How it works

From a domain to a clear next action.

Zoltra connects to what you already run and does the security work for you — verified, reviewed, and delivered to your team.

Three steps to your first finding

You stay in control of every domain. Add one or add ten, and watch them all on a single surface map.

1

Connect your app

Add your domain and, if you want fix PRs, connect its GitHub repository.

2

Zoltra investigates

Zoltra maps the public surface, follows suspicious paths, and confirms what is actually vulnerable.

3

Review the fix PR

Zoltra prepares the repair on a separate branch and opens a pull request. After you merge and deploy it, Zoltra checks the live app again.

The full picture

The short version gets you started. This is the deeper view for when you want to see how the work fits together.

Point it at one domain. Zoltra takes it from there.

Setup is a DNS record. Everything after that is Zoltra's job.

  1. Verify a domain you ownOne DNS TXT record and setup is done. It usually resolves in a few minutes._zoltra-verify.nexdojo.dev TXT "zoltra-site-verification=9f3c…"
  2. Zoltra maps the groundSubdomains, endpoints, services, certificates: everything that domain puts in front of the internet. Then it keeps looking, because your surface changes every time you ship.
  3. Review the fix, then prove itConfirmed findings can include a pull request with the proposed repair. You review and merge it; Zoltra verifies the live result after deployment.

What lands on day one

  • A map of everything that domain exposes to the internet.
  • Findings ranked by what an outside agent could actually do with them.
  • The evidence behind every one, so you can check the work yourself.
  • A reviewable fix PR for confirmed code-level vulnerabilities when GitHub is connected.
  • A retest that either closes the finding or tells you it is still open.

All of it is checkable in the dashboard. A guardian that will not show its work is not a guardian.

What you get

Not a list of problems. A decision, and somewhere to act on it.

A scanner hands you a CSV and wishes you luck. Zoltra keeps a live record of every finding on the domains you've verified: what it observed, how severe it is, whether it is still open. Each one gets routed to wherever your team already is.

Zoltra in the loop

Ask it a question in the channel you're already in. It runs the work in the open. You can watch it decide what to check, notice what changed since last time, and refuse to repeat work it has already done. Then it tells you what it found, and delivers the weekly summary to your team without being asked.

Findings, and the channels they're delivered to

Every finding carries its severity, its status, and the domain it was found on, and it reaches your team in the channel they already use.

What it found

Every finding leads with a plain-English title, never a scanner's rule name. The technical name stays in the record below, where you can check it yourself.

Weekly reports delivered automatically

Nobody has to ask for one. It arrives on schedule with what is new, what got fixed, and what failed.