Web Security Scanning Platform
Scan your domain from the outside and get the vulnerabilities as a report.
Overview
Web security scanning software scans the internet facing surface of a domain and reports the vulnerabilities it finds. The scan runs against the same points an attacker would reach from the outside.
Sensagraph is a web security scanning platform built by Kaşgar Yazılım. You add your domain, verify that you own it and start a scan.
Sensagraph is agentless. No software is installed on your servers, no code is touched and no configuration is changed in your infrastructure. The scan runs entirely from the public network.
A scan covers five check groups: application vulnerabilities, server configuration, encryption and certificates, technology versions in use, and open ports and services.
When the scan finishes, findings are ranked as critical, high, medium and low. Every finding comes with a plain language explanation and a concrete remediation step. The result is downloaded as a PDF report.
Sensagraph runs in a cloud environment and is used through a browser. A free plan lets you add and scan a single domain.
Benefits
The concrete problems this product solves inside an organisation.
Externally Visible Risk Becomes Clear
Your internet facing surface is scanned the way an attacker would see it.
Starts Without Setup
The first scan runs as soon as domain verification is complete.
Findings Are Prioritised
Critical, high, medium and low are separated. What to fix first becomes obvious.
Remediation Steps Are Given
Each finding states what needs to be done in plain language.
Changes Are Tracked
Scheduled scans report new risks that appear after infrastructure changes.
Reports Can Be Shared
The PDF report goes straight to a manager, a client or an audit team.
Features
Capabilities the product provides.
Web Application Security Test
SQL injection, XSS, CSRF plus authentication and session weaknesses are checked.
Web Server Configuration Analysis
Dangerous HTTP methods, directory listings and missing security headers are detected.
SSL and Certificate Analysis
Expired certificates, weak ciphers and outdated protocol versions are reported.
Technology and Version Detection
Externally visible components are identified and matched against known vulnerability records.
Open Port and Service Scanning
Reachable ports, exposed databases and admin panels are listed.
Email Configuration Analysis
Email security records for the domain are checked and gaps are reported.
Exposed Credential Detection
Leaked credentials and secrets linked to your domain are searched for.
Scheduled Scans
Scans run automatically on a daily, weekly or monthly schedule.
Email and Webhook Alerts
Notifications are sent when a scan finishes and when the result changes.
Report Download and Sharing
Findings are downloaded as a PDF report and shared across teams.
How It Works
Scan Flow
Agentless Scanning Architecture
Use Cases
The areas where the product is used most often.
Pre Release Check
The external surface is scanned before a new version goes live.
Agency and Client Sites
Several client domains are monitored regularly from a single account.
Audit and Compliance Prep
The current security posture is produced as a report before an audit.
Continuous Monitoring
Scheduled scans track changes that appear in the infrastructure over time.
Post Migration Verification
Open ports and configuration of a migrated system are checked on the new server.
Vendor Review
The external security posture of a system you will work with is reviewed.
Who Is It For?
Teams that use the product in their daily work.
Software Development Teams
They check the external surface of the application they build at regular intervals.
Digital Agencies
They monitor the security posture of the client sites they manage from one place.
System and Infrastructure Admins
They audit open ports, certificates and server configuration from the outside.
Information Security Officers
They scan and report the organisation internet facing assets on a schedule.
E-commerce Businesses
They check the external surface of sites that carry payment and customer data.
Independent Developers
A solo developer gets an independent external check for their project.
Modules
The product is built from these modules. You pick the ones you need at deployment.
Domain Management
Domains to be scanned are added and ownership verification is done on this screen.
Scan Engine
Application, server, encryption, technology and network checks run in this module.
Finding Management
Detected findings are listed by severity and reviewed one by one.
Report Output
A PDF report is produced from the scan result, downloaded and shared.
Scheduling
The recurring scan calendar is defined through this module.
Notifications
Email notifications and webhook endpoints are configured here.
Subscription and Usage
Plan, remaining scan allowance and domain count are shown on this screen.
Platform and Integration
Platform
- Runs in a cloud environment
- Accessed through a browser, no installation required
- Agentless scanning, nothing installed on your servers
- No configuration change needed in your infrastructure
- Scan results are stored privately in your account
- Encrypted connection over SSL
Integrations
- Domain verification with a DNS record, a file upload or a meta tag
- Webhook delivery of findings and status to external systems
- Email notifications for scan results and changes
- PDF report export for sharing across teams
Deployment Options
- Cloud subscription, usable immediately
- Free plan covering a single domain
- Higher plans for multiple domains and team use
Delivery Time
Sensagraph is a subscription product that runs in the cloud. It is usable immediately after you sign up and complete domain verification. There is no installation, development or waiting period.