Neutral benchmark

Your scanner. Our oracle.
No vendor lock-in.

VulnGym is not a scanner — it is the exam. You bring any tool that exports findings; we score it against planted vulnerabilities and safe decoys.

Who buys Pro

Scanner vendors

Investor-ready metrics: verified recall, decoy precision, versioned truth.

Enterprise AppSec

Compare tools in an RFI with the same blind rules — not vendor demos.

MSSP / consultancies

Standardize team training and quarterly regression on Rings 1–3.

How a benchmark run works

  1. Reseed the lab Reset SQLite, sessions, and rotating victim identities. Pro customers use a dedicated X-VulnGym-Key.
  2. Scan blind Point your product at the lab URL with attacker credentials only (e.g. Alice). Do not feed truth.json into the scanner.
  3. Export findings JSON array or { "findings": [...] } — any schema; our mapper aligns to ground truth.
  4. Score & report Run the open scorer locally or receive a Vendor Score Report v1 (Pro). Attach to security reviews or marketing (opt-in).

What you get that DVWA doesn’t

Typical vulnerable appVulnGym
Authenticated API chainsRareCore
Versioned ground truthNotruth.json
False-positive decoysNo6+ per ring
Anti-memorizationStaticReseed + rotating victim
CI regression gateManualTemplates + baseline

Deliverables

Sample report

See what a Pro run looks like on paper.

View sample JSON

Technical docs

Evaluation rules and CI integration live in the public repo.

BENCHMARK.md

Founding partner (5 slots) Contact sales See pricing