First scan free · No credit card

The pentester's toolkit.
No pentester invoice.

20 real Kali Linux tools — nmap, nuclei, testssl, and 17 more — orchestrated by AI in sequence, not fired off in parallel and hoped for. Scans finish in minutes. Every finding ships with severity, the raw tool output that produced it, and a remediation path. From €149/mo, against €5,000–20,000 for one quarterly pentest.

No credit card. No sales call. Results in under 20 minutes.

ironimo · scan #4812 · app.example.com
→ nmap 443/tcp open https nginx 1.18.0 4.1s → whatweb WordPress 6.2.1, PHP 8.0.28 1.8s → wafw00f no WAF detected 2.3s ↳ WordPress fingerprinted — chaining wpscan → wpscan 12 plugins enumerated 38.6s → nuclei CVE-2023-32243 unauth password reset 51.2s → testssl TLS 1.0 enabled, weak ciphers 44.9s → ffuf /.git/config exposed (200) 21.4s ✓ scan complete 1 critical 3 high 6 medium 9 low/info every finding links to the raw tool output that produced it

Illustrative scan output — an example of how Ironimo chains tools based on what it finds, not a recording of a specific scan.

Your pentest is a photograph.
Your attack surface is a video.

A quarterly engagement tells you what was true on the day the tester looked. Then you ship 400 commits, bump 60 dependencies, and stand up two new subdomains — and nobody looks again for 89 days.

Ironimo does not replace that pentest. It closes the 89 days in between: the same tools your pentester runs, on the cadence your codebase actually changes.

20
Kali tools in the chain
every one of them real and named
<20min
Typical scan
not two to six weeks
100%
Findings with raw tool output
plus a remediation path
€149
Entry price per month
vs €5,000+ per engagement

Three steps. No agents, no infrastructure.

1

Point it at a URL

Add your web application. Nothing to install, no sidecar, no VPC peering. If you need to scan behind a login, store credentials once — they are encrypted at rest and injected only at scan time.

2

The chain adapts

Ironimo runs reconnaissance first, then decides what to run next from what it found. WordPress detected? wpscan. Open service on a non-standard port? The matching probe. A parameter that reflects input? Injection testing. It follows leads the way a tester does.

3

Read findings, not noise

Findings arrive ranked by severity with the affected URL, the evidence, the tool and flags that produced it, and how to fix it. Nothing is a score you have to trust — everything is a result you can reproduce.

The 20 tools, named.

Proprietary scanners ask you to trust a number. We list every binary in the chain, because you already know these tools — and you can check our work.

nmapPort & service discovery
whatwebTechnology fingerprinting
wafw00fWAF detection
subfinderSubdomain enumeration
theharvesterOSINT & domain intelligence
gospiderCrawling & endpoint discovery
gobusterDirectory / DNS / vhost brute force
dirbContent discovery
ffufFast web fuzzing
arjunHidden parameter discovery
niktoWeb server misconfiguration
nucleiTemplate-based CVE detection
testsslTLS configuration testing
sqlmapSQL injection
xsstrikeCross-site scripting
commixCommand injection
jwt_toolJWT analysis & attacks
hydraCredential brute force
wpscanWordPress vulnerabilities
searchsploitExploit-DB lookup

How we compare

Ironimo Quarterly pentest Enterprise DAST Open source (ZAP) Dev-first DAST
Scanning engine 20 real Kali tools Human experts + Kali Proprietary Single tool Proprietary
Orchestration AI-driven chaining Manual, human-led Predefined configs Manual CI/CD focused
Depth 20 tools, multi-vector Deepest — finds logic flaws Deep (single engine) Moderate Shallow to moderate
Time to result Under 20 minutes 2–6 weeks to report Hours to days Hours (manual run) Minutes (CI-scoped)
Cadence Daily or weekly Quarterly or annual Scheduled Whenever you remember Per pull request
Setup A URL Scoping + scheduling Requires tuning Heavy manual config Pipeline integration
Transparency Raw tool output on every finding PDF, weeks later Limited Full — you run it Limited
Annual cost From €1,490 €5,000–20,000 per engagement €30,000–50,000+ Free, plus your team's time €2,500–7,000

To be straight about it: a good human pentester will find things we will not — chained business logic abuse, authorization flaws that need product context, creative exploitation. Keep your pentest. Ironimo is what runs on the other 89 days.

