About Panoptic Scans
Panoptic Scans is a hosted vulnerability scanning platform. It is a cloud service that runs industry-standard open-source scanners, collects findings in one dashboard, and explains how those findings can be exploited together. Panoptic Scans, LLC was founded in 2019 to make network and application scanning usable for teams that do not want to operate Greenbone, ZAP, or Nuclei themselves.
What is Panoptic Scans?
Panoptic Scans is a vulnerability scanning service for internet-facing and internal systems. Customers schedule OpenVAS network scans, ZAP web application tests (including authenticated DAST), Nmap service discovery, and Nuclei template scans. Results include severity, affected assets, and an attack narrative that describes how an attacker could chain issues. Plans start at $25 per month. External scans require no agents. Internal OpenVAS scans run from a customer-managed VM on the Pro plan.
Who operates the scanners?
The Panoptic Scans security engineering team designs scan profiles, maintains the hosted OpenVAS, ZAP, Nmap, and Nuclei infrastructure, and writes the reporting format used for SOC 2 and ISO 27001 evidence. Team credentials include operational experience with Greenbone vulnerability tests,ß ZAP authenticated crawling, and mapping scan output to trust-service criteria such as CC7.1, CC7.2, and CC7.3.
How does the methodology work?
Scanning follows the same phases described in NIST SP 800-115 technical testing guidance: discovery, vulnerability verification, and documentation. Web tests align with the OWASP Top 10 risk categories. Network tests use the Greenbone/OpenVAS NVT feed, which covers more than 100,000 vulnerability tests. Port and service data come from Nmap. Template matches come from the Nuclei community corpus maintained by ProjectDiscovery.
What reports do auditors receive?
Reports export as PDF, CSV, HTML, TXT, and XML. SOC 2 and HIPAA-aligned layouts are available. Vanta customers can upload evidence automatically. Typical quarterly scanning cadence matches what many auditors expect for CC7.1 (detection of vulnerabilities) rather than a one-time annual scan.