Security testing your whole team can run, and trust
Run Scana on your own servers. Turn scans into a graded pen-test report: what was found, why it matters, and how to fix it. Verify your targets, invite your team, and test internal systems from your own network.
- CriticalExposed .git directory
- HighMissing HSTS header
- MediumVerbose error page
Everything an authorised test needs
From recon to a shareable certificate, with the guardrails that keep testing authorised.
Graded certificates
Every pen test rolls up into a 0–100 score and an A–F grade, with each finding's concern and step-by-step fix. Print or save it as a report.
Verified targets
Add a domain and prove control with a DNS TXT record before scanning. IP addresses and ranges require confirmation that you're authorised to test them.
TXT scana-verify=a3f9c1…Offline CVE catalogue
Build a local copy of osv.dev to enrich findings with severity, fixed versions and references. Catalogue searches then run without live lookups.
Weakness reference
The OWASP Top 10 and the CWE classes behind them: clickjacking, missing headers, injection, each with how to prevent it, linked to real CVEs.
Set security headers and disable verbose errors in production.
API pen testing
Drop in an OpenAPI/Swagger spec or a Swagger link. Scana maps every endpoint and tests it for broken auth, injection, and misconfiguration.
A real toolkit
Recon, scanning, TLS grading, web checks and more. Run one tool or a full suite, each with a step-by-step pathway so you know exactly what you're running.
- 1
- 2
- 3
- 4
Guided, one decision at a time.
From install to certificate
Your infrastructure, your team, and targets you are authorised to test.
- 1
Install and set up
Run Scana with Docker Compose or Helm. Connect your own Clerk application, claim the install, and create your team.
- 2
Add & verify a target
Register a domain you own and confirm control with a DNS TXT record. Unverified targets can't be scanned.
- 3
Run a test
Choose a tool, a security check, or an API test from an OpenAPI spec. Higher-risk tools ask you to confirm authorisation before they run.
- 4
Get the certificate
Read the grade, every finding's fix, and OSV/CWE context, then re-test to prove it's resolved.
Start free, upgrade when you need to
Community covers your first few systems. Team adds every tool, and Enterprise adds managed devices. Every plan runs on your own servers.
Community
Check your websites and servers for common problems, at no cost.
Free with no licence key
- 3 systems: domains, IP addresses or ranges
- 5 people in total
- 100 scans a month
- Daily, nightly or weekly scheduled scans
- Safe, non-intrusive checks
Team
RecommendedEvery tool, for a small security team.
$99 a month, or $990 a year
$19 a month for each extra seat.
- 3 admin or operator seats
- Unlimited viewers
- 25 systems
- Unlimited scans, 3 at a time
- Advanced tools and AI analysis
- Connect your own Claude and run Autopilot engagements
- API testing and app analysis
- The full written report
Enterprise
No limits, for larger teams and the computers they look after.
$249 a month, or $2,490 a year
$25 a month for each extra seat, $2 for each extra device.
- Everything in Team, with no limits on systems or schedules
- 5 admin or operator seats
- 25 managed devices with the Scana Agent
- An offline licence that needs no renewal checks
- Priority support
Bring security testing into your own network
Start with Community at no cost. Choose Team for the full toolkit or Enterprise for managed devices.