CONTINUOUS EXPOSURE MANAGEMENT · DAST · SBOM

Security testing for modern web, API, and software supply chains.

See what is exposed. Know what is in your software. Operate evidence your auditor accepts. One platform for external and internal DAST, SBOM, SCA, and a CI/CD gate your pipeline already understands.

PROTOCOL COVERAGE
REST · OpenAPI · GraphQL · SOAP/WSDL · WebSocket · JWT
Product supports compliance with
GDPR
LGPD
PCI DSS v4.0
ISO 27001
BACEN 4893 & 4658
WASViking is working toward
SOC 2 Type I
ISO 27001 Certification
Visit Trust Center
Trusted by security teams at
What sets WASViking® apart

Capabilities most scanners do not have

Exploit Path Graph

Visualize real attack paths across your applications and infrastructure.

Correlate vulnerabilities into real attacker paths instead of isolated findings.

Sentinel Internal Scanning

Secure internal validation without inbound VPN exposure.

Outbound-only agent over mTLS for private and internal environment scanning.

Software Supply Chain Intelligence

Continuously validate what ships inside your software.

SBOM, SCA, OSV and compliance-ready evidence for audit and governance workflows.

In-Platform OAST Validation

Out-of-band attack validation without external data exposure.

Keep testing workflows and validation data fully inside the WASViking platform.

Platform Capabilities

One platform for external and internal testing, software supply chain, and audit-ready evidence.

Continuous Exposure Management

Always know your live attack surface across web, API, and internal assets.

Modern API Security

Test REST, GraphQL, SOAP, WebSocket, and JWT flows the way attackers actually probe them.

Edge Threat Radar

Detect scanners, credential abuse, and hostile automation activity in real time.

CI/CD Security Automation

Prevent vulnerable builds from reaching production pipelines.

Actionable Findings & AI Prioritization

Risk-scored findings with operational workflows and deterministic remediation guidance.

Compliance Evidence On Demand

Map findings to PCI DSS, LGPD, GDPR, ISO 27001, and governance workflows ready for audit.

Key Features

The core capabilities of the WASViking platform.

Built for modern security teams that need visibility, automation, and clear answers about what to fix first.

Certificate Monitoring
Continuity & Audit Evidence

Continuous discovery of public TLS certificates with policy-driven expiration alerts and per-subdomain posture evidence.

Threat Intelligence Enrichment
AI-Driven

Real-time threat data integration for deeper risk analysis and smarter decisions.

Internal Asset Coverage
Sentinel Agent

Monitor internal assets securely. No open ports, no VPN. Zero-trust by design.

AI-Powered Recommendations
Actionable Insights

Automated risk classification and mitigation steps using machine learning and expert logic.

What buyers ask in evaluations

Mapped to alternative patterns, not specific products. Validate every row against your shortlist.

The buyer asks What other tools do What WASViking does
Does it test modern APIs?REST only, GraphQL / SOAP / WebSocket as separate paid SKUsOne platform, all protocols, single license
Can it scan inside my network?VPN, jump host, or on-prem appliance with inbound portsOutbound-only mTLS tunnel via Sentinel agent
Can I see exploit chains, not just findings?Not at all in automated DASTExploit Path Graph with chokepoint analysis
Does it find blind-class vulnerabilities?Third-party collaborator you cannot operateProprietary OAST catcher, kept in-platform
Do you give me an SBOM?A flat CycloneDX dumpFour coordinated layers plus signed Evidence Bundle
Will the AI hallucinate findings?Often, because there is no engine underneathEngines detect, AI explains, deterministic override
Does it speak my auditor's language?Generic security reportPCI DSS, LGPD, GDPR, BACEN, ISO 27001 from one rule table

Plans that match how you run AppSec

Pricing is based on your scope: targets, modules, and deployment. Tell us what you need to cover and we will prepare a quote.

Starter

For teams putting their first structured AppSec program in place.

  • Up to 5 targets
  • Continuous vulnerability scanning
  • SSL & certificate visibility
  • Software supply chain visibility
  • Basic API security scanning
  • Security alerts & reporting
  • Scheduled security scans
Additional capacity is available as needed.
Request a Quote View included limits

Business

For companies consolidating DAST, API security, and exposure management.

