Vector

Vector

Vector is an AI-powered vulnerability scanner that runs in two modes. Blackbox points a real attacker agent at your live app with no code access. It discovers the attack surface, tests across categories, and proves each exploit on the running target. Whitebox also reads your source: it builds a call-graph, traces tainted data to dangerous sinks, and then confirms every candidate finding live against your deployed app. Both produce detailed reports with working proof-of-concept exploits, never signature matches or guesses.

Built on Claude's agent capabilities, Vector doesn't rely on signature databases or predefined rules. It reasons about your application the way a human pentester would, adapting its approach based on what it discovers during reconnaissance. It runs a real Chromium browser, injects crypto wallets, creates disposable email accounts, analyzes JavaScript bundles, and can even route through proxy browsers to bypass geo-blocks and CAPTCHAs. Every scan runs in its own isolated worker node with dedicated resources, and the infrastructure autoscales to handle concurrent scans without contention. Each worker gets its own browser instance, its own database connection pool, and its own memory space. There's no cross-contamination between scans. Cookies, sessions, localStorage, and network state from one scan never leak into another.

Vector Demo: Blackbox Scanning

Domain Verification

Before scanning, you must prove ownership of the target domain. Vector uses two verification methods depending on your domain type:

Custom domains: DNS TXT record

Add a TXT record to your domain's DNS with the value vector-verify=<your-token>. Vector queries multiple public resolvers (Cloudflare, Google, Quad9) to check for recently propagated records. This is the default method for any custom domain.

Platform subdomains: .well-known endpoint

If your site is hosted on a shared platform (Railway, Vercel, Netlify, Fly, Render, Cloudflare Pages, etc.), you can't modify DNS. Instead, serve a JSON response at /.well-known/vector-verify containing {"token": "<your-token>"}. Vector checks both root and www variants automatically.

Verification tokens expire after 1 hour. Multiple users can attempt verification simultaneously; first to verify wins exclusive ownership. Shared platform parent domains (e.g. vercel.app itself) are blocked to prevent claiming shared infrastructure.

Scan Modes

Vector runs in two modes. The mode is decided by what you give it: point it at a URL for a Blackbox scan, or connect a repository for a Whitebox scan that reads your source and then proves its findings live against the same running app.

Blackbox (Deep)
$49 · live app only

A real attacker agent against your live app with no code access. Full multi-wave recon and category testing with wallet injection, disposable-email account creation, and bonus deep-dive turns for categories that find vulnerabilities. Every finding is proven on the running target.

Whitebox (Source + Proof)
$150 · repo + live app

Everything in Deep, plus a full source-code audit: call-graph construction, taint tracing to dangerous sinks, secrets and dependency scanning, and business-logic review. Each candidate is then runtime-confirmed against your deployed app, so you get code-level depth with live proof, not a static-analysis report full of maybes. See How Whitebox works below.

Scan Setup

Before a scan starts you tell Vector what it's looking at and how to reach the parts that matter. The more you give it, the sharper the scan, but everything here is optional except proving you own the domain.

Target profile

App type

Web App tests the browser UI and the API behind it; API is headless and only exercises your /api surface with no UI.

Context

A short free-text description of what the app is. It's folded into the recon and category prompts so testing is grounded in what your app actually does.

Subdomains

Vector discovers subdomains from Certificate Transparency logs and lets you choose which to include. The root domain is always in scope.

Known endpoints & out-of-scope paths

List routes you already know exist and the agent probes them first instead of discovering blind. List paths it must never touch (destructive actions, logout, third-party) and anything found there is discarded. (Up to 100 of each.)

Test accounts

To test authenticated flows (auth, IDOR, and privilege escalation), give Vector up to five accounts, each an email or username, a password, and a role (e.g. User, Admin, View Only). Passwordless accounts (magic-link / SSO) are supported with a "no password" toggle. If you don't add any, the scanner creates disposable accounts where signup is available, or tests unauthenticated flows only. Accounts saved on a verified domain are reused automatically on later scans.

