Vertigo maps the full attack surface of modern web applications using a real browser engine and cloud-hosted machine learning.
Vertigo uses a real Chromium browser to authenticate, crawl, and classify your application — then delivers a structured JSON report your team can act on immediately.
Three focused commands — authentication, fingerprinting, and deep scanning — that compose cleanly into CI pipelines or standalone audit workflows.
-sub-depth, allowing recursive auditing of an entire application estate.Every vertigo scan produces a structured JSON report with a stable schema, designed to be consumed directly by downstream tooling, ticketing systems, or security dashboards.
All inference runs exclusively in the XAHICO cloud. The client package contains only the browser automation engine and HTTP plumbing — no model files, no training data, no GPU required.
A complete audit — from credential handoff to final report — runs as a single pipeline. Each stage builds on the last, and every step is logged to stderr when --debug is enabled.
vertigo auth, then handed off to vertigo scan-output <file>All output is suppressed unless --debug is passed. When enabled, structured log lines are written to stderr — one key=value pair per field, parseable by any log aggregator.
Get an API key, install the package, and run your first scan in under five minutes — no configuration required.
Get an API Key →