α Aql · Security
Find the weaknesses in your own systems before anyone else does.
Altair runs vulnerability scans across your infrastructure through Agents you deploy on your own network. It tracks every Asset and Vulnerability it finds, and turns each assessment window into a compliance Report.
01 · How it works
Three steps to your first Report
You decide what gets scanned and when. Altair does the scanning, the tracking and the paperwork.
- 01
Deploy an Agent
Run the one-line installer on a machine inside your network, on Linux, macOS, Windows, Docker or Kubernetes. The Agent enrols itself and only ever dials out.
- 02
Declare your Scope
Tell Altair what to cover: subnets, domains or specific Assets. Each Scope entry carries its own Credentials and its own Scan profile.
- 03
Run Assessments
Schedule them once, daily, weekly or monthly. Each Assessment covers your whole Scope, closes on its own and produces one Report.
02 · Features
Everything, on every plan
Assessments, Reports, rescans and the Assistant come with every plan. None of them sits behind a higher tier.
Outbound-only Agents
Agents never accept inbound connections. They talk to Altair over HTTPS and to the systems they scan, nothing else.
Checks that fit the Asset
A lightweight fingerprint prunes each Scan profile to the checks that apply, so a Windows check never fires at a Linux host.
A CMDB that keeps itself
Discovered hosts reconcile into your inventory by MAC address, then hostname, then IP, so one device stays one Asset.
Compliance Reports
Every Assessment ends in a PDF and CSV Report with a full timeline: the window, each scan, every intervention and why it closed.
Targeted rescans
Fixed something? Re-check that one Vulnerability now. Rescans are never limited by your plan.
An Assistant that asks first
Ask about your findings in plain language, or connect your own tools over MCP. The Assistant proposes changes; you confirm them.
03 · Tracking
Every finding, followed until it is fixed
A Vulnerability is one check matching on one service of one Asset. Altair follows it from detection to a verified fix, and reopens it if it comes back.
Lifecycle
Severity
- False positive
- Mark it once and ingestion never reverses it. Unmarking is audited.
- Risk accepted
- Requires a written reason, and lapses when the finding reopens or the next Assessment starts.
04 · Principles
Rules we do not bend
Remediation needs a re-test
A Vulnerability is Remediated only when the same check runs again on the same Asset and comes back clean. A check that did not run proves nothing.
Unreachable is not Remediated
When an Asset drops off the network its findings close as Asset Unreachable, and Reports list them apart from real fixes.
Credentials stay with their Scope
Credentials belong to a Scope entry, not an Agent, and are only ever sent to the Asset being scanned. They are redacted from every piece of evidence.
Your data is only yours
Every query is scoped to your organisation, every action is audited, and API keys act as a named User with that User's current Role.
05 · Pricing
Priced by Assets, never by features
Your plan sets how many Active Assets you expect to cover. That is the only thing it sets. Going over never drops data or hides a finding.
Unreachable Assets never count. Targeted rescans are never limited.
α Aql · 19h 50m 47s
See Altair on your own network
Tell us about your infrastructure and we will set up an evaluation.