Getting Started
Accounts, signing in, and the first-run checklist
Accounts are invite-only
There is no self-service signup. An Owner or Admin of your organisation invites you from Users & Roles, and hands you one-time credentials (your email and a one-time password shown only once at invite time).
Signing in
- Open the app — you land on the Sign in page.
- Enter your email address and click Send login code.
- Check your inbox for a 6-digit one-time code.
- Type the code (digits only) and click Verify & sign in. The button enables once all 6 digits are entered.
- You're taken to the Dashboard.
Clicked the wrong email? Use Use a different email to go back. If the code fails, you'll see an inline error — request a new one by returning to step 1.
First-run checklist
A brand-new organisation has no data yet. To get value quickly:
- Add your first domain — go to Assets → Add Asset, choose type Domain, and enter your root domain (e.g.
example.com). - Turn on data collection — go to Scan Settings → Settings and enable the checks you want (see Scan Settings for what each toggle does). Click Save Settings.
- Run your first scans — click Run Scan Now, run an Asset Discovery first (to find subdomains and IPs), then a Security Scan (to check them).
- Review the results — watch progress in Scan Settings → Scan Runs, then explore the Dashboard, Findings, and Attack Surface pages.
- Optionally, schedule recurring scans in Scan Settings → Schedules so this happens automatically.