Architecture and migration
Sizing, target environment, data transfer, cutover and recovery are resolved before production operations.

WZ-IT plans, installs and operates OpenVAS as managed hosting, in your cloud or on premises. Depending on the target design, we also provide migration, secure network and identity integration, monitoring, backups, updates, integrations and further development.
The following are trademarks of their respective owners: OpenVAS / Greenbone (Greenbone AG). WZ-IT is an independent service provider and has no business, partnership, or contractual relationship with these companies. We offer independent migration, installation, hosting, and operations services.

OpenVAS is a comprehensive vulnerability scanner that supports both authenticated and unauthenticated testing and covers a wide range of high-level and low-level internet and industrial protocols.
With performance tuning for large-scale scans and a powerful internal programming language that allows you to implement any type of vulnerability test, the scanner offers extensive functionality. The test feed draws on a long history and is updated daily.
We install, host and operate OpenVAS for your company - either on our secure, privacy-focused infrastructure in Germany or other locations, as well as on-premise in your own environment.
We operate an isolated Greenbone/OpenVAS instance per customer and provide monitoring, backups and maintenance according to the selected service level. The daily Community Feed comes without completeness or availability guarantees; an Enterprise Feed with additional tests and a vendor SLA is assessed separately when required.
Conduct security tests both with and without authentication to identify all vulnerabilities.
Test a wide range of internet and industrial protocols, from high-level to low-level.
Optimized for large-scale scans to efficiently assess extensive IT networks.
Allows you to implement custom vulnerability tests of any kind.
Access a comprehensive test feed with a long history that is updated daily.
Integrates current CVE information including links to CERT-Bund (Computer Emergency Response Team of the BSI) and others.
Professional installation on your infrastructure - on-premise, cloud or hybrid
In your data center
AWS, Azure, Hetzner & more
Advanced architecture after technical and licence assessment
Secure access and access control for your installation
WireGuard, NetBird or Tailscale
Directly or through an upstream identity layer
Depends on application, edition and identity provider
Fail2Ban, Rate Limiting, IP Whitelisting
We set up secure VPN access to your installation - ideal for remote work and external employees.
Full-service installation with no hidden costs
OpenVAS is the open-source standard for vulnerability scanning. We extend it for your specific compliance requirements.
The Greenbone Management Protocol enables full automation: Schedule scans, retrieve results, generate reports.
Critical findings can trigger alerts: Email, SNMP trap, syslog, or webhook to your SIEM.
We develop custom vulnerability tests in NASL for your proprietary systems or internal compliance checks.
How we implement OpenVAS development in practice.
ISO 27001 / BSI IT-Grundschutz require regular scans, but standard policies don't cover all requirements.
Custom scan configs checking exact compliance requirements. Reports automatically formatted for audits.
New deployments could introduce vulnerabilities. Security check only happens weeks later.
OpenVAS scan as pipeline stage. Deployment blocked on critical/high findings, ticket automatically created.
Scan results show IPs, but who's the owner? Which system is affected? Manual mapping needed.
Integration with CMDB: Findings automatically enriched with asset owner, criticality rating and SLA requirements.
We do more than provide an application. WZ-IT designs the technical architecture, integrates network and identity, operates the agreed scope and develops integrations when the standard product is not enough.
Sizing, target environment, data transfer, cutover and recovery are resolved before production operations.
SSO, secure access, internal systems and existing security components are integrated appropriately.
Updates, backups, technical monitoring and response paths follow a transparent operational scope.
APIs, automation and custom extensions can be delivered beyond basic deployment.
The exact scope depends on the application, edition, infrastructure and criticality. Vendor licences and non-standard components are quoted separately.
Security platforms create value only when data sources, resilient detection rules and clear response paths fit together.
Agents, scanners, logs and interfaces provide defined security events and findings.
TLS, firewall rules, reverse proxies or private network paths are designed around the platform's exposure.
Local accounts, SSO, directories, service accounts and emergency access are connected through clear roles.
Analysis, correlation, vulnerability assessment and rules run in a controlled security environment.
Indexes, retention, access protection and capacity aligned with the data rate.
Controlled signatures, policies, exceptions and documented change processes.
Prioritisation, deduplication, tickets and defined handoff to responsible teams.
The platform supports detection and response but does not replace risk assessment, ownership or agreed incident processes.
A clearly defined operating scope instead of an opaque hosting flat fee.
Compute, applications, storage and response are shown separately. You can see what ongoing operations include and which requirements need a technical assessment.
We also design custom OpenVAS architectures, integrations and migrations. Contact us for a technical assessment.
One managed standard OpenVAS application is included in the Starter workload. Every service level also includes flexible expert time for planned work during regular service hours. Select compute, additional applications, storage and the appropriate service level.
A workload is one compute instance with the applications agreed for it.
One standard app per workload is already included. Additional dedicated servers count as separate workloads.
€79.90 per started TB and month, including daily encrypted offsite backup with 7-day retention.
Briefly describe the current state and objective for OpenVAS. We assess infrastructure, integration, and ongoing operations.
Whether you run OpenVAS in-house or need to host confidentiality-professional data §203-ready - we build, operate and maintain OpenVAS on an encrypted on-site server. Data never leaves the building in cleartext.
See OpenVAS on-premise
These solutions are often used together with OpenVAS
These solutions offer similar functionalities and can be evaluated together
No risk: worst case, you leave with a clearer understanding of your project than before.


“WZ-IT's advice on our Azure migration was technically sound and completely non-binding right from the intro call - we took away a great deal.”
Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.
Timo Wevelsiep & Robin Zins
Managing Directors of WZ-IT
