

VulScan
By RapidFire Tools (A Kaseya Company)
Implementation of VulScan is designed to be completed in a single afternoon. The process begins with the deployment of a 'vulnerability scanner appliance' (a virtual machine) into the target network environment. Users can choose between Hyper-V, VMware, or Docker images. Once the appliance is active, it automatically checks in with the VulScan cloud portal. The next step involves configuring 'Scan Tasks' where the administrator defines the IP ranges, ports, and scan frequency. For remote devices, the lightweight discovery agent is deployed via an RMM tool or Group Policy. Most users can transition from account setup to their first full network report within 24 to 48 hours. The wizard-driven interface guides the user through connecting their PSA tools for automated ticketing right from the start.
VulScan offers extensive customization at both the scan and reporting levels. Administrators can create custom scan profiles to target specific IP ranges, TCP/UDP ports, or even individual hostnames. For organizations with specific compliance needs, the system allows for the filtering of results based on CVSS scores, vulnerability age, or device tags. Reporting can be customized with company logos and specific sections can be toggled on or off to suit different audiences (e.g., a high-level summary for executives vs. a detailed technical report for engineers). Users can also define custom 'Noise Management' rules to ignore specific vulnerabilities that are known to be low risk or handled by other controls, ensuring that dashboards remain focused on critical issues.
VulScan is noted for its transparent, fixed-price model which significantly reduces hidden costs. However, there are a few potential additional costs to consider. The 'Portable Vulnerability Scanner' (PVS) is typically an add-on physical hardware or specialized software license for mobile technicians. While the core subscription includes unlimited assets, certain advanced integrations with third-party tools outside the Kaseya ecosystem may require specialized connectors. Professional services for 'white-glove' setup or custom implementation consulting are also available for a fee. Aside from these, there are no hidden 'per-asset' fees or charges for additional data storage or report generation, which are standard in many other platforms.
Training is a core part of the VulScan onboarding experience. Every new subscriber has access to a dedicated 'VulScan Kickoff' training session, which can be scheduled via Calendly with a product specialist. RapidFire Tools also provides an extensive online documentation portal containing step-by-step guides, video tutorials, and technical whitepapers. For ongoing education, the company hosts monthly 'Deep Dive' webinars covering advanced topics like authenticated scanning and PSA workflow optimization. Additionally, users can access the 'Kaseya University' learning management system, which offers structured certification paths for security administrators and MSP technicians looking to master the full IT Complete platform.
VulScan is built on a highly secure, cloud-native architecture managed by Kaseya. All data transmitted between local scanner appliances and the cloud portal is encrypted using TLS 1.2 or higher. The cloud portal itself is hosted in Tier-III data centers that comply with ISO 27001 and SOC 2 standards. Multi-Factor Authentication (MFA) is mandatory for all administrative accounts to prevent unauthorized access. VulScan does not store sensitive credentials; instead, it uses secure tokens or encrypted local vaults within the scanner appliances for authenticated scans. Regular third-party penetration tests are conducted on the platform to ensure that the management infrastructure remains resilient against evolving cyber threats.
VulScan follows a continuous delivery model with minor updates and vulnerability database refreshes occurring almost daily. Major feature releases typically occur on a quarterly cadence. Since the management portal is cloud-based, UI updates and new reporting features are applied automatically without user intervention. Local scanner appliances and discovery agents are designed to auto-update when a new version is released, ensuring that the latest CVE (Common Vulnerabilities and Exposures) checks are always available. Release notes are published within the portal, and major updates are announced via the 'RapidFire Tools Blog' and monthly customer newsletters to keep administrators informed of new capabilities.
Data ownership remains strictly with the customer. While VulScan stores scan results and metadata in its secure cloud portal to provide historical trending and reporting, the customer retains the right to export this data at any time. Reports can be exported in multiple formats, including PDF, CSV, and XML, facilitating easy data portability. If a subscription is cancelled, Kaseya provides a grace period during which users can export their final reports before the data is securely purged from the system in accordance with their data retention policy. The terms of service explicitly state that RapidFire Tools does not sell or share customer-specific scan data with third parties.
VulScan is architected for extreme scalability. Because it uses a multi-tenant, distributed scanning model, it can scale from a single small office to a global enterprise with hundreds of locations. To handle large-scale networks, users can deploy multiple scanner appliances at the same site and divide the IP ranges between them; the cloud portal then aggregates all results into a single view. There is no limit on the number of scanners that can be attached to a single account. For organizations managing tens of thousands of endpoints, the backend infrastructure is designed to process massive amounts of concurrent scan data without performance degradation in the web-based management interface.
VulScan subscriptions are typically offered on an annual or multi-year basis with monthly billing. Contracts are designed with standard MSP-friendly terms, including clear renewal notification periods. Cancellations generally require a 30-to-90 day notice depending on the specific agreement. Service Level Agreements (SLAs) guarantee high availability for the cloud management portal, backed by Kaseya's global support infrastructure. The terms also include standard indemnification and limitation of liability clauses common in the SaaS industry. All product usage is subject to the 'RapidFire Tools Product Terms of Use,' which is publicly available on their website and updated periodically to reflect new compliance requirements.
Compliance is a primary use case for VulScan. The platform helps organizations meet the technical requirements for a wide variety of standards, including HIPAA, GDPR, PCI-DSS, and SOC 2, all of which mandate regular vulnerability assessments. VulScan reports are specifically designed to provide the documentation needed by auditors to prove that a vulnerability management program is in place. Furthermore, Kaseya, the parent company, maintains a robust compliance posture itself, ensuring that the software development lifecycle (SDLC) follows secure coding practices. The tool also provides specialized reporting modules that align with the NIST Cybersecurity Framework, helping users map technical findings to organizational risk categories.