Company intelligence
NightVision
Proof on every finding. Fixes in every PR
About NightVision
NightVision finds what is in your applications, proves it, and fixes it. The scan lifecycle is one loop, starting and ending in your source code. Your source tells us what the outside never could: what the code declares, compared against what the app actually answers. Same engine, same scan. Source intelligence just hands it more of your app to test. Four ways in, one engine underneath: (1) Black box scans of public targets (2) Gray box with Code Traceback (3) CI/CD through GitHub Actions (4) Agent-native through our MCP server Start where you are. Add the source and the agents when you are ready. Every finding carries evidence: full request and response, a curl command that reproduces it, and a verify rescan. Results export as SARIF. A finding that turns into a ticket turns into debt. Over MCP, your agent does the work and proposes the fix. Your team approves the merge and stays the reviewer. Setup is 6 to 12 clicks per target, with vaulted credentials and MFA, scan policy and check-category selection, and support for public and private targets. All of it is in the product today. Nothing here needs a custom build. nightviz.ai
Verified activity
Signals from NightVision
2 published signals
Products & Services
NightVision ships a completion contract that includes an org-level block in CLAUDE.md or AGENTS.md, an /app-security-scan skill, and an MCP call that reads the source, generates the API spec, starts the DAST scan, and leaves .nightvision/manifest.json in the repo.
Reported by NightVision
Research & Knowledge
NightVision reported three separate CVEs landed in CISA's Known Exploited Vulnerabilities list this quarter, from three unrelated products, with the same root cause of an admin or config endpoint that should have required a login and didn't.
Reported by NightVision