Home Pricing Features Docs Blog Support Contact Us
On-device AI security testing

Application Security
Testing, Built for the
Real World

Vooki Pro helps security teams find, validate and fix vulnerabilities faster — a DAST desktop app for web applications and REST APIs, with every scan running locally on your own machine.

Watch Demo

Every feature unlocked for 14 days · No credit card required

On-Device AI Accurate Results Developer Friendly Audit Ready
AI Finding Critical Risk The Vooki Pro dashboard: severity totals for critical, high, medium, low and informational findings, a 30-day findings-over-time chart, a severity mix breakdown and a triage queue of open findings.

Mapped to the standards your auditors ask for

OWASP Top 10OWASP API Top 10PCI-DSSNISTISO 27001HIPAAGDPRSOX
~480
Security Checks
25+
Attack Categories
6
Report Formats
100%
Local Scan Data
InjectionCross-Site ScriptingBroken Access ControlAuthentication FailuresCryptographic FailuresSSRFDeserializationInformation DisclosureBusiness LogicAPI SecuritySecurity HeadersCookie SecurityCSRFSession ManagementFile SecurityHTTP ProtocolOAuth / OIDC / SAMLPrototype PollutionLLM SecurityClient-Side SecurityConfigurationOutdated ComponentsInjectionCross-Site ScriptingBroken Access ControlAuthentication FailuresCryptographic FailuresSSRFDeserializationInformation DisclosureBusiness LogicAPI SecuritySecurity HeadersCookie SecurityCSRFSession ManagementFile SecurityHTTP ProtocolOAuth / OIDC / SAMLPrototype PollutionLLM SecurityClient-Side SecurityConfigurationOutdated Components
The Problem

Application testing is stuck

Manual testing can't keep up with release cadence, and most scanners hand you noise instead of evidence.

Testing Can't Match Releases

A manual assessment lands once a quarter while your team ships weekly. Everything between those two dates goes to production untested.

Findings You Can't Trust

Timing-based false positives, the same missing header filed 400 times, no request/response evidence. Triage costs more hours than the scan saved.

Your Targets Can't Leave

Staging behind a VPN, an internal admin app, a client's environment under NDA. Cloud scanners need a public target and a data-processing agreement you may never get.

Features

Everything a DAST run actually needs

Discovery, authentication, attack, triage, retest and reporting — in one desktop app, with no server to stand up.

Web Application Scanning

A six-step wizard walks you from target to results: discovery by quick seed, browser recording, crawl or hybrid, with an optional headless pass that captures background XHR endpoints. Depth, URL and time budgets included.

Target → Discovery → Auth → Policy → Schedule → Review

REST API Scanner & Builder

Import an OpenAPI v2/v3 spec, a Postman collection or a HAR file, or build requests by hand in the workspace — projects, folders, environments, variables and bulk auth. Then scan for BOLA, BFLA, mass assignment and GraphQL abuse.

OpenAPI · Postman · HAR

ThreatLens On-Device AI

A local language model triages findings and prioritises parameters and payloads. It downloads once and runs on your machine — no scan content is ever sent to a third-party AI service.

Runs entirely offline

Findings & Automated Retest

Browse findings across every scan, filter by severity, type or target, and read the full HTTP request and response with the injected payload highlighted. Fixed it? Retest re-runs the exact detector and returns a verdict.

Still Vulnerable / Fixed / Needs Review

Reports & Compliance

Export to PDF, HTML, Word (DOCX) or JSON. Standard reports carry an executive summary, risk score and per-finding evidence; compliance reports map control by control across seven frameworks.

4 export formats · 7 frameworks

Scheduling & CI/CD

Run scans on a cron expression or a simple every-N-hours interval. Export any wizard-configured scan as a JSON config and replay it headlessly from the command line, with reports and a complete .vpscan data file written as build artefacts.

Headless CLI · JSON config
How It Works

From target to report in 3 steps

1

Define the Target

Enter a URL or import an API spec, then set scope — same host, same domain or a custom host list, with include and exclude patterns. Authenticate with a form login, bearer token, API key, basic auth, OAuth2 or a recorded browser session.

2

Discover & Attack

Pick a policy — Default, Quick, OWASP Top 10, API Surface or your own — and a speed preset from stealth to aggressive. Every non-timing attack runs first, then a timing-only pass skips whatever is already confirmed.

3

Triage, Retest, Report

Review findings with full HTTP evidence and reproduction steps, mark false positives, override severity, file a ticket in Jira or GitHub, and export a standard or compliance report when you're done.

Integrations

Findings go where your work lives

Test the connection, pick a project, repository or team, and file a finding as a ticket in one click. Alerts land in Slack or any webhook you point at.

