← Back to Website
VAPTOR VAPTOR AI
SALES PROSPECTUS · 2026
⚡ AI-Powered Penetration Testing Platform

VAPTOR
AI Pentest GPT

Autonomous vulnerability assessment & penetration testing — from host discovery to exploit verification — in a single, 100% on-premise appliance. Enterprise-grade AI security for SMBs.

🛡
Enterprise-Grade Security
ETSI EN 304 223 Aligned
Fully Automated VAPT
Zero manual effort required
🔒
100% On-Premise
Data never leaves your network
VAPTOR Watchdog Appliance
CONFIDENTIAL — FOR AUTHORISED DISTRIBUTION ONLY vaptgpt.com · cyberwatchdogs.co.za 1 / 8
VAPTORAI
01 — BUSINESS CASE
The Business Case

Security testing hasn’t kept pace with risk

65,535
Ports Scanned
TCP & UDP per device
16+
AI Modules
Full pipeline
100%
On-Premise
No cloud exposure
6
Phase Pipeline
Discovery to report

Most organizations validate their security posture the way they did a decade ago: an annual penetration test scoped weeks in advance, delivered as a static PDF months after testing closed. In between, networks change, new services go live, and freshly disclosed CVEs sit unverified — leaving long, unmonitored windows of exposure.

Skilled penetration testers are expensive and difficult to schedule on demand. Compliance frameworks are moving from “show us a report” to “show us continuous assurance.” Stretching a lean security team to keep up with both is no longer realistic.

~40%
Orgs test only once or twice a year
Industry surveys
54.8d
Avg. time to remediate critical vuln
Edgescan 2025
45.4%
Vulns still unpatched after 12 months
Edgescan 2025
The VAPTOR AI Solution

A self-contained appliance and AI-driven testing platform that runs the same playbook a professional penetration tester would — discovery, vulnerability scanning, exploit verification, and AI-prioritized risk analysis — on whatever schedule your organization needs. Results land in a live dashboard and an evidence-ready report your team and auditors can act on immediately.

Always-On Assurance

Scheduled scans run daily, weekly, or monthly so new exposures are caught between audits — not at the next one.

AI-Prioritized Findings

Every finding is enriched and explained in plain language so your team fixes what matters first.

Audit-Ready Evidence

Executive summaries, technical detail, and compliance mappings generated automatically, every run.

CONFIDENTIALvaptgpt.com2 / 8
VAPTORAI
02 — PLATFORM CAPABILITIES
Platform Capabilities

Everything you need to secure your network

VAPTOR automates the full penetration testing lifecycle — no team of experts required.

🔍

Automated Vulnerability Scanning

Full TCP/UDP scanning across all 65,535 ports with OS detection, service fingerprinting, and banner grabbing using Nmap, Masscan, and Nuclei.

🤖

AI-Assisted Reporting

Natural-language remediation guidance, risk narrative generation, and severity contextualisation powered by multi-provider AI.

📋

Compliance Mapping

Automatically maps findings to PCI DSS, HIPAA, NIST CSF, and ISO 27001 — generating audit-ready evidence packages every run.

🛡

Exploit Verification

Safe, controlled exploit confirmation with CVE-to-exploit mapping via NVD API, Metasploit integration, and real evidence capture.

🔒

100% On-Premise

Data never leaves your network. No cloud dependency, no third-party exposure — full data sovereignty guaranteed.

📄

Audit-Ready Reports

Tamper-evident PDF, CSV, HTML, and JSON reports with PCAP archives — demonstrable proof for stakeholders and auditors.

Module Ecosystem
VAPTORSCOUTVAPTORRECONVAPTORWEBVAPTORSQLVAPTORMSFVAPTORFWVAPTORSHARKVAPTORAIVAPTORAPI + 7 in development
Industry Data
$4.44M

Global average cost of a data breach (2025) — IBM Cost of a Data Breach Report

48.2k

New CVEs published in 2025 — ~133 new vulnerabilities daily. CVE.org / Jerry Gamblin 2025

20%

Breaches via vulnerability exploitation in 2025 — overtaking phishing as #1 vector. Verizon DBIR 2025

Security Architecture

PBKDF2-SHA256 at 260,000 iterations — no plaintext credentials, ever

JWT-secured sessions with server-side permission checks on every request

Hardware-bound licensing — device identity permanently bound at registration

Role-based access control — Admin, Operator, Analyst, Client

Parameterized queries throughout — no string-built SQL anywhere

CONFIDENTIALvaptgpt.com3 / 8
VAPTORAI
03 — HOW IT WORKS
How It Works

From discovery to decision — automatically

Every VAPTOR AI engagement runs through the same disciplined six-phase pipeline a senior penetration tester would follow — without needing to schedule one.

1

Discovery

Network and port scanning maps every live host and service in scope using Nmap and Masscan across all 65,535 ports.

2

Scouting

Deep reconnaissance enumerates technology stacks, web applications, exposed services, and open intelligence sources.

3

Pentest

Web, SQL, and exploit-verification testing with OWASP ZAP, SQLMap, and Metasploit confirms what is actually exploitable.

