Resources

Every web security answer, one click away.

Pentesting explainers, per-check guides, fix guides, tool comparisons, free passive scanners and compliance prep. Written for engineers shipping real products.

FAQ

Resources, answered.

Where should I start if I'm new to web security?
Run a free scan against your live site at /tools/website-security-scan, then read the per-check explainers under /learn for the findings you got. Each explainer links to a step-by-step fix guide under /vulnerabilities, so the path from "what's wrong" to "how to fix it" is two clicks.
Are the free tools really free, or a teaser?
Really free. The scanners at /tools run real checks against your live URL and return the same kind of data the paid product surfaces. No signup needed to run a single tool. Sign up only if you want history, scheduled scans, exports, or the unified passive scan report (18 checks on the free plan, 35+ on paid plans).
What's the difference between /learn and /vulnerabilities?
/learn is the per-check explainer (what the check is, why it matters, how Barrion runs it). /vulnerabilities is the per-finding fix guide (how to actually patch the issue on Nginx, Apache, Node, Next.js and Express). Most learn pages link to the matching fix guide and vice versa.
Do the compliance pages map to specific controls?
Yes. Each compliance page (SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR) lists the control families Barrion's continuous monitoring produces evidence for, plus the PDF and CSV exports you can hand to your auditor.
How fresh are the comparison pages?
We refresh /compare entries when product or pricing details shift on either side. Each comparison is factual and side-by-side: scan type, primary use case, remediation flow, pricing posture, and who the tool is built for. No marketing hand-waving.

Run a free passive scan on your site.

It takes about 60 seconds, needs no credit card and shows real findings from your live app, each with a fix.

A scan shows the surface. A pentest tests what gets in.

Passive scan

  • Reads what your app already exposes
  • Never logs in or submits a form
  • Cannot confirm what is exploitable

Active AI pentest

  • Tests your app the way an attacker would
  • Chains requests to confirm real exploits
  • Replays findings against your live app
  • Runs on a schedule or on demand, retests free

Probes for

  • SQL injection
  • Broken access control
  • IDOR
  • SSRF
  • Business-logic abuse

How AI pentesting works

Paid in credits. Free retests of found issues, and expert review from Standard up.