Custom headers

Attach custom HTTP headers that ride on every request: a bearer token, an API key, a tenant selector, whatever your app needs. Set them globally or per-subdomain (up to 20). The agent applies them to every HTTP-tool call and browser request throughout the scan.

Rate limit

A maximum-requests-per-second control (10–200, default 50) keeps the scan gentle on production. It is a hard egress limiter, not a hint to the model. Requests are spaced in real time, so a low setting genuinely throttles traffic. 200 removes the cap.

Test-account credentials and custom headers are AES-256-GCM encrypted at rest, and never appear in reports. Secrets are redacted from all output.

How Whitebox Works

Whitebox reads your source and reasons about it the way an auditor would, then proves what it finds against your running app. It is not a static-analysis linter that dumps a thousand maybes. Static analysis predicts; Vector then goes and proves. Every finding lands in one of three tiers: Confirmed (demonstrated live), Reachable (a real call-path reaches the sink), or Reported (flagged, not yet reached). Live proof requires a deployed URL; without one the scan stays static.

The pipeline

01
Sink scan

Fast deterministic detectors sweep every file for dangerous sinks and secrets: SQL/NoSQL injection, command exec, unsafe eval and deserialization, path traversal, XXE, open redirect, weak crypto, "alg:none" JWTs, mass-assignment, prototype pollution, ReDoS, and hardcoded credentials. Sub-second, produces candidates.

02
Code property graph

A tree-sitter call-graph is built across your whole repo, then reachability is walked from each HTTP route → handler → sink (resolving Express mount prefixes and Next.js routing). Only sinks a real request can actually reach survive. Known-vulnerable dependency call-sites are merged in here too.

03
Agentic code comprehension

Claude agents read the reachable code in parallel across nine specialists (access-control / IDOR-BOLA, injection, auth, secrets & dependencies, business-logic, SSRF & redirect, input-validation, XSS, and config exposure). This is where semantic bugs a regex can never see get caught: broken object-level authorization, price/quantity/state-machine flaws, race conditions.

04
Runtime confirm

When you give Vector a live target, it fires a precise probe at the exact route the graph proved (a timing sleep-oracle for deserialization, an identical-body replay for IDOR, an /etc/passwd read for path traversal), and promotes only what actually fires to Confirmed, with the real request/response as proof.

05
Triage & verify gate

A compact per-finding LLM pass demotes low-confidence candidates (it never silently drops them), then a verify gate replays each finding anonymously with no credentials and discards anything the app refutes. Confirmed findings skip both, since they are already proven.

06
Live exploitation & runtime battery

A browser+API agent then exploits surviving candidates against your deployed app, and a runtime hygiene battery checks the live origin for rate-limiting, CORS reflection, weak password policy, verbose errors, and exposed files, with backend-aware adapters for Supabase, Firebase, GraphQL/Hasura, Appwrite, and PocketBase.

07
Finalize

Findings are de-duplicated across every engine, scored (CVSS + severity reconciliation), and paired with code-level remediation before they reach your report.

What you connect

Connect a GitHub, Bitbucket, or GitLab repository (a one-click GitHub App install is available), or upload a .zip of your source. Vector does a shallow, single-branch clone; the access token is injected into the clone URL and never logged, and an uploaded archive is deleted right after extraction. Whitebox scans don't require domain verification. Add a live URL only if you want findings proven against the running app.

Your code stays private

Secrets are redacted from every finding, code snippet, and agent log before anything leaves the worker (Stripe, AWS, Google, GitHub, Slack, SendGrid keys, private keys, JWTs, and high-entropy blobs are all scrubbed). The scan view is owner-only: it returns only your own scan and never exposes internal infrastructure, proxies, tokens, or other users' data. Engineering telemetry (cost, tokens, turns) is stripped at the log boundary and never reaches your report.

Billing & Refunds

No subscriptions or seat licenses. You buy credits and pay a flat fee per scan.

Deep Scan

Blackbox. Full multi-pass pentest of your live app.

