Vector
Vector is an AI-powered vulnerability scanner that runs in two modes. Blackbox points a real attacker agent at your live app with no code access. It discovers the attack surface, tests across categories, and proves each exploit on the running target. Whitebox also reads your source: it builds a call-graph, traces tainted data to dangerous sinks, and then confirms every candidate finding live against your deployed app. Both produce detailed reports with working proof-of-concept exploits, never signature matches or guesses.
Built on Claude's agent capabilities, Vector doesn't rely on signature databases or predefined rules. It reasons about your application the way a human pentester would, adapting its approach based on what it discovers during reconnaissance. It runs a real Chromium browser, injects crypto wallets, creates disposable email accounts, analyzes JavaScript bundles, and can even route through proxy browsers to bypass geo-blocks and CAPTCHAs. Every scan runs in its own isolated worker node with dedicated resources, and the infrastructure autoscales to handle concurrent scans without contention. Each worker gets its own browser instance, its own database connection pool, and its own memory space. There's no cross-contamination between scans. Cookies, sessions, localStorage, and network state from one scan never leak into another.
Domain Verification
Before scanning, you must prove ownership of the target domain. Vector uses two verification methods depending on your domain type:
Custom domains: DNS TXT record
Add a TXT record to your domain's DNS with the value vector-verify=<your-token>. Vector queries multiple public resolvers (Cloudflare, Google, Quad9) to check for recently propagated records. This is the default method for any custom domain.
Platform subdomains: .well-known endpoint
If your site is hosted on a shared platform (Railway, Vercel, Netlify, Fly, Render, Cloudflare Pages, etc.), you can't modify DNS. Instead, serve a JSON response at /.well-known/vector-verify containing {"token": "<your-token>"}. Vector checks both root and www variants automatically.
Verification tokens expire after 1 hour. Multiple users can attempt verification simultaneously; first to verify wins exclusive ownership. Shared platform parent domains (e.g. vercel.app itself) are blocked to prevent claiming shared infrastructure.
Scan Modes
Vector runs in two modes. The mode is decided by what you give it: point it at a URL for a Blackbox scan, or connect a repository for a Whitebox scan that reads your source and then proves its findings live against the same running app.
A real attacker agent against your live app with no code access. Full multi-wave recon and category testing with wallet injection, disposable-email account creation, and bonus deep-dive turns for categories that find vulnerabilities. Every finding is proven on the running target.
Everything in Deep, plus a full source-code audit: call-graph construction, taint tracing to dangerous sinks, secrets and dependency scanning, and business-logic review. Each candidate is then runtime-confirmed against your deployed app, so you get code-level depth with live proof, not a static-analysis report full of maybes. See How Whitebox works below.
Scan Setup
Before a scan starts you tell Vector what it's looking at and how to reach the parts that matter. The more you give it, the sharper the scan, but everything here is optional except proving you own the domain.
Target profile
Web App tests the browser UI and the API behind it; API is headless and only exercises your /api surface with no UI.
A short free-text description of what the app is. It's folded into the recon and category prompts so testing is grounded in what your app actually does.
Vector discovers subdomains from Certificate Transparency logs and lets you choose which to include. The root domain is always in scope.
List routes you already know exist and the agent probes them first instead of discovering blind. List paths it must never touch (destructive actions, logout, third-party) and anything found there is discarded. (Up to 100 of each.)
Test accounts
To test authenticated flows (auth, IDOR, and privilege escalation), give Vector up to five accounts, each an email or username, a password, and a role (e.g. User, Admin, View Only). Passwordless accounts (magic-link / SSO) are supported with a "no password" toggle. If you don't add any, the scanner creates disposable accounts where signup is available, or tests unauthenticated flows only. Accounts saved on a verified domain are reused automatically on later scans.
Custom headers
Attach custom HTTP headers that ride on every request: a bearer token, an API key, a tenant selector, whatever your app needs. Set them globally or per-subdomain (up to 20). The agent applies them to every HTTP-tool call and browser request throughout the scan.
Rate limit
A maximum-requests-per-second control (10–200, default 50) keeps the scan gentle on production. It is a hard egress limiter, not a hint to the model. Requests are spaced in real time, so a low setting genuinely throttles traffic. 200 removes the cap.
Test-account credentials and custom headers are AES-256-GCM encrypted at rest, and never appear in reports. Secrets are redacted from all output.
How Whitebox Works
Whitebox reads your source and reasons about it the way an auditor would, then proves what it finds against your running app. It is not a static-analysis linter that dumps a thousand maybes. Static analysis predicts; Vector then goes and proves. Every finding lands in one of three tiers: Confirmed (demonstrated live), Reachable (a real call-path reaches the sink), or Reported (flagged, not yet reached). Live proof requires a deployed URL; without one the scan stays static.
The pipeline
Fast deterministic detectors sweep every file for dangerous sinks and secrets: SQL/NoSQL injection, command exec, unsafe eval and deserialization, path traversal, XXE, open redirect, weak crypto, "alg:none" JWTs, mass-assignment, prototype pollution, ReDoS, and hardcoded credentials. Sub-second, produces candidates.
