Multi-protocol discovery
Active and passive techniques cross-checked so you don't miss devices that hide from one method.
FortLock packages the same scanning techniques the pros use, then writes the report so a human can actually read it. Every feature below ships in the free download.
ARP, mDNS, SSDP, NetBIOS, WS-Discovery — plus a 45,000-entry vendor database. The kind of fingerprinting the enterprise tools charge for.
Active and passive techniques cross-checked so you don't miss devices that hide from one method.
Every MAC address resolves to a real manufacturer name — no more 'Unknown'.
NetBIOS, mDNS, DHCP, reverse DNS — whichever source has the highest confidence wins.
We know what an Echo Dot looks like vs a Sonos vs a Hue bridge. The report calls it out.
Open ports, weak TLS, exposed admin panels, default credentials, router CVEs. Enriched with EPSS so you fix what's actually exploited.
1.2M+ CVEs from NVD, GitHub Advisories, OSV, and Vulners. Multi-source so you see exploit availability, not just severity.
Single-attempt check against the most common router/IoT default credentials. Safe, slow, and disabled by default.
Subdomain discovery, DNSBL listings, SPF/DMARC/DKIM hygiene, public-facing CVE checks for your domains.
SSL Labs–style grading on every TLS endpoint. OWASP-style HTTP header scoring for every web service.
Plain English at the top. Drill-down detail for the technical reader. PDF export. Branded for your business on Pro+.
An executive summary written by FortLock's analysis layer — no jargon, no CVE IDs in the headline.
Letter grade (A–F) per scan plus a 30-scan trend so you know if your network is getting safer or worse.
Print or save the report at any point. Layout collapses to a clean linear PDF, ready to email.
Click any device for a full card: ports, fingerprints, CVEs, MITRE techniques, and recommended fixes.
Start free with on-demand scans. Add scheduled monitoring, authenticated scans, multiple subnets, and API access as you go.
Daily, weekly, or monthly. Get alerted on new devices, new ports, or new critical findings.
Add SSH credentials for read-only on-host package enumeration. Find CVEs that pure network probes miss.
Powered by a bundled local model that runs entirely on your machine. Toggle it off in settings to ship reports without an AI pass — the raw findings still work.
On Pro+, get programmatic access to inventory, alerts, and report exports. Build it into your dashboards.
Scan execution, findings, and the optional AI analysis all run on your device. The AI is a bundled local model that ships inside the desktop app — toggle it on for plain-English summaries, toggle it off for raw findings only. Either way, no findings, no fingerprints, and no traffic ever leave your machine. The Tauri shell enforces an outbound egress allowlist so you can audit every byte.
Cloud-assisted analysis is reserved for the enterprise tier — not yet shipped. When it lands, it will be opt-in, scoped to enterprise SKUs only, and clearly labeled in the UI.
Devices
14
+2
Open ports
38
-4
Risk grade
B+
up
Inventory
ASUS RT-AX88U
192.168.1.1 · Router
MacBook Pro · Ryan
192.168.1.14 · Laptop
iPhone 17 · Ryan
192.168.1.22 · Mobile
HP Color LaserJet
192.168.1.31 · Printer
Samsung TV · Living
192.168.1.46 · Smart TV
Synology DS920+
192.168.1.59 · NAS
Free download. First scan free. About five minutes from install to report.
Curious about pricing? See plans.