Skip to content
VITI Security

Vexta · tier

Vexta Enterprise: vulnerability scanning that ships findings, not noise.

Everything in Pro, plus unlimited scans, unlimited seats with role-based access (priced per seat, minimum 5), single sign-on (OIDC), compliance evidence packs, attack-path and reachability analysis, Active Directory and cloud audits, a named consultant and a 4-hour response SLA.

Vexta

Vexta Enterprise

Everything in Pro, plus unlimited scans, unlimited seats with role-based access (priced per seat, minimum 5), single sign-on (OIDC), compliance evidence packs, attack-path and reachability analysis, Active Directory and cloud audits, a named consultant and a 4-hour response SLA.

$129/ seat / month

Minimum 5 seats. Monthly, quarterly or yearly billing.

Refunds follow our Terms: up to 80% within 30 days of your first purchase, then pro-rated for unused time on quarterly and yearly plans. Monthly plans are not refunded after 30 days.

Get started →

Why this tier

What you get with Vexta.

No agents to install

A single binary on a machine you control. Point it at a target, get results.

Verified findings

Proof-of-exploitation checks on every plan mark each finding proven, refuted or unproven.

Self-hosted

Runs on your own hardware or a cloud VM (AWS, GCP, Azure or similar). Results stay there unless you turn on an integration that sends them out.

CI/CD output

Pro and Enterprise: the scan-ci command writes SARIF, JUnit and JSON and fails builds on the severities you choose.

Reports

Pro and Enterprise: HTML and PDF reports with an executive summary and remediation steps. Enterprise adds compliance evidence packs.

OWASP Top 10 and CVE checks

Web vulnerability checks for OWASP Top 10 classes on every plan; CVE matching against a local NVD, EPSS and KEV mirror, and dependency (SCA) checks, on Pro and Enterprise.

Everything in Enterprise.

The short list above is the headline. Open the full list for every check and capability this plan unlocks in the Vexta binary.

Show full feature list (74 features)

Included on every plan

  • IncludedPassive OSINT recon and subdomain enumeration across 40+ public sources
  • IncludedAsset intelligence: host, IP, open ports, technology stack and TLS certificate summary
  • IncludedCore web vulnerability checks for OWASP Top 10 classes (SQL injection, reflected XSS, command injection, file inclusion, CRLF, open redirect, CORS)
  • Included10,000+ bundled vulnerability templates in every binary (community templates from ProjectDiscovery’s nuclei-templates)
  • IncludedJSON scan output and a native Word (DOCX) report on every scan
  • IncludedBuilt-in dashboard with real-time updates and a light or dark theme
  • IncludedWAF detection and adaptive rate limiting
  • IncludedPlain-language explanation, impact and CWE/OWASP references on every finding

Recon and discovery

  • IncludedContent and URL discovery: Wayback history, directory and content fuzzing, exposed-file checks and injection-class bucketing
  • IncludedNetwork port and service scanning (SYN and ACK scans, service detection)
  • IncludedArchive URL aggregation (CommonCrawl, OTX, URLScan)
  • IncludedPer-host screenshots and active OS fingerprinting
  • IncludedCross-scan asset diffing (new, changed and removed assets)
  • IncludedSubdomain-takeover and lookalike-domain detection
  • IncludedCloud storage bucket enumeration (S3, GCS, Azure)
  • IncludedLeaked-secret and credential-exposure checks: GitHub and GitLab dorking, exposed .git history, breach lookups
  • IncludedWeb-app cataloguing and origin-server discovery
  • IncludedRelated-infrastructure discovery across an organisation