  • Everything in Pro, plus:
  • Enterprise access controls (RBAC & granular permissions)
  • Compliance mapping (PCI DSS, LGPD, GDPR, ISO 27001, BACEN)
  • Signed compliance evidence for audits
  • Findings SLA workflow & security orchestration
  • Centralized exposure visibility
  • Jira & enterprise integrations
  • Dedicated customer success manager
  • Invoice & PO billing
Request a Quote View included limits

Enterprise

For organizations with compliance mandates, SSO, and internal network coverage.

  • Everything in Business, plus:
  • Custom volume and unlimited scanning
  • Private and on-premises deployment
  • Custom compliance modules and premium SLAs
  • Guided onboarding and dedicated support team
Get a Demo View included limits

Every engagement starts with a guided demo and a sales-assisted evaluation on your own targets.

Compare WASViking® Plans

Compare Plans Starter Pro Business Enterprise
How you scan it
Targets 5 10 30 Custom*
Subdomain discovery 5
Scheduled scans Up to 2 active schedules Up to 5 active schedules Up to 20 active schedules Custom*
AI Recommendation Custom*
AI Assistant 100 / month 600 / month 5000 / month Custom*
SSL Scan (Certificate) Custom*
Sentinel Agent 1 5 Custom*
Scan report retention 3 months 1 year 1 year Custom*
SSL report/history retention 3 months 1 year 1 year Custom*
How you see it
Dashboard
Scans overview page
Attack surface view
Scans Reporting
SSL Certificate Reporting
Edge Intelligence & Threat Detection (Real-Time Threat Visibility)
Edge Threat Radar
Edge Threat Radar Data Retention 15 days 30 days Custom*
Edge Threat Radar Targets (Edge Assets) 1 target 2 target Custom*
Integrations & Alerts
Email alerts
Slack alerts
MS Teams alerts
API Webhook
Payment
Credit card payments
Payment by invoice Available
Support & Services
Knowledge center
Onboarding support Optimization
Dedicated Customer Success
Enterprise add-ons & services Available All included
Security
Email security code on login
Two-factor authentication (2FA)
Single sign-on (SSO)
Access logs
Administration
Admin account & user seats 1 admin, up to 3 users 2 admins, up to 10 users 5 admins, up to 50 users Custom*
Optional Platform Modules
Mobile Security Assessment Add-on Add-on Add-on Add-on
AI Guardian Add-on Add-on Add-on
Exposure Intelligence Add-on Add-on Add-on
Exposure Reasoning Engine Add-on Add-on Add-on

Not available in this plan   |   Included   |   Add-on Optional module, licensed separately   |   Contact us for Business and Enterprise pricing
*Displayed limits are standard allocations. Pro plans allow contractual adjustments to features and capacity. Business and Enterprise plans are fully customized and governed by the commercial agreement. Optional platform modules are not included in any plan; they are quoted based on scope and enabled for your organization by our team.

Pricing questions, answered

Pricing is based on your scope: the number of targets, the modules you activate, and how you deploy. After a short conversation about what you need to cover, our team prepares a quote for your organization. Request a quote and you will hear from us within one business day.

Yes. Every engagement starts with a guided demo of the product, followed by a sales-assisted evaluation where you run real scans against targets you authorize. You review your own findings, not sample data, before any commitment.

A target is a primary asset you scan, such as a website, domain, or application. Subdomains discovered under a target do not consume additional target slots.

Yes. The Sentinel agent, included from the Pro plan, opens an outbound-only connection over mTLS, so you can scan internal applications without a VPN or inbound firewall rules. Private and on-premises deployment options are available on the Enterprise plan.

Findings are mapped to frameworks including PCI DSS, LGPD, GDPR, ISO 27001, and BACEN. Out-of-band testing uses a proprietary OAST collaborator under WASViking control, which keeps interaction data inside the platform rather than a third-party service.

Yes. Most customers buy annual agreements. Card payments are available on all plans, and invoice or purchase-order billing is available from the Business plan. You can expand capacity or add modules at any time through your account team.

Why WASViking?

Continuous security for your digital assets, with clear actions you can take today.

AI Recommendations

Clear security insights with the context your team needs to act on them.

Continuous Scanning

Automated, real-time scanning for vulnerabilities, SSL, and misconfigurations.

Conversational AI

Ask questions about your environment in plain language and get direct, contextual answers.

Talk to our team

We protect companies in the US and Brazil from web and API threats. Tell us what you want to secure and you will hear from us within one business day.

WASViking
6735 Conroy Rd, Orlando, FL 32835
Support, sales, or partnership inquiries: we read every message.

Talk to our team

Tell us about your environment. You will hear from us within one business day.

Your information stays with our sales team. See our Privacy Policy.