Documentation

Getting Started With Vulnify

Pick the right entry point, run your first workflow, and understand what to do after the first result.

Who This Topic Is For

Security-conscious teams and operators starting with Vulnify for the first time.

Prerequisites

Before You Start

Use this checklist to make sure the workflow guidance applies cleanly to your current task.

  • A public target URL that you own or are authorized to assess.
  • A decision on whether you need a focused public tool result or a saved account workflow.
  • Clarity on whether your immediate goal is rapid validation or broader ongoing coverage.
Expectations

What To Expect

Use this section to set the right outcome before you start the workflow.

Public tools first, account when you need history

No account is required for focused public tools. Create an account when you need saved scans, Scheduled Scans, Website Watch, white-label reports, or a pentest workspace.

Watch Standard or Deep is chosen per site

Website Watch is a per-site subscription with a daily pulse and a weekly Standard or Deep scan. Pick the depth when you add the site; it is locked for that seat. Quick and Comprehensive still live on the dashboard with credits.

White-label is Team and Enterprise

Free and Pro keep Vulnify branding on exports. Agencies that need a logo, hide-Vulnify, and a client share link should start on Team.

Playbook

Step-By-Step Guidance

Follow these steps in order for a reliable and repeatable outcome.

  1. Choose your workflow entry point.

    Use a focused public tool when you need one category-specific answer, use the Run All Tools workflow when you want a one-domain tool suite result with generated artifacts, and use the dashboard flow when you need saved history, recurring follow-through, and broader account-backed continuity.

  2. Set scan depth based on risk and urgency.

    Quick is best for rapid baseline visibility.

    Standard is the default for production checks. Deep and Comprehensive are better when higher release risk or stronger validation confidence is required.

    Watch only offers Standard or Deep for the weekly scan, chosen when you add the site. Quick and Comprehensive stay on the dashboard with credits.

  3. Run and review findings with remediation context.

    Treat the result as a workflow output, not a score alone. Use finding details and remediation guidance to prioritize what gets fixed first.

  4. Move into repeatable follow-through or a verified pentest.

    Use Website Watch when you need always-on change alerts on one HTTPS origin.

    Use Scheduled Scans when you need a custom credit cadence and depth. Order a $297 Penetration Test or $497 Comprehensive Pentest when you need verified automated active testing with HTML and PDF.

    Team and Enterprise agencies brand those reports in Settings under White-Label Reports.

Examples

Worked Examples

These scenarios show how the workflow looks in practice, including the result you should see.

First-week shop launch

Run the free website scanner, then a Standard dashboard scan before launch. After go-live, add the origin to Website Watch so certificate and header drift is emailed without spending credits on the included cadence.

Launch uses Standard. Ongoing change detection uses Watch. Watch Deep is a Watch seat. Comprehensive stays on credits.

Agency delivering a weekly scan PDF

The agency is on Team. They save White-Label Reports with a PNG logo, hide Vulnify, run Standard, then Copy client link with Prepared for set to the retailer name.

The client opens a 14-day branded view. They do not create a Vulnify account.
Validation

Validation Checklist

Use this checklist to confirm the workflow was completed correctly.

  • The selected workflow matches the scope of the question being answered.
  • Scan depth aligns with release risk and required confidence level.
  • At least one remediation action is identified from real findings.
  • A next scan or follow-up review point is defined.
Troubleshooting

Common Problems And Fixes

If something does not match expectation, check these common failure modes first.

Choosing a depth that is too shallow for the situation

If findings are too limited for launch or audit confidence, move from Quick to Standard or above and rerun for broader coverage.

Common failure mode

Treating score output as final decision

Use score direction for trend awareness, but prioritize remediation decisions using the specific findings and their risk context.

Common failure mode

No follow-up plan after first scan

Create a repeat cadence with Website Watch for always-on change detection, Scheduled Scans for custom credit cadence, or documented rerun criteria so coverage does not degrade after the first pass.

Common failure mode
FAQ

Getting Started With Vulnify FAQs

Common questions for this topic.

No account is required for focused public tools. Use an account-backed workflow when you need saved reports, history, and broader operational continuity.

Next Recommended Action

Continue to the best next page based on where you are in your workflow.