Byte Optimizer

Scanning that finds
what checklists don't.

A stack of specialist engines runs in parallel against targets you own, unauthenticated or authenticated, returning live, never-cached structured reports, a full REST API, and an MCP server for AI agents. The scan itself never calls an LLM; optional, opt-in AI Findings analyze the results when you turn them on.

OnScanner is a separate product. Full marketing, pricing, and documentation at onscanner.com ↗ app at app.onscanner.com ↗ See also how it compares to other scanners ↗
Illustrative rendition, actual invocations stream fresh and non-cached.
capabilities

Everything OnScanner does.

Nine capabilities, one API, one dashboard.

Security scanning

Web vulnerabilities (OWASP Top 10), exposed services, and misconfigurations, across authenticated and unauthenticated scans.

Active exploitation checks

Safe, non-destructive probes confirm whether known CVEs are actually exploitable on your stack, not just present.

CVE intelligence

Detected technologies matched to CVEs with severity, EPSS, and KEV context so you fix what attackers actually use.

Patch-status detection

Distinguishes patched, unpatched, and won't-fix CVEs using vendor and distro data. Fewer false alarms on backported fixes.

End-of-life detection

Flags products past end-of-life that no longer receive security support.

Privacy scanning

40+ detection categories: trackers, fingerprinting, session recording, storage tracking, WebRTC leaks, and PII exposure.

Technology & infrastructure

Fingerprints your tech stack, DNS, TLS, and WAF posture on every run.

Live results + monitoring

Never-cached scans on demand, plus scheduled recurring scans with notifications when your posture changes.

REST API + MCP server

Drop scans into CI, pull structured results, or connect AI agents through the MCP server.

how it works

Many engines. One report.

OnScanner runs a stack of specialist scanning engines in parallel against your live target. Each engine is deterministic and never calls an LLM on your data. Findings ship as a structured report and an API call you can drop into CI.

Optional, opt-in AI Findings analyze completed results: executive summaries, prioritized risks, MITRE ATT&CK mapping, and compliance assessment. The scan itself stays deterministic, and for a human-verified deliverable our pentest team picks up where automation stops.

questions

Automated scanning FAQ.

How is OnScanner different from a penetration test?

OnScanner is automated vulnerability scanning: fast, continuous, and broad, ideal for catching known issues and regressions between engagements. A penetration test is a manual, human-led assessment that chains weaknesses together to prove real impact, including business logic flaws no scanner can find. Most teams use OnScanner for breadth and our pentest team for depth.

What does OnScanner check?

It scans for OWASP Top 10 vulnerabilities, exposed services, and misconfigurations, matches your detected technologies to CVEs with severity, EPSS, and KEV context, confirms exploitability with safe probes, flags unpatched and end-of-life software, and runs privacy scanning across 40+ categories. Results ship as structured reports, a REST API, and an MCP server.

Will it work on my single-page app or API?

Yes. OnScanner is built for modern JavaScript-heavy stacks and APIs, which is exactly where legacy scanners lose coverage. Its live engine exercises client-rendered routes and API endpoints rather than only crawling static HTML.

Does OnScanner send my data to an LLM?

The scan itself never calls an LLM: the engines are deterministic. AI Findings is optional and opt-in; only when you enable it are your completed results analyzed for executive summaries, prioritized risks, MITRE ATT&CK mapping, and compliance assessment.

Have a question? Let's talk.

Talk to sales → Book a call →