Dynamic Application Security Testing built for evidence, not guesses.
Nyxeara is a DAST platform for live web applications and APIs. It discovers attack surface, runs controlled security tests, verifies findings with cryptographic evidence integrity, and supports investigation, automation, and CI/CD delivery.
- DAST engine — 4 scan profiles, configurable crawling, ZAP integration
- 22 check families — SQLi (6 DBMS), XSS, SSRF, LFI, RCE, auth, cloud, GraphQL, modern web, DNS, compliance, and more
- WAF engine — fingerprint, evade, circuit break, generate rules
- OAST — out-of-band callbacks for blind SSRF, XXE, RCE verification
- Evidence & verification — SHA-256 integrity, 6-state lifecycle, redaction pipeline
- Workflow automation — 37+ node types, approvals, checkpoints
- AI analysis — evidence-grounded copilot, STRiX agent with 6 plugin tools
- CLI, API, webhooks — device auth, 26 route groups, HMAC-signed events
- CI/CD — SARIF 2.1.0, severity gates, baseline diff, GitHub Code Scanning
- 22 external tool integrations — nmap, gobuster, wpscan, sqlmap, nuclei, amass, and more