Less than a quarterly pentest. Every month.

One engagement costs €5,000–20,000 and lands as a PDF weeks later. Ironimo starts at €149/mo and runs continuously. Your first scan is free — no card, no call.

Starter

For small teams that need coverage between engagements

€149/mo

€1,490/yr billed annually

  • Up to 5 web applications
  • 20 scans per month
  • Weekly scheduled scanning
  • All 20 Kali tools
  • 30-day scan history
  • 3 team members
Start free scan

Enterprise

For portfolios, subsidiaries, and procurement that asks hard questions

Custom

Talk to us

  • Unlimited applications
  • Unlimited scans
  • Continuous monitoring
  • API access with webhooks
  • SSO / SAML
  • Unlimited team members
  • Dedicated support and SLA
Contact us

Common questions

What exactly does Ironimo scan?

Web applications — anything reachable at a URL. It tests for the vulnerability classes in the OWASP Top 10 — SQL injection, XSS, command injection, misconfigurations, outdated software, exposed sensitive files, weak SSL/TLS, open ports, and more — though findings are reported individually rather than mapped to OWASP categories. Each scan draws on up to 20 Kali Linux tools, orchestrated by AI based on what it discovers about your target.

How is this different from running Kali tools myself?

Orchestration, correlation, and time. Running 20 tools by hand is hours of configuration and interpretation. Ironimo chains them — nmap finds an open port, the right follow-up tool probes the service. Results are correlated, deduplicated, and ranked. You get broad coverage in minutes instead of a weekend. Automated scanning excels at enumerable issues: known CVEs, misconfigurations, injection points. Business logic flaws still need a human, and Ironimo is built to complement that work rather than replace it.

Will Ironimo disrupt my production environment?

Default scan profiles use non-destructive techniques: reconnaissance, fingerprinting, and passive vulnerability detection. Aggressive tools such as sqlmap and hydra only run in profiles you explicitly enable, and we recommend pointing those at staging. You control which tools run against which targets. See the Security page for how we constrain scans.

Does Ironimo help with SOC 2 or ISO 27001 compliance?

SOC 2 Trust Services Criteria and ISO 27001 Annex A both require regular vulnerability assessment. Ironimo gives you scheduled, automated scanning with reports that map findings to those frameworks — continuous evidence between annual human-led assessments, which is what auditors want documented throughout the year, not just at audit time.

What about false positives?

Because Ironimo chains tools, findings get cross-verified: when one tool flags something, follow-up tools probe it before it surfaces. Every finding carries its evidence and the exact tool output, so you can confirm it yourself instead of taking a score on faith. We would rather show you our work than ask for your trust.

Where is my scan data stored?

Ironimo is a Netherlands-based company. Scan data is processed and stored in the EU, and our analytics run on the EU endpoint. Retention, access, and deletion are covered on the Privacy page.

Can I scan an application that requires login?

Yes. Ironimo supports authenticated scanning with password, token, or cookie-based sessions. Credentials are encrypted at rest and decrypted only at scan time. Unauthenticated scanning only ever sees your front door — most of the interesting surface is behind the login.

How long does a scan take?

A typical scan finishes in under 20 minutes. Tools are parallelized where possible and sequenced where one result feeds the next. Time varies with target size and the profile you pick, but even full-depth runs across all 20 tools are fast.

Stop waiting for the pentest report.

Point Ironimo at one URL. Your free scan runs a fixed, time-boxed pass — nmap, whatweb, wafw00f, testssl, nuclei — and ends in a report. The exact tool set varies by target type. Paid plans run the full 20-tool chain. No card, no call.

We count page views without cookies (PostHog, EU-hosted) — nothing is stored on your device until you choose. Accept for full analytics, Decline to switch it off entirely. No personal data is sold or shared with advertisers.