// SIGN IN TO CONTINUE
Single sign-on required
The documentation is available to signed-in users. Sign in with any provider — it's free.
By scan type
// required vs optionalAPI SCAN
REQUIRED
The base URL of the API.
OPTIONAL
Credentials (bearer, API key, basic, OAuth2, form/SPA login, HMAC) to test behind auth · an OpenAPI/Postman/HAR import to seed discovery · a scan profile and goal · an AI provider key for the AI layer.
WEB SCAN
REQUIRED
The site URL.
OPTIONAL
Login credentials so the built-in browser can sign in and reach the app behind the login · a scan profile to set depth.
NETWORK SCAN
REQUIRED
The targets — IPs, CIDR ranges, or hostnames.
OPTIONAL
Nothing — web services it discovers get API recon automatically.
WI-FI SCAN
REQUIRED
Run NewScan on a machine with Wi-Fi, in range of the networks to assess (the host helper the launcher starts gives it the radio).
OPTIONAL
Your authorized and guest SSIDs plus a minimum encryption standard, so rogue and shadow-IT networks get flagged. Name the site to make it repeatable — your verdicts are remembered per access point, so the next scan there only asks about new ones and reports what changed. Add vantage points to turn it into a guided walk that locates each unknown device, and mark any that sit outside your coverage boundary to catch signal leakage.
SEGMENTATION SCAN
REQUIRED
The segmentation rules you expect to hold and where to test from — the guided setup collects both.
OPTIONAL
A custom port list to probe beyond the default set.
READING YOUR RESULTS
Findings are ranked by one calibrated severity and each carries the evidence and reproduction that proved it. The origin tag shows whether the deterministic layer or the AI layer found it — both validate before recording. Export any run as SARIF, JSON, Markdown, CSV, or HAR from the report menu.
USING THE SANDBOX
The sandbox is a free-form request runner bound to your scan: click any endpoint, finding, or previous probe to pre-fill the request, edit it, and send. It reuses the scan's captured auth and stays scope-locked to the target — and every call you make lands in the probe log so you can replay it later.