$49 per scan

Endpoint, header & subdomain mapping

Site crawling & JS analysis

Auth flow testing

CORS & SSRF probing

Session & privilege escalation

IDOR & token analysis

Whitebox Scan

Source-code audit, proven live on your running app.

$150 per scan

Everything in Deep

Full source-code analysis

Call-graph & taint tracing

Secrets & dependency scanning

Business-logic & auth flaws

Every finding runtime-proven live

Stake ZAUTH for up to 50% off any scan.

When you start a scan, the flat fee is charged from your credit balance upfront. Every transaction is logged as an auditable ledger entry with before/after balance snapshots.

AI-Powered Reconnaissance

Every scan begins with an autonomous recon phase using 30% of the total turn budget. The AI agent crawls your application with a real browser, discovers endpoints, intercepts network traffic to find hidden API calls in SPAs, analyzes JavaScript bundles for hardcoded routes and secrets, enumerates subdomains via Certificate Transparency logs and DNS brute force, and maps authentication flows.

The recon agent produces structured intelligence: technology stack, authentication mechanisms, all discovered endpoints, API patterns, form inventories, security headers, and potential entry points. This data feeds directly into each category scanner so vulnerability testing is targeted, not generic.

Scan Categories

In blackbox mode Vector tests across five vulnerability categories, executed in two waves. Wave 1 establishes authenticated sessions and maps data structures. Wave 2 leverages those sessions for deeper testing. Each category runs its own specialized AI agent with a three-stage pipeline: vulnerability detection, queue extraction, and exploitation verification. (Whitebox widens this to nine source-aware classes; see How Whitebox works.)

Wave 1Authentication

Tests login flows, session management, password reset mechanisms, OAuth implementations, JWT validation, and credential handling. Creates real accounts using disposable email, then inspects session cookies (HttpOnly, Secure, SameSite), tests for session fixation, token rotation, and logout invalidation. Follows an 11-step methodology checklist with strict evidence requirements.

Wave 1Injection

SQL injection, NoSQL injection, command injection, LDAP injection, and template injection. Tests both classic and blind techniques (time-based, error-based, out-of-band) across all discovered input vectors including URL parameters, form fields, headers, and JSON bodies.

Wave 2Cross-Site Scripting (XSS)

Reflected, stored, and DOM-based XSS testing. The agent executes payloads in a real Chrome instance and verifies actual script execution via browser_evaluate, not pattern matching against response bodies.

Wave 2Authorization (IDOR / Access Control)

Insecure direct object references, horizontal and vertical privilege escalation, missing function-level access controls, and API authorization bypasses. Uses accounts created during Wave 1 to test cross-user access patterns.

Wave 2Server-Side Request Forgery (SSRF)

Tests URL parameters, file upload handlers, webhook endpoints, and any functionality that makes server-side HTTP requests. Includes private IP range detection to prevent the scanner itself from being used as an SSRF vector.

Categories that discover vulnerabilities receive bonus deep-dive turns (5% of budget) to escalate findings, gather stronger evidence, and explore related attack paths.

Scanner Tooling

The AI agent has access to 14+ specialized security tools during scans, plus full bash access for running curl, wget, and custom scripts. These aren't wrappers around existing scanners. Each tool is purpose-built for the Vector pipeline.

HTTP Requests

Raw GET/POST/PUT/DELETE/PATCH/OPTIONS with redirect control and private IP blocking

Browser Navigation

Real Chromium with full JS execution, form filling, clicking, and JS evaluation

Network Interception

Captures all XHR, fetch, and WebSocket requests during navigation for SPA API discovery

Site Crawler

Multi-page crawling with tech fingerprinting, form inventory, and inline API hint extraction

JavaScript Analysis

Parses JS bundles with 40+ regex patterns to extract API routes, secrets, and config values

Subdomain Discovery

Certificate Transparency log enumeration + DNS brute force across 27 common prefixes

Rate Limit Probing

Sends 50 rapid requests to empirically detect 429s, timing delays, and CAPTCHA triggers

