Vulnerability Assessment & Pentest

Find the security gaps before someone else does.

Macan continuously scans your public and internal assets, verifies every finding against live CVE data to cut false positives, and turns results into audit-ready reports — without a large in-house security team.

Continuous Scanning24/7 asset monitoring
Accurate & VerifiedLive CVE validation
Audit-Ready ReportsExport in one click
scan-workspace-01
Live
TOTAL FINDINGS
128
CRITICAL
18
HIGH
32
MEDIUM
48
4 targets scanned 0 findings verified
▣   View Full Report
Product

One platform, two security needs.

Automated scanning for day-to-day coverage, and structured pentest workflows for deeper engagements — both in a single dashboard.

Automated scanning

Public assets are scanned directly from our servers; internal networks are scanned through a lightweight on-prem agent that runs quietly behind your firewall — no VPN, no open ports.

Pentest workflows

Manage engagements from initial recon through to final report. Every finding is checked against current CVE data before it ever reaches a client deliverable.

One-run agent

One file, run once. Scanning tools are already bundled inside — your team doesn't install or configure anything by hand.

Multi-workspace

Every team or business unit gets its own workspace — assets, scan history, and reports never mix between them.

How It Works

From install to report, four steps.

01

Download & run the agent

For internal networks, download one file from the dashboard and run it once. No extra install, no manual configuration.

02

Set your targets & schedule

Enter an IP range, domain, or asset list to scan — one-off or on a recurring schedule.

03

Findings get verified automatically

Every finding is matched against current vulnerability data and assigned a confidence level — Critical, High, Medium, or Low — not just a raw list.

04

Download an audit-ready report

PDF reports are generated on demand, structured for internal and external security audits alike.

Pricing

One plan. Every feature.

No asset limits, no features locked behind higher tiers — just pick the billing period that fits.

$500/month
billed monthly
  • Unlimited public & internal asset scanning
  • Unlimited zero-touch on-prem agents
  • Pentest workflow & engagement management
  • Audit-ready PDF reports, on demand
  • Multi-workspace support
Start Subscription
FAQ

Questions you might have.

Automated scans are non-intrusive by design — findings are reasoned from banners, headers, and version data rather than exploit payloads, so there's no risk of crashing a live service.

You download and run one file agent behind your firewall — it reports results back out to your workspace, so you don't need to set up a VPN for us to reach in.

Every finding is checked against current CVE data and assigned a confidence level — confirmed, probable, or unconfirmed — instead of being reported as a flat, unverified list. This cuts down false positives significantly compared to raw scanner output.

Yes — targets can be scanned one-off or on a recurring schedule, and every workspace keeps its own separate asset list, scan history, and reports.

PDF reports are generated on demand and structured for audit use — findings grouped by severity, confidence level and remediation guidance for review or auditors.