ASMGUARD runs real offensive engines — AI red-teaming, attack-surface recon, and OWASP probes — against your apps and ships kill-chain reports your team can act on.

Enter a domain, subdomain, or API endpoint. ASMGUARD verifies ownership via DNS or a well-known file before any active scanning begins — no accidental probes.
Pick from passive recon through full AI red-teaming. Mix scan types to match your threat model. Schedule recurring scans for continuous coverage.
Attack narratives, CVSS scores, step-by-step remediation, and an AI-generated roadmap — ready in minutes, ready to share with your engineering team.
A guided simulation of what an authenticated scan looks like — phased execution, ranked findings, and the kill-chain context our reports ship with.
EASM recon starts from your root domain and uncovers every subdomain, open port, leaked credential, and exploitable service — then maps how they connect. Explore a live sample below: toggle layers, filter by severity, and pivot through the graph.
Adversarial LLM probing for jailbreaks & unsafe tool use.
Direct & indirect injection across tools, RAG, and memory.
Reasoning-driven probes for the most dangerous web flaws.
Live external attack-surface mapping & port discovery.
Catch AI-generated pitfalls, secrets & weak crypto in code.
Network ownership, cloud footprint & exposure analysis.
SPF / DMARC / DKIM spoofability scoring.
Known-exploited vuln matching against your stack.
Scheduled rescans with new-CVE email alerts.
AI attack-path narratives & remediation roadmaps.
BOLA, broken auth & rate-limit abuse across your endpoints.
Workflow abuse, privilege escalation & logic-flaw probing.
Static, dynamic, and supply-chain testing in one platform — from your source code to your running apps to every dependency you ship.
Deep static analysis of your code — paste a snippet, connect a GitHub repo, or upload a ZIP.
Live offensive probes against your deployed apps — the same techniques a real adversary uses.
Supply-chain scanning across 9 package managers, enriched with real-world exploit intelligence.
14-day Pro trial · 1 asset · no card required
Free forever on 1 internet-facing asset — no card required. New accounts start with a 14-day Pro trial (passive suite + AI reports on 1 asset); paid tiers unlock more assets, monitoring & offensive analysis.
| Feature | Free | Starter | Pro | Business |
|---|---|---|---|---|
| Internet-facing assets | 1 | 5 | 25 | Up to 100 |
| Monitoring frequency | On-demand | Weekly | Daily | Continuous |
| Email alerts | ||||
| CVE matching | ||||
| AI remediation guidance | ||||
| Advanced offensive analysis | ||||
| Attack-path report | ||||
| Public security badge | ||||
| Multi-client workspace | ||||
| RBAC | ||||
| API access | ||||
| White-label reports | ||||
| Audit log |
Business includes up to 100 internet-facing assets. Additional assets available on request.
ASMGUARD is an attack surface management and offensive security platform. It runs real probes — AI red-teaming, EASM recon, OWASP tests, CVE matching — against your web apps and APIs, then delivers kill-chain reports with actionable remediation steps.
When you sign up, you get 14 days of Pro-level access on 1 internet-facing asset — the full passive & monitoring suite (Headers, SSL/TLS, recon, DNS, email security, CVE matching) plus AI reports. Offensive scans (OWASP, red-team, attack chains) stay paid-only during the trial — upgrade or contact sales to unlock them. No credit card required. After the trial your account moves to the free forever tier (Headers + SSL, 1 internet-facing asset).
No. ASMGUARD is fully cloud-based. Add a target URL, verify domain ownership, and launch a scan — everything runs on our infrastructure. We also offer a CI/CD API for automation.
You may only scan internet-facing assets you own or have explicit written permission to test. ASMGUARD requires ownership verification before enabling active/offensive scans. Scanning third-party assets without permission is prohibited and may be illegal.
Most scanners run passive checks. ASMGUARD runs active, offensive engines — autonomous AI red-teaming, multi-step attack chains, and real OWASP probes — the same techniques an adversary would use. You get kill-chain reports, not just a list of CVEs.
Advanced offensive analysis — OWASP-focused checks, attack-path reports, and all other offensive scan types — is available on the Pro plan and above. The free forever tier covers HTTP Headers and SSL/TLS. Starter adds passive recon and CVE matching.
EASM (External Attack Surface Management) starts from your root domain and uses DNS enumeration, TLS certificate transparency logs, port scanning, and ASN lookups to build a live map of every exposed asset — subdomains, IPs, open ports, cloud footprint.
Yes. Every Pro+ account gets an API key. Use POST /api/ci/scan to trigger scans and GET /api/ci/scans/:id to poll results. The Developer page in your console has ready-to-paste curl and GitHub Actions examples.
Scan results and findings are stored in encrypted PostgreSQL. We are a Dutch entity (VerlorenEnergie, KvK 95543511) subject to GDPR. Data is not shared with third parties or used to train AI models.
Your account stays active on the free forever tier — you keep access to your historical reports and can still run Headers & SSL scans on 1 internet-facing asset. To unlock more scan types and assets, upgrade to Starter, Pro, or Business — offensive scans require Pro or above.
Have questions about pricing, custom plans, MSSP partnerships, or want a live demo? Fill in the form and we'll get back to you within one business day.
// we drink our own champagne
"Caught a critical BOLA vulnerability in our decisioning API before it reached production. One OWASP scan, 12 minutes. The kill-chain report went straight to the eng team with no translation needed."
"EASM recon surfaced three forgotten subdomains running outdated runtimes. We didn't even know they existed. Scheduled rescans now catch drift before it becomes a breach."