CORS Testing

Tests 8+ origin variations (reflected, wildcard, null) to detect CORS misconfigurations

GraphQL Introspection

Full schema extraction with sensitive field detection (tokens, passwords, keys, roles)

Disposable Email

Generate addresses, poll inboxes, and auto-extract verification links for account creation

Browser-Based Testing

Vector runs a real Chromium browser instance during every scan. This isn't headless HTTP requests pretending to be a browser. The agent navigates pages, fills forms, clicks buttons, intercepts all network traffic (XHR, fetch, WebSocket), evaluates arbitrary JavaScript in the page context, and inspects cookies, localStorage, and sessionStorage directly.

Each scan gets an isolated BrowserContext with memory protection. Chrome is configured with a 512MB V8 heap cap and WebGL disabled to prevent memory-heavy sites (ThreeJS, heavy canvas apps) from crashing the worker. This doesn't affect authentication flows, CAPTCHA rendering, or any functional testing. The agent can still read console logs, inspect the network log, and take screenshots throughout the scan.

Wallet Injection

For Web3 applications, Vector injects fully functional crypto wallets into the browser before navigating to your site. These are real wallets with real cryptographic signing, not mocks.

The Ethereum wallet implements the full MetaMask JSON-RPC interface: eth_requestAccounts, personal_sign, eth_signTypedData_v4 (EIP-712), and eth_sendTransaction. It generates real secp256k1 keypairs, produces valid checksummed addresses, and auto-approves all signing requests. It even announces itself via EIP-6963 so web3 libraries discover it automatically.

The Solana wallet implements the Phantom provider interface: connect, signMessage, signTransaction, and signAllTransactions. It uses Ed25519 signing via Web Crypto with base58-encoded public keys. Both window.solana and window.phantom.solana access patterns are supported.

This enables Vector to test wallet-gated flows, sign-in-with-Ethereum (SIWE), token-gated access, and any authentication that requires a connected wallet. Wallet injection is enabled by default on every scan.

Disposable Email Server

Vector operates its own email infrastructure on the zauthvector.com domain via Cloudflare Email Routing and a custom Worker. During scans, the agent generates disposable addresses (like [email protected]), uses them to register accounts on your site, then polls the inbox for verification emails.

Incoming emails are parsed for both plain text and HTML content, and verification URLs are automatically extracted and ranked by relevance. Links containing "verify", "confirm", or "activate" are prioritized over generic URLs. Common non-verification links (analytics, schema.org, image files) are filtered out. The agent then visits the verification link to complete account creation and proceeds to test the authenticated attack surface.

False Positive Prevention

Vector applies automated severity validation to every finding before it lands in your report. The AUTH category operates under a "assume false until proven" default stance, and Critical findings require Level 3+ proof (demonstrated exploitation, not theoretical attack chains).

The validator catches common misidentifications that trip up other scanners:

CORS + localStorage conflation

CORS does not grant cross-origin localStorage access. Same-origin policy is independent of CORS headers. Findings claiming this are downgraded.

Critical without exploitation proof

A Critical finding must include actual exploitation evidence ("successfully accessed", "data extracted"), not theoretical chains ("if victim visits"). Unsupported Criticals are downgraded to High.

Header names reported as vulnerabilities

Access-Control-Expose-Headers listing header names is not a vulnerability without demonstrated data extraction. Capped at Medium.

localStorage as architectural observation

Using localStorage for tokens is an architectural choice, not a vulnerability, unless paired with proven XSS. Downgraded to Low without XSS evidence.

Security Reports

Each scan produces a detailed security report with every finding categorized by severity. Findings include descriptions, affected endpoints, proof-of-concept reproduction steps, and remediation guidance. Each finding carries a verdict badge indicating whether the vulnerability was fully exploited, blocked by defenses, or remains a potential risk.

Reports stream in real time as the scan runs. Progress events are broadcast via Redis pub/sub so you can watch recon discoveries, tool executions, and findings appear live in the dashboard. Screenshots are captured throughout the scan so you can see exactly what the agent saw at each step.