On-Demand, Live, Non-Cached

Live, on-demand
web vulnerability & privacy scanning.

OnScanner is a web vulnerability, security and privacy scanner: a stack of specialist engines runs in parallel against every target you own, unauthenticated or authenticated, finding vulnerabilities and the trackers watching your visitors. Live results, never cached, delivered as a structured report and an API call. The scan itself never calls an LLM; optional AI Findings analyze the results only when you turn them on.

Live, Non-Cached DataDeterministic CoreOWASP Top 10 Coverage
Trusted by
BioMDRespoCareThinkOfThemPictogeneProbalythicHelixCap

Detection That Checklist Tools Miss

A stack of deterministic scanning engines running in parallel, across unauthenticated and authenticated scans. Broader coverage than checklist tools, with optional AI Findings on top.

AI Findings

Turn on AI analysis in the scan options and OnScanner writes an executive summary, ranks the top risks, explains and gives remediation for every finding, and can produce a compliance report (SOC 2, ISO 27001, GDPR, PCI-DSS, HIPAA). Optional and opt-in; it runs on the results after the deterministic scan finishes.

Attack-Chain Correlation

AI Findings links related results into real attack paths and maps them to the MITRE ATT&CK kill chain, so you see how a small signal becomes a breach instead of just reading a list of issues.

Zero-Day Heuristics

Behavioral and heuristic checks flag unknown vulnerabilities before a CVE exists. Our engines look at what a response means, not just whether it matched a signature.

Attack Surface Intelligence

Host discovery, domain & subdomain enumeration, subdomain takeover detection, forward/reverse DNS, ASN mapping, and SSL/TLS certificate, protocol, and cipher analysis.

Vulnerability Detection

CPE/CVE mapping, OWASP Top 10 and API security checks, safe active exploitation probes, zero-day identification, vulnerability chaining, and WAF & shared-infrastructure detection.

Privacy & Tracker Analysis

Third-party tracker detection across 40+ categories, cookie auditing, canvas & font fingerprinting, session recorder identification, consent/CMP checks, and privacy scoring.

Technology Fingerprinting

Product, vendor, and version detection with CPE correlation, end-of-life tracking, confidence scoring, and CNAME & favicon-hash matching.

Email Security

DMARC, DKIM, and SPF validation to protect your domain from spoofing, phishing, and deliverability issues.

API, MCP & Reporting

Full REST API plus an MCP server for AI agents (Claude, Cursor). Python & JavaScript clients, JSON/PDF export, and embeddable security badges.

How it works

Two layers.
One scan.

At the bottom, live scanning engines (security, privacy, CVE, DNS, tech fingerprinting, WAF, email, infrastructure). Deterministic. Always on. They run end-to-end without a single LLM call and give you a complete report.

On top, optional AI Findings. You turn on AI analysis and AI compliance in the scan options before you start a scan, and once the deterministic scan finishes, AI reads the results to write an executive summary, prioritized risks, per-finding remediation, attack chains, a MITRE ATT&CK kill chain, and a multi-framework compliance assessment. It runs on the findings only when you opt in, so the scan itself stays deterministic.

AI Findings (optional)SummarizeExplainCorrelateComplyCore Scanning EnginesSECPRIVCVEDNSTECHWAFMAILINFRAEngines run in parallel on every scan

From Domain to Full Report in Minutes

No agents to install. No firewall rules to change. Enter a target. Our engines scan in parallel, deliver a structured report, and optional AI Findings summarize and prioritize what matters.

1

Add Your Target

Enter a domain, subdomain, or IP address. OnScanner maps the attack surface automatically including DNS, subdomains, SSL certificates, and hosting infrastructure.

2

Choose Your Scan

Pick security, privacy, or a full comprehensive scan, unauthenticated or authenticated. Specialist scanners run in parallel and produce a structured report. Optionally turn on AI Findings to summarize, prioritize, and remediate.

3

Review & Export

Get a detailed report with severity ratings, risk scores, and remediation guidance. Export as PDF, or pull data via the REST API.

4

Monitor Continuously

Schedule daily, weekly, or monthly re-scans. Track changes over time and get alerted when new risks appear on your targets.

For AI agents

Run OnScanner from your AI agent.

Connect Claude, Cursor, or any MCP-compatible client to the OnScanner MCP server. Your agent can start scans, poll status, and read structured findings, authenticated with your API key.

  • Streamable HTTP at mcp.onscanner.com/mcp
  • Works with Claude Code, Claude Desktop, Cursor, VS Code, and the Anthropic API
  • Same API key, same authorization rules, scan only what you own
~/project
claude mcp add onscanner \
  --transport http https://mcp.onscanner.com/mcp \
  --header "ONSCANNER-KEY: <your-key>"

# then, in your agent:
"Scan example.com using OnScanner and summarize the findings."
What customers say

Byte Optimizer's manual pentest team found complex logic flaws that other vendors missed. Their reporting is technically precise and easy for our devs to act on.

SR
Sabibur Rahman
CTO, HealthTech

Meeting HIPAA and ISO requirements is complex. Their PPA and CAP analysis gave us a clear roadmap from day one. It turned a stressful audit into a manageable checklist.

AP
Andrey Pavlov
CTO, Diagnostics SaaS

By combining OnScanner with manual pentesting, we identified and fixed a critical vulnerability that had been present for months.

MK
Mike K.
Head of IT, E-commerce

Simple, Transparent Pricing

Start free. Scale as you grow. No hidden fees.

Starter
Free

Flexible pay-as-you-go scanning

  • Includes 5 sign-in bonus free scan credits
  • Includes 2 monthly free scan credits
  • Pay-as-you-go: $10/credit
  • All scan types (Security, Privacy and Full)
  • All scan modes (Quick, Advanced and Deep)
  • Regular queue
  • Upto 10 subdomains in a single scan
  • Unlimited active exploit checks
  • Unlimited targets and scans
  • Unlimited scheduled scans and monitoring
  • Unlimited PDF reports
  • REST API & MCP access
  • Email support
Get Started Free
Enterprise
Custom

Scale security across your organization

  • Minimum 50 scans credits/month
  • Pay-as-you-go beyond credits ($5/credit)
  • Dedicated account manager
  • All scan types (Security, Privacy and Full)
  • All scan modes (Quick, Advanced and Deep)
  • Highest priority queue
  • Upto 10 subdomains in a single scan
  • Unlimited active exploit checks
  • Unlimited team members
  • Unlimited targets and scans
  • Unlimited scheduled scans and monitoring
  • Unlimited PDF reports
  • REST API & MCP access
  • Priority Support
Contact Sales

Frequently Asked Questions

Ready to Secure Your Web Applications?

Start a conversation with our security team. Confidentiality guaranteed.