Vulnerability scanning

  • IncludedSource-code pattern (SAST) checks: SSRF, XXE, weak crypto, SQL concatenation, path traversal and more
  • IncludedCross-site scripting: DOM-based, stored, blind (out-of-band), multi-step and charset-confusion
  • IncludedInjection testing: SSTI, SSRF (including cloud metadata), XXE, NoSQL and command injection
  • IncludedGraphQL security checks (introspection, batching, auth gaps, DoS)
  • IncludedHTTP request smuggling (CL.TE, TE.CL, multi-header)
  • IncludedRace-condition testing (single-packet, workflow, idempotency)
  • IncludedWeb3 and smart-contract checks, and mobile app (APK/IPA) analysis
  • IncludedRequest-forgery and parameter abuse: CSRF strength, chained CSRF, on-site request forgery, clickjacking, parameter pollution
  • IncludedOther web flaws: file-upload polyglots, ViewState tampering, format strings, SOAP and SMTP injection, prototype pollution, risky third-party scripts, denial-of-service
  • IncludedAdvanced injection detection (timing and boolean oracles, second-order injection, encoding variants)
  • IncludedLogin and authentication flaws: username enumeration, missing lockout, multi-step login and step-skipping
  • IncludedSession and cookie security: fixation, weak entropy, predictable tokens, padding oracles, scope and cross-response differences
  • IncludedBroken access-control differential checks (method, header, sitemap, parameter-trust and Referer-based checks)
  • IncludedSSO, OAuth and OIDC flaws and account-takeover chains (redirect, state, PKCE, password-reset host injection)
  • IncludedNetwork service checks: FTP bounce, ident leak, SNMP write, RPC and SMB null-session enumeration, idle scan, WebDAV
  • IncludedAdditional checks: TLS certificate (null-byte CN/SAN, wildcard scope), sitemap and framework discovery, Microsoft 365 configuration
  • IncludedAuthenticated (logged-in) and headless-browser scanning

Offensive and infrastructure testing

  • IncludedNetwork service exploitation (SSH, SMB, RDP, LDAP, SNMP)
  • IncludedIntercepting proxy: live feed, request replay and edit, per-host TLS and scope filtering
  • IncludedBroken access control / BOLA differential testing (IDOR, session-matrix auth diff)
  • IncludedDedicated SSO, SAML and OIDC misconfiguration scanning
  • IncludedCredential engine: tests discovered credentials against live services
  • IncludedActive Directory auditing and red-team modules (BloodHound graph, Kerberoasting, NTLM relay, DCSync, PsExec/WinRM/WMI, Zerologon, PetitPotam)
  • IncludedCloud infrastructure auditing (AWS, Azure, GCP)
  • IncludedOffline password cracking (hashcat)
  • IncludedWi-Fi assessment agent
  • IncludedCommand-and-control egress testing
  • IncludedPhishing simulation toolchain for authorised campaigns
  • IncludedRed-team engagement reporting
  • IncludedDatabase capability and out-of-band probes (MSSQL, Oracle, OLE DB, stored-procedure and SMTP-collaborator checks)

Verification and intelligence

  • IncludedProof-of-exploitation verification on every finding (proven, refuted or unproven)
  • IncludedOut-of-band (OOB) callbacks for blind SSRF, XXE and XSS
  • IncludedCVE matching with a local NVD mirror plus EPSS and KEV enrichment, and dependency (SCA) checks
  • IncludedFull confidence scoring (severity, proof, reachability, EPSS, KEV)
  • IncludedInteractive attack-graph view of findings
  • IncludedFix verification and baseline scanning (only new issues since a known-good run)
  • IncludedApplication security posture management: asset criticality, reachability and SLA banding
  • IncludedAttack-path chaining and exploit-chain analysis

Reporting

  • IncludedHTML, PDF and Google Docs reports with executive summary and remediation
  • IncludedSARIF (GitHub and GitLab code scanning) and JUnit output
  • IncludedCross-scan diff reports, reproduction packages and one-click export to HackerOne and Bugcrowd

CI/CD and integrations

  • IncludedCI/CD pipeline command that fails builds on the severities you choose
  • IncludedNotifications: email, Microsoft Teams, Google Chat, Pushover and custom webhooks
  • IncludedScheduled scans and targeted subscans
  • IncludedREST API access, findings query language and endpoint change timeline

Optional AI (your own LLM key)

  • IncludedOptional AI triage, asset insight, report drafting and scan planning, using your own LLM key
  • IncludedAI-assisted configuration and security analysis, using your own LLM key

Team and compliance

  • IncludedCompliance mapping (OWASP, NIST, PCI-DSS, SOC 2), evidence packs and PDF export
  • IncludedTeam access with role-based permissions and an admin audit log

Platform, scale and audit

  • IncludedQuick and standard scan profiles
  • IncludedDeep, bounty-hunt and low-noise scan profiles
  • IncludedMulti-target scanning and higher concurrency (up to 50 threads)
  • IncludedTamper-evident, hash-chained audit trail of every request
  • IncludedUnlimited targets and concurrent jobs, up to 100 threads, and unrestricted API
  • IncludedFinding lifecycle metrics (MTTR, recurrence, SLA breaches)
  • IncludedCustom YAML scan profiles

Compare all plans →

Get started with Vexta Enterprise.

Questions before you buy? Free 30-minute call. Fixed quote in 1 business day for anything custom.