Vulnerability assessments and pen test services
A-LIGN can perform both authenticated and unauthenticated scans for both on-prem and cloud environments. A-LIGN can also perform scheduled continuous vulnerability scanning.
Contact usVulnerability scanning services
We will provide a detailed report that outlines the validated vulnerabilities present within your organization, as well as risk rankings and recommendations for remediation of listed vulnerabilities.
Penetration testing
Vulnerability scans identify known weaknesses from a database. Penetration testing reveals how an attacker actually moves through your environment.
A-LIGN by the numbers
Why security leaders trust A-LIGN
Support for your compliance journey
From guides to whitepapers, we've got the resources to move your compliance program forward.
View resourcesFrequently asked questions
What is the purpose of a vulnerability scan?
A vulnerability assessment checks an organization’s network and systems for any known vulnerabilities against a database of vulnerability information. At the completion of the scan, the organization obtains a report that outlines their risk exposure.
What types of vulnerability scans exist?
Though vulnerability scans have two methods, the type of scans that exist typically fall into one of three categories: Full scan – As the name implies, a full scan is a thorough vulnerability scan that leverages its database of known vulnerabilities to look for any existing vulnerabilities across an organization’s network and systems. This can also be referred to as a “deep scan.” Quick scan – Also known as a “discovery scan” or a “stealth scan,” this type of vulnerability scan is meant to elevate awareness of the type of vulnerabilities that could be possible based on the network devices and system applications that exist. Compliance scan – This type of vulnerability scan is leveraged primarily as a means to audit an organization’s security as it relates to compliance regulations.
Can a penetration test and vulnerability scan be paired together?
A penetration test may not list or confirm every vulnerability in the environment, but a vulnerability scan will scan all systems looking for signatures that match known vulnerabilities that may (or may not) be able to be penetrated. This approach enables an organization to enhance its security posture with a more complete picture of the threat surface.