A tree-sitter call-graph is built across your whole repo, then reachability is walked from each HTTP route → handler → sink (resolving Express mount prefixes and Next.js routing). Only sinks a real request can actually reach survive. Known-vulnerable dependency call-sites are merged in here too.
Claude agents read the reachable code in parallel across nine specialists (access-control / IDOR-BOLA, injection, auth, secrets & dependencies, business-logic, SSRF & redirect, input-validation, XSS, and config exposure). This is where semantic bugs a regex can never see get caught: broken object-level authorization, price/quantity/state-machine flaws, race conditions.
When you give Vector a live target, it fires a precise probe at the exact route the graph proved (a timing sleep-oracle for deserialization, an identical-body replay for IDOR, an /etc/passwd read for path traversal), and promotes only what actually fires to Confirmed, with the real request/response as proof.
A compact per-finding LLM pass demotes low-confidence candidates (it never silently drops them), then a verify gate replays each finding anonymously with no credentials and discards anything the app refutes. Confirmed findings skip both, since they are already proven.
A browser+API agent then exploits surviving candidates against your deployed app, and a runtime hygiene battery checks the live origin for rate-limiting, CORS reflection, weak password policy, verbose errors, and exposed files, with backend-aware adapters for Supabase, Firebase, GraphQL/Hasura, Appwrite, and PocketBase.
Findings are de-duplicated across every engine, scored (CVSS + severity reconciliation), and paired with code-level remediation before they reach your report.
What you connect
Connect a GitHub, Bitbucket, or GitLab repository (a one-click GitHub App install is available), or upload a .zip of your source. Vector does a shallow, single-branch clone; the access token is injected into the clone URL and never logged, and an uploaded archive is deleted right after extraction. Whitebox scans don't require domain verification. Add a live URL only if you want findings proven against the running app.
Your code stays private
Secrets are redacted from every finding, code snippet, and agent log before anything leaves the worker (Stripe, AWS, Google, GitHub, Slack, SendGrid keys, private keys, JWTs, and high-entropy blobs are all scrubbed). The scan view is owner-only: it returns only your own scan and never exposes internal infrastructure, proxies, tokens, or other users' data. Engineering telemetry (cost, tokens, turns) is stripped at the log boundary and never reaches your report.
Billing & Refunds
No subscriptions or seat licenses. You buy credits and pay a flat fee per scan.
Deep Scan
Blackbox. Full multi-pass pentest of your live app.
$49 per scan
Endpoint, header & subdomain mapping
Site crawling & JS analysis
Auth flow testing
CORS & SSRF probing
Session & privilege escalation
IDOR & token analysis
Whitebox Scan
Source-code audit, proven live on your running app.
$150 per scan
Everything in Deep
Full source-code analysis
Call-graph & taint tracing
Secrets & dependency scanning
Business-logic & auth flaws
Every finding runtime-proven live
Stake ZAUTH for up to 50% off any scan.
When you start a scan, the flat fee is charged from your credit balance upfront. Every transaction is logged as an auditable ledger entry with before/after balance snapshots.
AI-Powered Reconnaissance
Every scan begins with an autonomous recon phase using 30% of the total turn budget. The AI agent crawls your application with a real browser, discovers endpoints, intercepts network traffic to find hidden API calls in SPAs, analyzes JavaScript bundles for hardcoded routes and secrets, enumerates subdomains via Certificate Transparency logs and DNS brute force, and maps authentication flows.
The recon agent produces structured intelligence: technology stack, authentication mechanisms, all discovered endpoints, API patterns, form inventories, security headers, and potential entry points. This data feeds directly into each category scanner so vulnerability testing is targeted, not generic.
Scan Categories
In blackbox mode Vector tests across five vulnerability categories, executed in two waves. Wave 1 establishes authenticated sessions and maps data structures. Wave 2 leverages those sessions for deeper testing. Each category runs its own specialized AI agent with a three-stage pipeline: vulnerability detection, queue extraction, and exploitation verification. (Whitebox widens this to nine source-aware classes; see How Whitebox works.)
Tests login flows, session management, password reset mechanisms, OAuth implementations, JWT validation, and credential handling. Creates real accounts using disposable email, then inspects session cookies (HttpOnly, Secure, SameSite), tests for session fixation, token rotation, and logout invalidation. Follows an 11-step methodology checklist with strict evidence requirements.
SQL injection, NoSQL injection, command injection, LDAP injection, and template injection. Tests both classic and blind techniques (time-based, error-based, out-of-band) across all discovered input vectors including URL parameters, form fields, headers, and JSON bodies.
Reflected, stored, and DOM-based XSS testing. The agent executes payloads in a real Chrome instance and verifies actual script execution via browser_evaluate, not pattern matching against response bodies.
Insecure direct object references, horizontal and vertical privilege escalation, missing function-level access controls, and API authorization bypasses. Uses accounts created during Wave 1 to test cross-user access patterns.
