Why this is useful
Most vulnerability scanners produce long lists of alerts that are difficult to interpret.
Vectorguard focuses on clarity. This reduces the time spent analysing results and helps you focus on what actually needs to be fixed. Instead of asking you to work through raw results, it provides:
- Prioritised findings with clear severity
- Explanations that can be understood without specialist knowledge
- Evidence linked to every issue
- Confidence scores so you know how much to trust each result
End-to-end clarity
What happens when you run a scan
Vectorguard runs a set of security tools against your target and then analyses the results using our own AI system, so your data never leaves our infrastructure. This means your scan data is not shared with third-party services.
Step 1
Scan the target
The system runs security tools to identify exposed services and potential vulnerabilities.
Step 2
Analyse the results
Raw outputs are processed and structured into meaningful findings.
Step 3
Generate the report
You receive a clear report with evidence, explanation, and confidence.
Built for Trust
In alignment with the Vectorguard Ethical Covenant, we believe that security should never come at the cost of your privacy. The system is designed to minimise data collection and retain only what is strictly necessary.

Automated Data Hygiene
To prevent the accumulation of unnecessary digital footprints, Vectorguard employs a strict 30-day retention policy. Our automated clean-up system permanently wipes all scan result data older than 30 days, regardless of user activity, ensuring your technical vulnerabilities do not become permanent records.

Sovereign Security & Integrity
Vectorguard operates within UK infrastructure and is designed so your scan data is not retained beyond what is necessary to deliver your report. We do not track users, and we do not store scan data. As soon as the scan is completed the only data we retain is the report itself, this is deleted after 30 days. This means that no data is available for tracking, sale or reuse

Your Right to Erasure
You can delete your account and all associated identifying metadata at any time. We ensure that all such data is removed promptly and completely.
Designed for action
Reports are structured so you can quickly understand
- What needs attention
- What can be deprioritised
- What action to take
Verified findings with confidence
Each finding includes:
- A clear description of the issue
- Supporting evidence
- An explanation of why it matters
- A recommended next step
Inspectable logic, when needed
Vectorguard reports are designed to be readable by default. For users who need deeper insight, each finding is based on observable signals and defined classification logic. This means the reasoning behind a finding can be examined if required, rather than hidden within an obscure 3rd party system.
A model designed for accessibility
Vectorguard is developed as part of the Jane Foundation, which is structured to ensure that security tools remain accessible to those who need them. The platform is free for individuals, small businesses, and NGOs. Its development is supported through contributions, allowing professional-grade security analysis to be made available without relying on data monetisation and without requiring the kind of budgets that many smaller organisations simply do not have.
Technical Scope
Infrastructure & Application Layers
Network Infrastructure
Service & Version Detection
Identifying active services, protocols, and version numbers to flag outdated or vulnerable software.
Port State Analysis
Comprehensive TCP and UDP port scanning to discover exposed entry points and "ghost" services.
OS Fingerprinting (Where Possible)
Analysing packet responses to determine the underlying operating system and its specific security patches.
Script-Based Auditing (NSE)
Deploying the Nmap Scripting Engine to detect specific high-risk flaws like Heartbleed, EternalBlue, or open mail relays.
Web Application Security
Automated Spidering
Deep-crawling the target to map the entire attack surface, including hidden directories and API endpoints.
Injection Flaw Analysis
Rigorous testing for SQL injection (SQLi), Command Injection, and LDAP manipulation.
Security Header Audit
Verifying the presence and configuration of HSTS, CSP, and X-Frame-Options to ensure browser-level defence.
Broken Access Control
Testing for insecure direct object references (IDOR) and improper authentication persistence.
