NightVision provides a browser‑first dynamic application security testing (DAST) platform that automatically discovers APIs from source code and runs fully authenticated, MFA‑enabled scans in real browsers. The tool delivers findings as actionable work orders, enabling development and security teams to verify fixes quickly without slowing down release cycles.
Funding
Funding not disclosed
Founders
Product
Problem
Enterprises increasingly rely on AI‑assisted development and low‑code tools, leading to a rapidly expanding set of internal applications and APIs that are often undocumented and unaudited. Traditional dynamic application security testing (DAST) tools struggle to discover these hidden endpoints and cannot reliably test fully authenticated, multi‑factor protected flows, leaving critical vulnerabilities unchecked.
Solution
NightVision offers a browser‑first DAST platform that first performs deterministic analysis of the application’s source code to generate an OpenAPI specification in seconds, ensuring comprehensive API discovery. The platform then executes fully authenticated scans using real browsers, including multi‑factor authentication, to emulate actual user interactions and uncover runtime and business‑logic flaws. Test results are delivered as actionable work orders with HTTP evidence, enabling developers to remediate issues directly within existing security workflows. The service supports SOC 2 Type 2 compliance and can be started via a free trial that requires no credit card, facilitating rapid adoption without disrupting development cycles.
Target Audience
NightVision targets security and engineering teams in enterprise organizations that need to secure a growing portfolio of internal web applications, APIs, and low‑code services.
Features
- Deterministic local source analysis that produces an OpenAPI spec in under 20 seconds, capturing undocumented routes
- Real‑browser dynamic scanning that performs fully authenticated, MFA‑enabled interactions
- Automated generation of work orders with detailed HTTP request/response evidence for developer triage
- Integration hooks for existing security and ticketing systems to fit into current workflows
- SOC 2 Type 2 compliance assurance and a no‑credit‑card free trial for quick onboarding