CONTINUOUS EXPOSURE MANAGEMENT · DAST · SBOM
Security testing for modern web, API, and software supply chains.
See what is exposed. Know what is in your software. Operate evidence your auditor accepts. One platform for external and internal DAST, SBOM, SCA, and a CI/CD gate your pipeline already understands.
Capabilities most scanners do not have
Visualize real attack paths across your applications and infrastructure.
Correlate vulnerabilities into real attacker paths instead of isolated findings.
Secure internal validation without inbound VPN exposure.
Outbound-only agent over mTLS for private and internal environment scanning.
Continuously validate what ships inside your software.
SBOM, SCA, OSV and compliance-ready evidence for audit and governance workflows.
Out-of-band attack validation without external data exposure.
Keep testing workflows and validation data fully inside the WASViking platform.
Platform Capabilities
One platform for external and internal testing, software supply chain, and audit-ready evidence.
Continuous Exposure Management
Always know your live attack surface across web, API, and internal assets.
Modern API Security
Test REST, GraphQL, SOAP, WebSocket, and JWT flows the way attackers actually probe them.
Edge Threat Radar
Detect scanners, credential abuse, and hostile automation activity in real time.
CI/CD Security Automation
Prevent vulnerable builds from reaching production pipelines.
Actionable Findings & AI Prioritization
Risk-scored findings with operational workflows and deterministic remediation guidance.
Compliance Evidence On Demand
Map findings to PCI DSS, LGPD, GDPR, ISO 27001, and governance workflows ready for audit.
Key Features
The core capabilities of the WASViking platform.
Built for modern security teams that need visibility, automation, and clear answers about what to fix first.
Certificate Monitoring
Continuity & Audit EvidenceContinuous discovery of public TLS certificates with policy-driven expiration alerts and per-subdomain posture evidence.
Threat Intelligence Enrichment
AI-DrivenReal-time threat data integration for deeper risk analysis and smarter decisions.
Internal Asset Coverage
Sentinel AgentMonitor internal assets securely. No open ports, no VPN. Zero-trust by design.
AI-Powered Recommendations
Actionable InsightsAutomated risk classification and mitigation steps using machine learning and expert logic.
What buyers ask in evaluations
Mapped to alternative patterns, not specific products. Validate every row against your shortlist.
| The buyer asks | What other tools do | What WASViking does |
|---|---|---|
| Does it test modern APIs? | REST only, GraphQL / SOAP / WebSocket as separate paid SKUs | One platform, all protocols, single license |
| Can it scan inside my network? | VPN, jump host, or on-prem appliance with inbound ports | Outbound-only mTLS tunnel via Sentinel agent |
| Can I see exploit chains, not just findings? | Not at all in automated DAST | Exploit Path Graph with chokepoint analysis |
| Does it find blind-class vulnerabilities? | Third-party collaborator you cannot operate | Proprietary OAST catcher, kept in-platform |
| Do you give me an SBOM? | A flat CycloneDX dump | Four coordinated layers plus signed Evidence Bundle |
| Will the AI hallucinate findings? | Often, because there is no engine underneath | Engines detect, AI explains, deterministic override |
| Does it speak my auditor's language? | Generic security report | PCI DSS, LGPD, GDPR, BACEN, ISO 27001 from one rule table |
Plans that match how you run AppSec
Pricing is based on your scope: targets, modules, and deployment. Tell us what you need to cover and we will prepare a quote.
Starter
For teams putting their first structured AppSec program in place.
- Up to 5 targets
- Continuous vulnerability scanning
- SSL & certificate visibility
- Software supply chain visibility
- Basic API security scanning
- Security alerts & reporting
- Scheduled security scans
Pro
For teams that need continuous scanning wired into CI/CD.
- Everything in Starter, plus:
- Exploit Path Graph
- Sentinel internal scanning agent (no VPN)
- Authenticated app & API security testing
- Supply Chain Threat Intelligence
- Edge Threat Radar
- Enterprise access controls (SSO) & multi-user collaboration
- CI/CD security automation & AI-driven scheduling
- Slack, Teams & webhook integrations
Business
For companies consolidating DAST, API security, and exposure management.
