Skip to content
Scana
Authorised testing only. Every target is verified

Security testing your whole team can run, and trust

Run Scana on your own servers. Turn scans into a graded pen-test report: what was found, why it matters, and how to fix it. Verify your targets, invite your team, and test internal systems from your own network.

A–F
Security grade
CVE
Offline catalogue
OWASP
Top 10 mapped
API
OpenAPI pen test

Everything an authorised test needs

From recon to a shareable certificate, with the guardrails that keep testing authorised.

Graded certificates

Every pen test rolls up into a 0–100 score and an A–F grade, with each finding's concern and step-by-step fix. Print or save it as a report.

Verified targets

Add a domain and prove control with a DNS TXT record before scanning. IP addresses and ranges require confirmation that you're authorised to test them.

Offline CVE catalogue

Build a local copy of osv.dev to enrich findings with severity, fixed versions and references. Catalogue searches then run without live lookups.

Weakness reference

The OWASP Top 10 and the CWE classes behind them: clickjacking, missing headers, injection, each with how to prevent it, linked to real CVEs.

API pen testing

Drop in an OpenAPI/Swagger spec or a Swagger link. Scana maps every endpoint and tests it for broken auth, injection, and misconfiguration.

A real toolkit

Recon, scanning, TLS grading, web checks and more. Run one tool or a full suite, each with a step-by-step pathway so you know exactly what you're running.

From install to certificate

Your infrastructure, your team, and targets you are authorised to test.

  1. 1

    Install and set up

    Run Scana with Docker Compose or Helm. Connect your own Clerk application, claim the install, and create your team.

  2. 2

    Add & verify a target

    Register a domain you own and confirm control with a DNS TXT record. Unverified targets can't be scanned.

  3. 3

    Run a test

    Choose a tool, a security check, or an API test from an OpenAPI spec. Higher-risk tools ask you to confirm authorisation before they run.

  4. 4

    Get the certificate

    Read the grade, every finding's fix, and OSV/CWE context, then re-test to prove it's resolved.

Start free, upgrade when you need to

Community covers your first few systems. Team adds every tool, and Enterprise adds managed devices. Every plan runs on your own servers.

Community

Check your websites and servers for common problems, at no cost.

Free with no licence key

  • 3 systems: domains, IP addresses or ranges
  • 5 people in total
  • 100 scans a month
  • Daily, nightly or weekly scheduled scans
  • Safe, non-intrusive checks

Team

Recommended

Every tool, for a small security team.

$99 a month, or $990 a year

$19 a month for each extra seat.

  • 3 admin or operator seats
  • Unlimited viewers
  • 25 systems
  • Unlimited scans, 3 at a time
  • Advanced tools and AI analysis
  • Connect your own Claude and run Autopilot engagements
  • API testing and app analysis
  • The full written report

Enterprise

No limits, for larger teams and the computers they look after.

$249 a month, or $2,490 a year

$25 a month for each extra seat, $2 for each extra device.

  • Everything in Team, with no limits on systems or schedules
  • 5 admin or operator seats
  • 25 managed devices with the Scana Agent
  • An offline licence that needs no renewal checks
  • Priority support

Bring security testing into your own network

Start with Community at no cost. Choose Team for the full toolkit or Enterprise for managed devices.

Authorization-gated Domain-verified targets Audit trail on every action