Vulnerability assessment & penetration testing, in one platform
ErnX is EraNovaX's first product — real scan engines across your code, containers, cloud, and network, plus the manual testing tools a pentester actually reaches for, unified in one dashboard with one findings pipeline.
From zero to findings, in minutes
Every screen below is the real, live product, mid-use — an organization was created, an asset added, six scans run against it for real, and a report generated from the results.
1. Create an organization — every asset, scan, and finding is scoped to it.
2. Add an asset — a host, web app, repo, container image, or cloud account.
3. Pick a scan type — network, web, SSL, DNS, and more, run with one click.
4. Review findings — every result across every asset, in one triage view.
5. Generate a report — a downloadable PDF, built from your current findings.
Every layer of your attack surface, one tool
Real, working scan engines — not a roadmap slide.
Code & dependencies (SAST)
Static analysis and software-composition scanning across your source, catching real vulnerabilities and known-CVE dependencies before they ship.
Web & network
DAST, network/port scanning, SSL/TLS posture, and DNS security checks against your live web apps and infrastructure.
Containers & Kubernetes
Image and manifest scanning that catches vulnerable base layers and risky Kubernetes configuration before deploy.
Cloud posture (CSPM)
Connect a cloud account and get real misconfiguration findings against your actual running infrastructure, not a checklist.
Compliance (SCAP)
Standards-based compliance scanning against your own hosts, with real remediation guidance per failed rule — not a self-attestation form.
Manual testing tools
Repeater, Intruder, and an intercepting Proxy — for the moments automated scanning isn't enough, feeding the same unified findings pipeline as everything else.
One asset inventory, every finding in one place
Add an asset once — a host, web app, repo, container image, or cloud account — and every scan type that applies to it reports into the same findings view, with per-org role-based access control and (Enterprise) MSSP sub-tenant management for teams managing more than one organization's security posture.
Start free, upgrade when you need more
Launch pricing — Free is live today. Paid tiers are opening progressively; join free now and you'll be first in line.
Get started — it's freeStarter
5 assets · active scanning · 3 users
Coming soonGrowth
25 assets · full engine set · 10 users
Coming soonEnterprise
Unlimited · MSSP · SSO · white-label
Coming soonReady to see your real attack surface?
Create a free ErnX account — no card required.