Internal and external vulnerability assessments.

One self-managed scanning portal for internal and external vulnerability assessment, mapped to nearly every major framework, with our support team on hand to help you troubleshoot.

Internal + External
Scanning under one portal
Credentialed
Authenticated deep scans
Framework-mapped
PCI · HIPAA · SOC 2 · NIST · ISO +
Self-managed
Support team on hand to troubleshoot
Vulnerability Assessment Capabilities

Everything a modern assessment program needs, in one module.

Discovery, internal and external scanning, credentialed depth, risk-based prioritization, and audit-ready reporting, all through the same CloneGuard portal.

Asset Discovery & Inventory

The portal continuously maps hosts, services, and applications so your scope stays accurate as environments drift.

External Network Scanning

Cloud-based scanners evaluate your internet-facing perimeter with no software to install and no appliance to babysit.

Internal Network Scanning

A lightweight physical or virtual scanning server inside your network covers VLANs, data centers, and lab environments.

Credentialed & Uncredentialed

Run authenticated deep scans for accurate patch-level detection, or unauthenticated scans to see what an attacker sees.

Risk-Based Prioritization

Findings are scored on severity, exploitability, and business impact so remediation starts with what actually matters.

Audit-Ready Reporting

Executive summaries, technical detail, remediation reports, and compliance-mapped exports are one click away in the same portal.

The CloneGuard Scanning Portal

One console for every scan, every finding, every report.

Vulnerability Assessment is one module inside CloneGuard. Launch scans, review prioritized results, export compliance reports, and rescan after remediation, all from the same portal your PCI ASV scans run in.

Clone Systems
7
CL
Security Overview

Your posture, what changed, and what to do next.

Security Posture
B+
342 open findings
High8
Medium47
Compliance
Passing
PCI DSS 4.0.1 ready
Passed 90d128
Failed 90d6
What's New
+23
since last scan
New KEVs 7d3
Scans 30d42
Next Scan
Tomorrow
weekly · 02:00 UTC
Running2
IPs1,284
Risk Over Time
-38% · 90 days
90450
JFMAMJJASOND
Clone Guard® Security Scanning  |  © 1998–2026 Clone Systems, Inc. All rights reserved

External Vulnerability Scanning

Cloud-based scanners continuously evaluate your perimeter, identifying and reporting public, internet-facing vulnerabilities with no software installation or deployment overhead.

  • Rapid setup, typically live in a day
  • Cloud-based scanning infrastructure
  • No software installation required
  • Continuous perimeter coverage

Internal Vulnerability Scanning

Internal scanning uses a lightweight security scanning server deployed inside your network, with physical and virtual options including VMware, Hyper-V, VirtualBox, and Citrix XEN. Run full credentialed or partial uncredentialed scans against your assets.

  • Physical or virtual appliance options
  • Full credentialed authenticated scans
  • Partial uncredentialed scans
  • Segmented VLANs, data centers, and labs covered
How Vulnerability Assessment Works

From asset discovery to verified fix, in five steps.

A predictable model your team runs independently, with support a message away whenever you need help.

01

Discovery

The portal maps your assets across networks, cloud accounts, and on-prem hosts so nothing in scope is missed.

02

Scanning

Cloud-based external scanners and internal appliances run credentialed or uncredentialed assessments on your schedule.

03

Prioritization

Every finding is scored by severity, exploitability, and asset criticality so remediation effort goes where it matters.

04

Reporting

Dashboards and audit-ready exports translate findings for engineering, leadership, and auditors in the same portal.

05

Rescan & Verify

Rescan on demand after remediation to confirm issues are closed and track improvement over time.

Compliance Coverage

Mapped to nearly every framework you report against.

Our findings are pre-mapped to the controls your auditors care about, so you export the evidence you need without translating scanner output into control language yourself.

Need help scoping which frameworks apply to your environment? A senior specialist can walk you through it.

PCI DSS 4.0.1
Req 11.3.1 / 11.3.2
HIPAA
Security Rule §164.308
SOC 2
CC7.1 · Vulnerability Mgmt
NIST 800-53
RA-5 · SI-2
NIST CSF
ID.RA · PR.IP · DE.CM
ISO 27001
A.8.8 · A.12.6.1
CIS Controls
Control 7 · CVM
GLBA
Safeguards Rule
FISMA
NIST 800-53 Moderate
CMMC
Level 2 · RA.L2-3.11
GDPR
Art. 32 · Security
State privacy laws
CCPA · CPRA · more
Why Vulnerability Assessment

Better visibility, focused remediation, cleaner audits.

One Portal, Full Coverage

Internal and external scanning, asset inventory, findings, and reports live in one self-managed console.

Focus Remediation Effort

Risk scoring and business-impact context tell your team what to patch this week versus what can wait.

Evidence Auditors Accept

Framework-mapped exports and rescan history make audit prep a download, not a fire drill.

Continuous Improvement

Trend views measure how quickly you close findings and how your posture is changing month over month.

Who Runs Vulnerability Assessment

Built for teams that need continuous visibility, not point-in-time reports.

Mid-Market & Enterprise IT Teams

Standardize internal and external scanning across offices, data centers, and cloud accounts on a single platform.

Regulated Financial & Payment Environments

Meet PCI DSS 4.0.1 quarterly internal and external scanning requirements with evidence built for auditors.

Healthcare & HIPAA-Regulated Businesses

Continuous scanning of clinical systems, back office, and cloud workloads, with HIPAA-aligned reporting.

E-Commerce & Cloud-Native Operations

Track exposure across web frontends, APIs, cloud infrastructure, and workforce endpoints as they change.

New · AI Add-On

An AI assistant that turns scan output into a remediation plan.

Add the Clone Systems AI assistant to your Vulnerability Assessment module and stop reading scanner output line by line. It explains what each finding means, groups related issues, and hands your team a ranked plan to fix first.

  • Plain-English findings. Every vulnerability is rewritten in language engineers and non-engineers can act on together.
  • Grouped remediation. Related findings across hosts collapse into one work item so patching one thing closes many alerts.
  • Risk-ranked priority. Exploitability, asset value, and framework impact combine into a single, defensible priority order.
  • Auditor-ready summaries. Draft executive and compliance-mapped narratives you can edit and export from the portal.
CloneGuard AI Assistanton shift
What should we fix first from last night's internal scan?
412 findings collapsed into 27 remediation items. Top priority is an unpatched OpenSSH release on 14 production hosts, exploitable pre-auth and in-scope for PCI Requirement 6.3.3.
Severity: 9.4Hosts: 14PCI 6.3.3
Recommended Plan
Patch OpenSSH to the fixed release on the 14 hosts, then rescan the internal segment. Want me to draft the change ticket and queue the rescan for tonight?
READY WHEN YOU ARE

Continuous scanning, live in days, not months.

Scope your environment with a senior specialist, see the CloneGuard scanning portal running against real assets, and get a plan for standing up continuous internal and external assessment.

  • Internal and external scanning under one portal
  • Framework-mapped reporting for PCI, HIPAA, SOC 2, and NIST
  • Credentialed and uncredentialed scan options
  • Support team available to help you troubleshoot
TALK TO OUR SCANNING TEAM

Scope your vulnerability assessment

Tell us about your environment and what you want assessed. A senior specialist will get back to you. All fields required.

No spam, ever.

Vulnerability Assessment FAQ

Vulnerability assessment questions, answered.

Everything you need to know about running internal and external vulnerability assessments with Clone Systems. Still stuck? Talk to us.