AI Architecture & Dependency Intelligence

Understand your entire technology ecosystem in a single graph.

Map dependencies, identify blast radius, understand attack paths, and gain complete visibility into modern software systems.

No credit card required · Workspace-isolated · Built for the enterprise

APIAuthDBCoreQueueAI AgentSecret

See a cross-service scan

Watch VulnGraph trace an attack path across services — the class of finding single-repo scanners miss.

~/my-microservices

…or run it yourself, right now:

Sample architecture

order-servicekafka: order-eventspayment-service · no authpayments DB
↳ also consumed byshipping-service · runs shellwebhook-service · calls dynamic URL
Real cross-service taint engine · no signup

Relationship intelligence, not a list of alerts.

VulnGraph turns scattered repositories and infrastructure into one connected model you can reason about.

Architecture Intelligence

Automatically discover services, APIs, databases, queues, cloud resources and AI agents — then see how they truly connect in one living graph.

Dependency Mapping

Trace every dependency across repositories, manifests and infrastructure. Understand what depends on what before you change anything.

Blast Radius Analysis

Quantify what breaks when a system fails. Identify single points of failure and the downstream services they would take down.

AI Architecture Review

Get an explainable review grounded strictly in discovered data — never hallucinated. Executive summaries, risks and prioritized actions.

Explainable Risk Scores

Architecture, Security, AI Exposure and Blast Radius scores — each factor shows the raw value, points and the reason it mattered.

Findings Engine

Concrete, evidence-backed findings: public surface near sensitive data, hardcoded secrets, excessive blast radius, AI access risk and more.

Built for the people who own the risk.

CISOs & Security Teams

See where public exposure meets sensitive data, where secrets leak, and where AI agents can reach what they shouldn't.

CTOs & VP Engineering

Understand architecture health and technical debt across the org, and where risk concentrates before it becomes an incident.

Enterprise Architecture

Maintain an always-current map of systems and dependencies instead of stale diagrams that rot the day they're drawn.

PE / VC & Technical Due Diligence

Assess a target's real architecture, dependency risk and blast radius in days, with evidence — not slideware.

Simple, transparent pricing.

Start free. Scale when you're ready.

Starter

$0/ forever

For individuals exploring a single codebase.

  • 1 workspace
  • Up to 3 repositories
  • Graph & blast radius
  • Deterministic AI review
Most popular

Team

$499/ month

For engineering orgs mapping their estate.

  • Unlimited repositories
  • Workspace roles & invites
  • LLM-powered AI review
  • Executive reporting & export
  • Audit logging

Enterprise

Custom

For regulated and large organizations.

  • SSO & SCIM
  • Private model providers
  • On-prem / VPC deployment
  • Custom detectors & rules
  • Dedicated support

Compare all plans & features →

Frequently asked questions

Is VulnGraph just another vulnerability scanner?+

No. VulnGraph is graph-based relationship intelligence. Rather than listing CVEs, it maps how your systems connect and where risk propagates — blast radius, attack paths, dependency concentration and AI access.

Does the AI invent findings?+

Never. The AI review is grounded strictly in discovered graph data. When no model is configured, a deterministic review is produced directly from the graph. No systems or findings are fabricated, and confidence is always stated.

How is my data isolated?+

Every entity is workspace-scoped and protected by Postgres Row Level Security. No user can read or write another tenant's data, enforced at the database layer.

What can it scan?+

Public GitHub repositories today — package.json, requirements.txt, pyproject.toml, Dockerfiles, docker-compose, Terraform, Kubernetes manifests, GitHub Actions, plus source-level API, database, secret, external-service and AI-agent references.

See your architecture, mapped.

Request a demo and we'll walk you through mapping your dependencies, quantifying blast radius, and producing an executive-ready review.

  • Live graph of your real systems
  • Blast radius & single points of failure
  • Explainable risk scores & findings