Documentation

Scans And Depths

Understand how depth selection changes coverage breadth, runtime, and operational confidence.

Who This Topic Is For

Operators deciding which level of scan coverage to run for a target and change window.

Prerequisites

Before You Start

Use this checklist to make sure the workflow guidance applies cleanly to your current task.

  • Target scope and release context are known.
  • You understand whether this is a fast check or a release-gating decision.
  • You know if the run must be tracked in an account-backed workflow.
  • You know whether you are evaluating a website target or importing an API specification.
Expectations

What To Expect

Use this section to set the right outcome before you start the workflow.

Depth labels apply to dashboard website scans

Quick, Standard, Deep, and Comprehensive are credit-scan depths on the dashboard. Website Watch also offers Standard or Deep for the weekly scan, chosen when you add the site and locked for that seat. API Spec Scan is a separate import workflow.

Deeper is slower and broader

Quick is a baseline. Standard is the usual production default. Deep and Comprehensive cost more credits and take longer because coverage is wider.

Watch does not replace Comprehensive

A weekly Watch Standard is the same Standard pack as the dashboard. Watch Deep is the Deep pack on a Watch seat. Neither is Comprehensive, and neither is a pentest.

Playbook

Step-By-Step Guidance

Follow these steps in order for a reliable and repeatable outcome.

  1. Map business urgency to validation confidence.

    Fast triage can start with Quick. Production readiness and broader risk checks should use Standard or deeper.

  2. Choose depth intentionally.

    Use Quick for baseline checks, Standard for default production review, Deep for higher-risk windows, and Comprehensive for widest automated coverage where account-backed continuity matters. Keep public tool-suite quick/comprehensive modes separate in your mind from full platform scan-depth choices.

  3. Treat API spec scanning as a separate workflow.

    API Spec Scan is not another depth option for website crawling. It is a dedicated workflow for importing OpenAPI, Swagger, or Postman JSON so Vulnify can build endpoint inventory, run deterministic API checks, and optionally layer headless crawl enrichment where relevant.

  4. Run, compare, and adjust.

    If findings are incomplete for decision confidence, rerun at a deeper tier. Keep historical comparison to track posture improvements over time.

Examples

Worked Examples

These scenarios show how the workflow looks in practice, including the result you should see.

Pre-release gate at Standard

The team needs launch confidence this afternoon. They run Standard from the dashboard, triage Critical and High, then rerun after the header fix.

Standard is enough for this gate. Watch is added after launch; pick Standard or Deep then, because that weekly depth is locked for the seat.

Watch Deep is a Watch seat, not a credit click

An operator needs weekly Deep on a shop. They add the origin on Watch, pick Deep, and complete the $49 checkout. A one-off Deep from the dashboard still uses credits and does not change that Watch seat.

Watch Deep is locked to that origin. Dashboard Deep remains a credit scan. Comprehensive stays on credits.
Validation

Validation Checklist

Use this checklist to confirm the workflow was completed correctly.

  • Quick Scan: ~2-3 minutes | ~40 checks | $4.50
  • Standard Scan: ~5-7 minutes | ~80 checks | $9.00
  • Deep Scan: ~12-15 minutes | ~120 checks | $18.00
  • Comprehensive Scan: ~15-20 minutes | ~140+ checks | $36.00
Troubleshooting

Common Problems And Fixes

If something does not match expectation, check these common failure modes first.

Depth mismatch with release risk

Increase depth when release context or external exposure risk justifies broader validation before deployment.

Common failure mode

Confusing tool checks with platform depth

Public tools, platform-specific profiles, and the one-domain tool suite solve different workflow problems. Depth selection applies to broader scan workflows, while public tool quick/comprehensive modes and stack presets are part of the tool experience.

Common failure mode

Expecting Quick, Standard, Deep, or Comprehensive inside API spec import

API Spec Scan uses its own import workflow rather than website depth labels. Choose the API spec path when you need specification-driven endpoint review, then use website scan depths separately for browser-facing surface validation.

Common failure mode
FAQ

Scans And Depths FAQs

Common questions for this topic.

Yes. Standard is the default production-oriented option and is often the best first run when broader confidence is needed.

Next Recommended Action

Continue to the best next page based on where you are in your workflow.