NightVision is a Web and API Security Testing Platform that delivers fast, comprehensive scans with minimal false positives. The platform integrates directly into CI/CD workflows, enabling developers to quickly locate and remediate vulnerabilities by tracing findings back to the exact area of code. This approach streamlines security operations, saves engineering time, and provides a tangible increase in security ROI.
Funding
$5.4M raised to dateRaised to date based on public sources. This may differ from the amount the company actually raised and is based only on what is publicly available on the internet.
Founders
Product
Problem
Traditional Dynamic Application Security Testing (DAST) methods often create numerous time-consuming and boundless issues for development teams, while Static Application Security Testing (SAST) solutions may lack code context, leading to delays and bottlenecks in the software development lifecycle. Existing API security testing requires detailed OpenAPI Specifications, and without proper documentation, many REST APIs miss out on comprehensive security assessments, leaving systems vulnerable to security breaches.
Solution
NightVision offers a web and API security testing platform that simplifies the identification of exploitable vulnerabilities in source code during the CI/CD process. The platform provides comprehensive scans of applications on both public and private networks, delivering fast, high-quality results with fewer false positives compared to traditional DAST and SAST products. NightVision's modern gray box testing emulates attacks to pinpoint vulnerabilities at the area of code, enabling security and development teams to efficiently collaborate on remediation before code reaches production. Additionally, NightVision's API eNVy automatically generates detailed documentation of existing APIs, ensuring comprehensive API discovery and enhanced testing coverage.
Target Audience
NightVision is designed for security engineers, platform engineers, security champions, and developers seeking to integrate security testing seamlessly into their development workflows and reduce the risk of vulnerabilities in production.
Features
- Comprehensive DAST scanning for web applications and APIs on public and private networks
- Fast scan times, typically between 3-10 minutes
- Integration into CI/CD pipelines for continuous security testing
- Modern gray box testing to emulate attacks and pinpoint vulnerabilities at the code level
- Automatic API documentation generation for undocumented APIs
- Identifies the exact area of code for faster remediation
- AI-powered explanations for instant remediation support
- Integration with GitHub Security Alerts for streamlined vulnerability management