Jira
File findings as issues with live project lookup
Ticketing
GitHub Issues
Raise an issue on the right repository
Ticketing
Linear
Push straight to the owning team
Ticketing
GitLab
Issues on self-managed or gitlab.com
Ticketing
Azure DevOps
Work items in the project you choose
Ticketing
Slack & Webhooks
Alerts on new findings and scan completion
Notifications
Coverage

25+ categories, ~480 checks

304 active attack checks plus 177 version and outdated-component fingerprints, all selectable individually when you build a custom policy.

Injection & XSS

SQL and blind SQL, NoSQL, XXE, XPath, LDAP, OS command, SSTI, SSI, CRLF, host header, GraphQL, expression language, ORM, HPP and XSLT — plus reflected, stored, DOM, mutation, SVG and header-based cross-site scripting.

29 checks

Access Control & Auth

IDOR, BFLA, path traversal, forced browsing, privilege escalation and method override, alongside default credentials, user enumeration, weak password policy and the full JWT family — alg none, weak alg, algorithm confusion, jku and kid.

24 checks

API Security

BOLA, BOPLA, BFLA, mass assignment, unrestricted resource consumption, GraphQL introspection and DoS, API misconfiguration, inventory and versioning issues — mapped to the OWASP API Top 10.

12 checks
The full category list
Injection Cross-Site Scripting Broken Access Control Authentication Failures Cryptographic Failures SSRF Insecure Deserialization Information Disclosure Business Logic API Security Security Headers Cookie Security CSRF Session Management File Security HTTP Protocol Web Cache Deception OAuth / OIDC / SAML Prototype Pollution Denial of Service Encoding Attacks LLM Security DNS Security CVE-Class Attacks Client-Side Security Configuration Outdated Components
Fewer duplicates

Header, cookie, CORS, SRI and outdated-dependency issues are consolidated into one finding per host, origin, cookie or dependency — not one per crawled URL.

Fewer false positives

Timing-based attacks run in a separate second pass that skips anything already confirmed, so network jitter doesn't turn into a critical finding.

Honest scans

WAF and CDN detection, auth-health checks and session-expiry detection warn you when a scan is being blocked or the session died halfway through.

Pricing

One app, one licence

Start with a 14-day full-feature trial, then activate a licence key. No per-scan metering, no per-target billing.

Trial
14 days
free, no card required

Every feature unlocked for 14 days, so you can evaluate the real thing before you buy.

Full web & REST API scanning
All ~480 checks & policies
ThreatLens on-device AI triage
All report & export formats
Email support
6-Month Licence
$249
per individual seat, 6 months

For a fixed engagement or a half-year assessment cycle.

Everything in the trial
REST API Builder
Scheduled & recurring scans
Custom scan policies
Offline grace period
Buy 6-Month Licence
Most Popular
Annual Licence
$399
per individual seat, 12 months

For teams running continuous, scheduled testing all year.

Everything in the 6-month licence
Portable scan archives (.vpscan)
Headless CLI for pipelines
Compliance report pack
Priority support
Buy Annual Licence

Activation limits and licence duration are set on your account. Need more than 10 seats? Talk to us about custom pricing.

FAQ

Common questions

No. Findings and the HTTP transactions behind them live in a local SQLite database under your home directory, and the AI model runs on-device. Outbound traffic is limited to the target you are scanning, licence validation with the Vegabird server, the one-time AI model download, and any integration you configure yourself.

Vooki Pro is a native desktop application. macOS ships as a signed and notarized .dmg; Windows ships as an installer; Linux ships as an AppImage. It is not a SaaS and there is no browser version — the scan engine runs on your own hardware.

Yes. Choose form login, bearer token, API key header, HTTP basic, OAuth2 client credentials, raw headers and cookies, or record a real browser session and replay it. For APIs, an auto-login request mints a fresh token at scan start and refreshes it mid-scan when it expires.

No, and deliberately so. Vooki Pro is DAST-only: it tests running web applications and REST APIs. It also ships no manual-pentest tooling — no proxy interceptor, repeater or fuzzer. Its answer to "re-check this finding" is an automated retest.

Yes. Export any wizard-configured scan as a JSON config and run it headlessly from the command line. Reports and a complete .vpscan data file are written as build artefacts, ready to publish from your pipeline.

You activate the app with a licence key, which is verified against the Vegabird server and stored encrypted on your device. The trial unlocks every feature. Paid licences revalidate roughly once a day and keep working through an offline grace period, so you can scan on a disconnected network.
14-day full-feature trial · No credit card required

Ready to scan
your first target?

Start your 14-day trial, point Vooki Pro at an application you're allowed to test, and see what a two-phase DAST run turns up.

Signed and notarized for macOS · Windows installer · Linux AppImage

Vooki Pro
Start your 14-day trial
Please fill all fields.

Tell us where to send your licence key and installer. Every feature is unlocked for 14 days — no credit card required.

By requesting a trial you agree to our Terms & Privacy Policy, and to only scan systems you are authorised to test.