Professional VAPT platform for East African businesses — web, API, network, SSL scanning with AI-powered remediation. Built by Heptadev, Kigali.
Click each phase to explore what Heptasec does under the hood
OSINT gathering, DNS enumeration, subdomain discovery via certificate transparency logs, WHOIS analysis, and attack surface mapping.
Exposed admin panels, forgotten subdomains, leaked credentials
CVSS score, evidence, and AI remediation in one view
The login endpoint is vulnerable to SQL injection via the username parameter. Payload ' OR SLEEP(5)-- confirmed a 5-second delay — unauthenticated database access possible.
Use parameterized queries: prisma.user.findUnique({ where: { email } }). Under Rwanda Law No. 60/2018 Article 14, failure to implement basic injection prevention is considered negligence.
Hover a card to simulate a live scan
Rwanda Law No. 60/2018 mandates written authorization before any security testing. Heptasec enforces this at code level — no authorization document, no scan.
MTN MoMo accepted · Stripe for international customers
Join authorized security professionals across East Africa. First scan free — no credit card required.