VulWall Logo
VulWall
  • Pricing
  • FAQ
  • Knowledge Base
  • Get Started

Frequently Asked Questions

Last updated: Feb 2026

Getting Started

How long does the first scan take?

Most scans complete in under an hour. You'll get results immediately, no waiting days for a report.

Do I need technical knowledge to use this?

No. VulWall is built for teams without security expertise. Every finding comes with a plain-English explanation and step-by-step fix.

What do I need to get started?

Just your domain name. No agents to install, no code changes, no access credentials needed.

What exactly do you check?

We scan for the security issues that matter most: SSL/TLS configuration, exposed ports, security headers, subdomain vulnerabilities, known CVEs, and misconfigurations. Think of it as seeing your infrastructure the way an attacker would.

Pricing & Plans

What's included in the free plan?

One domain, monthly scans, and a summary report. Enough to see if VulWall is useful for you.

When should I upgrade to Pro?

When you need continuous monitoring, multiple domains, the Security Certificate for customers, or AI-powered remediation guidance. Most teams upgrade when a customer, investor, or a compliance audit asks about security.

Can I cancel anytime?

Yes. No contracts, no cancellation fees. Cancel from your dashboard whenever you want.

Security & Compliance

Is this enough for SOC 2 or ISO 27001?

VulWall provides continuous vulnerability monitoring and audit-ready reports, which directly support the technical vulnerability management requirements in SOC 2, ISO 27001, and NIS2. We're not a compliance certification ourselves, but we give you the evidence and documentation that auditors look for. Many teams use VulWall alongside their compliance program.

Does VulWall help with NIS2 compliance?

NIS2 requires organisations to implement continuous vulnerability monitoring, incident reporting, and risk management for their infrastructure. VulWall covers the technical vulnerability monitoring part: automated scanning, audit-ready reports, and a Security Certificate that documents your security posture over time. It won't cover everything NIS2 requires (policies, governance, supply chain risk), but it gives you the continuous monitoring and documentation that auditors will ask for first.

Can I share the Certificate with customers?

Yes, that's exactly what it's for. Your Certificate is a shareable link that shows your security posture. Send it to procurement, include it in sales decks, or link it from your website.

How does the Certificate help close deals?

When a customer, auditor, or partner asks about your security, send them your Certificate instead of scrambling. It shows what you've tested, what you've fixed, and that you monitor continuously. One link, always current.

Do you store my scan results?

Yes, securely encrypted in the EU. You own your data and can delete it anytime. See our Privacy Policy for details.

Comparisons

How does VulWall compare to Qualys or Nessus?

Qualys and Nessus are powerful tools built for security teams with dedicated staff to configure, run, and interpret results. VulWall is built for teams without that expertise: zero configuration, plain-English findings, AI-powered remediation guidance, and a shareable Security Certificate. If you have a full-time security engineer, those tools are great. If you don't, VulWall gets you covered without the learning curve.

How is VulWall different from Snyk?

Different layers of the stack. Snyk scans your source code, dependencies, and containers inside your CI pipeline. VulWall scans what's visible from the outside: your live infrastructure, exposed services, SSL configuration, security headers, and email security. Snyk catches vulnerable packages before you deploy. VulWall catches what's exposed after you deploy. Many teams use both.

How is this different from free tools like Nessus or OWASP ZAP?

Those tools require security expertise to configure, run, and interpret. VulWall is automated, continuous, and explains everything in plain English. You get actionable results, not raw vulnerability dumps.

Can this replace hiring a security person?

For most companies without dedicated security staff, yes, at least for infrastructure vulnerability management. VulWall handles continuous monitoring, AI-powered remediation, and audit-ready reports. For business logic testing and complex security architecture, you'll eventually want human expertise, but VulWall covers the continuous baseline.

Why not just do annual pentests?

Annual pentests are valuable for business logic and application-level testing. But the majority of a typical pentest covers infrastructure checks that can be automated and run continuously. VulWall handles that part for you. When you do commission a pentest, your firm can skip the infrastructure scanning and focus on business logic testing, significantly reducing the scope and cost of the engagement.

Common Concerns

What if my score is bad?

That's actually good: you found issues before a customer or attacker did. We prioritize findings and show you exactly what to fix first. Most teams improve their score within a week.

Will this slow down my website?

Our scans generate minimal traffic comparable to normal web browsing. There is no meaningful performance impact on your servers or anything your users would notice.

What if I disagree with a finding?

You can mark findings as false positives or accepted risks. We know not every finding applies to every situation. Your Certificate reflects your actual security decisions, not just raw scan output.

What if I need help fixing something?

Pro users get AI-powered remediation guidance with step-by-step fixes. If you need hands-on help, someone to actually resolve issues for you, contact us for dedicated support options.

VulWall Logo
VulWall

Continuous security monitoring. No security team required.

Product

  • Pricing
  • FAQ
  • Security Certificates
  • Knowledge Base
  • Roadmap

Company

  • About
  • Contact

Legal

  • Privacy Policy
  • Terms of Service

© 2026 VulWall. Continuous security monitoring. No security team required.

Built in the EU 🇪🇺