Tests URL parameters, file upload handlers, webhook endpoints, and any functionality that makes server-side HTTP requests. Includes private IP range detection to prevent the scanner itself from being used as an SSRF vector.
Categories that discover vulnerabilities receive bonus deep-dive turns (5% of budget) to escalate findings, gather stronger evidence, and explore related attack paths.
Scanner Tooling
The AI agent has access to 14+ specialized security tools during scans, plus full bash access for running curl, wget, and custom scripts. These aren't wrappers around existing scanners. Each tool is purpose-built for the Vector pipeline.
Raw GET/POST/PUT/DELETE/PATCH/OPTIONS with redirect control and private IP blocking
Real Chromium with full JS execution, form filling, clicking, and JS evaluation
Captures all XHR, fetch, and WebSocket requests during navigation for SPA API discovery
Multi-page crawling with tech fingerprinting, form inventory, and inline API hint extraction
Parses JS bundles with 40+ regex patterns to extract API routes, secrets, and config values
Certificate Transparency log enumeration + DNS brute force across 27 common prefixes
Sends 50 rapid requests to empirically detect 429s, timing delays, and CAPTCHA triggers
Tests 8+ origin variations (reflected, wildcard, null) to detect CORS misconfigurations
Full schema extraction with sensitive field detection (tokens, passwords, keys, roles)
Generate addresses, poll inboxes, and auto-extract verification links for account creation
Browser-Based Testing
Vector runs a real Chromium browser instance during every scan. This isn't headless HTTP requests pretending to be a browser. The agent navigates pages, fills forms, clicks buttons, intercepts all network traffic (XHR, fetch, WebSocket), evaluates arbitrary JavaScript in the page context, and inspects cookies, localStorage, and sessionStorage directly.
Each scan gets an isolated BrowserContext with memory protection. Chrome is configured with a 512MB V8 heap cap and WebGL disabled to prevent memory-heavy sites (ThreeJS, heavy canvas apps) from crashing the worker. This doesn't affect authentication flows, CAPTCHA rendering, or any functional testing. The agent can still read console logs, inspect the network log, and take screenshots throughout the scan.
Wallet Injection
For Web3 applications, Vector injects fully functional crypto wallets into the browser before navigating to your site. These are real wallets with real cryptographic signing, not mocks.
The Ethereum wallet implements the full MetaMask JSON-RPC interface: eth_requestAccounts, personal_sign, eth_signTypedData_v4 (EIP-712), and eth_sendTransaction. It generates real secp256k1 keypairs, produces valid checksummed addresses, and auto-approves all signing requests. It even announces itself via EIP-6963 so web3 libraries discover it automatically.
The Solana wallet implements the Phantom provider interface: connect, signMessage, signTransaction, and signAllTransactions. It uses Ed25519 signing via Web Crypto with base58-encoded public keys. Both window.solana and window.phantom.solana access patterns are supported.
This enables Vector to test wallet-gated flows, sign-in-with-Ethereum (SIWE), token-gated access, and any authentication that requires a connected wallet. Wallet injection is enabled by default on every scan.
Disposable Email Server
Vector operates its own email infrastructure on the zauthvector.com domain via Cloudflare Email Routing and a custom Worker. During scans, the agent generates disposable addresses (like [email protected]), uses them to register accounts on your site, then polls the inbox for verification emails.
Incoming emails are parsed for both plain text and HTML content, and verification URLs are automatically extracted and ranked by relevance. Links containing "verify", "confirm", or "activate" are prioritized over generic URLs. Common non-verification links (analytics, schema.org, image files) are filtered out. The agent then visits the verification link to complete account creation and proceeds to test the authenticated attack surface.
False Positive Prevention
Vector applies automated severity validation to every finding before it lands in your report. The AUTH category operates under a "assume false until proven" default stance, and Critical findings require Level 3+ proof (demonstrated exploitation, not theoretical attack chains).
The validator catches common misidentifications that trip up other scanners:
CORS does not grant cross-origin localStorage access. Same-origin policy is independent of CORS headers. Findings claiming this are downgraded.
A Critical finding must include actual exploitation evidence ("successfully accessed", "data extracted"), not theoretical chains ("if victim visits"). Unsupported Criticals are downgraded to High.
Access-Control-Expose-Headers listing header names is not a vulnerability without demonstrated data extraction. Capped at Medium.
Using localStorage for tokens is an architectural choice, not a vulnerability, unless paired with proven XSS. Downgraded to Low without XSS evidence.
Security Reports
Each scan produces a detailed security report with every finding categorized by severity. Findings include descriptions, affected endpoints, proof-of-concept reproduction steps, and remediation guidance. Each finding carries a verdict badge indicating whether the vulnerability was fully exploited, blocked by defenses, or remains a potential risk.
Reports stream in real time as the scan runs. Progress events are broadcast via Redis pub/sub so you can watch recon discoveries, tool executions, and findings appear live in the dashboard. Screenshots are captured throughout the scan so you can see exactly what the agent saw at each step.
On this page