- Everything in Pro, plus:
- Enterprise access controls (RBAC & granular permissions)
- Compliance mapping (PCI DSS, LGPD, GDPR, ISO 27001, BACEN)
- Signed compliance evidence for audits
- Findings SLA workflow & security orchestration
- Centralized exposure visibility
- Jira & enterprise integrations
- Dedicated customer success manager
- Invoice & PO billing
Enterprise
For organizations with compliance mandates, SSO, and internal network coverage.
- Everything in Business, plus:
- Custom volume and unlimited scanning
- Private and on-premises deployment
- Custom compliance modules and premium SLAs
- Guided onboarding and dedicated support team
Every engagement starts with a guided demo and a sales-assisted evaluation on your own targets.
Compare WASViking® Plans
| Compare Plans | Starter | Pro | Business | Enterprise |
|---|---|---|---|---|
| How you scan it | ||||
| Targets | 5 | 10 | 30 | Custom* |
| Subdomain discovery | 5 | |||
| Scheduled scans | Up to 2 active schedules | Up to 5 active schedules | Up to 20 active schedules | Custom* |
| AI Recommendation | Custom* | |||
| AI Assistant | 100 / month | 600 / month | 5000 / month | Custom* |
| SSL Scan (Certificate) | Custom* | |||
| Sentinel Agent | 1 | 5 | Custom* | |
| Scan report retention | 3 months | 1 year | 1 year | Custom* |
| SSL report/history retention | 3 months | 1 year | 1 year | Custom* |
| How you see it | ||||
| Dashboard | ||||
| Scans overview page | ||||
| Attack surface view | ||||
| Scans Reporting | ||||
| SSL Certificate Reporting | ||||
| Edge Intelligence & Threat Detection (Real-Time Threat Visibility) | ||||
| Edge Threat Radar | ||||
| Edge Threat Radar Data Retention | 15 days | 30 days | Custom* | |
| Edge Threat Radar Targets (Edge Assets) | 1 target | 2 target | Custom* | |
| Integrations & Alerts | ||||
| Email alerts | ||||
| Slack alerts | ||||
| MS Teams alerts | ||||
| API Webhook | ||||
| Payment | ||||
| Credit card payments | ||||
| Payment by invoice | Available | |||
| Support & Services | ||||
| Knowledge center | ||||
| Onboarding support | Optimization | |||
| Dedicated Customer Success | ||||
| Enterprise add-ons & services | Available | All included | ||
| Security | ||||
| Email security code on login | ||||
| Two-factor authentication (2FA) | ||||
| Single sign-on (SSO) | ||||
| Access logs | ||||
| Administration | ||||
| Admin account & user seats | 1 admin, up to 3 users | 2 admins, up to 10 users | 5 admins, up to 50 users | Custom* |
| Optional Platform Modules | ||||
| Mobile Security Assessment | Add-on | Add-on | Add-on | Add-on |
| AI Guardian | Add-on | Add-on | Add-on | |
| Exposure Intelligence | Add-on | Add-on | Add-on | |
| Exposure Reasoning Engine | Add-on | Add-on | Add-on | |
Not available in this plan | Included | Add-on Optional module, licensed separately | Contact us for Business and Enterprise pricing
*Displayed limits are standard allocations. Pro plans allow contractual adjustments to features and capacity. Business and Enterprise plans are fully customized and governed by the commercial agreement. Optional platform modules are not included in any plan; they are quoted based on scope and enabled for your organization by our team.
Pricing questions, answered
Why WASViking?
Continuous security for your digital assets, with clear actions you can take today.
AI Recommendations
Clear security insights with the context your team needs to act on them.
Continuous Scanning
Automated, real-time scanning for vulnerabilities, SSL, and misconfigurations.
Conversational AI
Ask questions about your environment in plain language and get direct, contextual answers.
Talk to our team
We protect companies in the US and Brazil from web and API threats. Tell us what you want to secure and you will hear from us within one business day.
Talk to our team
Tell us about your environment. You will hear from us within one business day.