Skip to content

Vortex — application & API security

Vortex is BestDefense’s application and API security scanner. Point it at a web app or an API you own, and it probes for vulnerabilities — missing security controls, injectable parameters, exposed data, and more — then ranks what it finds by severity so you know what to fix first.

Vortex offers three scan types, from broad automated reconnaissance to an AI-driven pen-tester that reasons its way through your application like an attacker would. Every finding comes with evidence and per-finding actions: fix it with AI, accept the risk, or hand it to Jira.

Scan typeWhat it doesAvailability
AnalogBroad dynamic (DAST) reconnaissance and scanning across your app or APIEvery plan
AI pen-testAn agentic, ML-driven pen-tester that reasons, explores, and attempts exploitation in distinct phasesGrowth and higher
APIProgrammatic scanning focused on your API endpoints and contractsVaries by plan

Each scan also has an intensityQuick, Standard, Thorough, or Maximum. Quick is available on every plan; higher intensities generally require Growth or higher.

  1. Go to VortexRun scan.
  2. Choose your target site (or add one).
  3. Choose a scan type — Analog, AI, or API.
  4. Choose an intensity.
  5. Optionally attach pre-configured test users so Vortex can scan behind authentication.
  6. Launch. The report page shows live progress while the scan runs.

When the scan finishes you get a report you can explore, act on, and export.

If you’re brand new, start with the Quickstart.