4

Assessment

AI enrichment cross-references findings against live CVE and threat intelligence feeds, scoring risk in plain language.

5

Report

Executive summary and technical detail are generated automatically — re-runnable, never hand-edited, always audit-ready.

6

Complete

Findings land in the dashboard with remediation tracking, ready for your team, board, and auditors.

Watchdog CP
Watchdog CP — scan orchestration and real-time phase monitoring.
RBAC Settings
RBAC Settings — role-based permission matrix per user role.
Deployment: Plug It In. It Starts Testing.

VAPTOR AI ships as a self-contained hardware appliance — the VAPTOR Watchdog — that connects directly to your network. No lengthy install, no agents, no cloud dependency. Zero-touch deployment, hardware-bound identity, and multi-organisation support for MSSPs.

CONFIDENTIALvaptgpt.com4 / 8
VAPTORAI
04 — PLATFORM INTERFACE
Platform Interface

Built for security operators

A live dashboard surfaces active scans, vulnerabilities, verified exploits, and aggregate risk scores in real time.

Executive Dashboard
Executive Dashboard — aggregate risk score, vulnerability counts, and compliance status at a glance.
Compliance Certificate
Compliance Certificate — tamper-evident, dated compliance certificate per device for auditors.
Certificate Portal
Certificate Portal — generate and download certificates per device from the portal.
Vulnerability List
Vulnerability List — full finding inventory with severity, CVE reference, and remediation status.
Control Panel
Control Panel — centralised fleet management for MSSPs tracking every device, licence, scan, and update from one place.
CONFIDENTIALvaptgpt.com5 / 8
VAPTORAI
05 — EDITIONS & PRICING
Editions

A tier for every stage of your security program

Every tier includes the VAPTOR Watchdog appliance, the full scan pipeline, AI-driven risk analysis, and reporting.

Starter
For small teams getting started
Adhoc Support
VAPTOR Watchdog appliance
Full 6-phase scan pipeline
AI-driven risk analysis
PDF, CSV, JSON, HTML reports
Compliance mapping (PCI, HIPAA, NIST, ISO)
20
Scan Assets
Professional
Most popular for growing orgs
SLA Support
Everything in Starter
SLA-backed support
Scheduled scan automation
Multi-user RBAC (4 roles)
Executive reporting suite
≤100
Scan Assets
Enterprise
For large networks & MSSPs
SLA + Management
Everything in Professional
Dedicated device management
Multi-organisation support
MSSP fleet management portal
Priority SLA & onboarding
>100
Scan Assets
Compliance Frameworks Supported
PCI DSS HIPAA NIST CSF ISO 27001 ETSI EN 304 223

Every scan automatically maps findings to the relevant framework controls and generates an evidence package auditors can use immediately.

ROI in Plain Terms

A traditional pentest engagement runs roughly $10,000–$35,000 and covers a single point in time, once or twice a year. VAPTOR AI runs the same discovery-to-exploit-verification pipeline on a schedule you set, so the gap between “tested” and “today” stops being measured in months.

CONFIDENTIALvaptgpt.com6 / 8
VAPTORAI
06 — SECURITY & COMPLIANCE
Security & Access Control

Built to the standard it’s testing for

A tool that probes your network for weaknesses has to be held to a higher security standard than the systems it tests.

No plaintext credentials, ever. Passwords hashed with PBKDF2-SHA256 at 260,000 iterations with a unique random salt per user.

Role-based access control. Four roles — Admin, Operator, Analyst, Client — govern exactly who can launch scans, run exploits, view reports, or manage settings.

JWT-secured web access with short-lived, signed sessions and server-side permission checks on every request.

TLS-verified, audited API calls. Every outbound integration is encrypted and logged; sensitive fields are automatically redacted.

Credentials are never harvested. Network-observed credentials are masked, hashed, and never stored or displayed in raw form.

Hardware-bound licensing. A device’s license key is permanently bound to its hardware — a lost key cannot be reused elsewhere.

Parameterized everything. All database access uses parameterized queries — no string-built SQL anywhere in the platform.

Certificate Portal
Certificate Portal — generate and download compliance certificates per device.
Vulnerability Detail
Vulnerability Detail — CVE cross-referenced findings with CVSS scores and AI remediation steps.
Regulatory Compliance

VAPTOR automatically maps vulnerabilities to PCI DSS, HIPAA, NIST CSF, ISO 27001, and ETSI EN 304 223 — generating evidence packages auditors can use immediately. Every scan run produces an executive summary, technical detail, and compliance mapping without any manual effort.

CONFIDENTIALvaptgpt.com7 / 8
VAPTOR VAPTOR AI
VAPTOR AI PENTEST GPT · 2026
VAPTOR
Ready to get started?

Let us show you VAPTOR AI in action

Book a demo, request a proof-of-concept deployment, or download the full technical whitepaper to share with your security and compliance teams.

Request a Demo
Download Whitepaper PDF
Website

vaptgpt.com

Provider

Cyber Watchdogs
cyberwatchdogs.co.za

Email

sales@vaptgpt.com

CONFIDENTIAL — FOR AUTHORISED DISTRIBUTION ONLY vaptgpt.com · cyberwatchdogs.co.za 8 / 8