Light scan
Public, passive checks for TLS, security headers, exposed files and other signals visible without authentication.
VICE separates observation, evidence, confidence and severity so every result explains what was seen, how certain it is and what to do next.
Public, passive checks for TLS, security headers, exposed files and other signals visible without authentication.
The complete verified-domain audit, including active but non-destructive probes across the supported web security modules.
A verified audit limited to the modules you select when you need a focused check or a faster retest.
VICE observed direct evidence that proves the condition, such as exposed data or a reproducible security control failure.
Several strong signals point to the issue, but one missing proof prevents VICE from calling it confirmed.
A pattern deserves review, but it is not enough on its own to claim a vulnerability.
Useful context about the attack surface or hardening state with no vulnerability claim.
The VICE Score weights severity and confidence, caps repeated findings from the same rule and excludes weak signals from punitive scoring. It is a prioritization tool, not a certification.
Light scans stay passive. Deeper probes require a verified domain and remain confined by protocol, DNS, IP, redirect and request budgets. Credentials never travel to a secondary origin.
An automated audit is a point-in-time view. It cannot prove that every code path is safe, replace a manual penetration test or see private systems that were not connected.