- SOC 2 CC7.1 & ISO 27001 evidence
- Local-only — zero cloud upload
- Nessus CSV import
SSRF-safe scanning
Every scan target is validated against private/internal network ranges before we ever connect. Your infrastructure is never a target.
No scan data leaves your perimeter
VulnPilot runs entirely on your machine. Findings, credentials, and scan history are never transmitted to PatchVex or any third party.
Audit-ready evidence
VulnPilot tracks every exception, SLA, and remediation with a full history. One export covers an entire audit cycle.
Open source at the core
VulnPilot is MIT-licensed and auditable. No black-box scoring — see exactly how every finding is prioritized.
Ready to check your next deploy?
Free instant scan — no account, no credit card. Evaluating PatchVex for your team or org instead?