IOTVAS API enables you to discover IoT/Connected devices in the network and provides detailed real-time risk analysis, including firmware vulnerability analysis without requiring the user to uplo
Full LLM thinking from the 4-phase benchmark pipeline.
```json
{
"service_type": "platform",
"base_url": "https://firmalyzer.com:iotvas",
"auth_method": "unknown",
"auth_config": {},
"endpoints": [],
"pricing_model": {
"type": "unknown",
"details": {}
},
"rate_limits": {},
"capabilities": [
"IoT / connected device discovery on a network",
"real-time risk analysis of discovered devices",
"firmware vulnerability analysis without firmware upload",
"AI-driven security assessment (per categorization)"
],
"raw_analysis": "IoTVAS is a product from Firmalyzer that provides IoT and connected-device security assessment. The service discovers IoT/connected devices on a network and performs real-time risk analysis, including firmware vulnerability analysis that does not require the user to upload firmware — implying the analysis is done remotely (likely via device fingerprinting, exposed service probing, and firmware identification from known vendor/model signatures).\n\nWHO IT'S FOR: Security teams, network administrators, and enterprises needing visibility and risk scoring for the growing population of IoT/OT devices on their networks. Likely relevant for compliance, vulnerability management, and incident response contexts.\n\nMATURITY / FORM: The URL format 'https://firmalyzer.com:iotvas' is unusual — the ':iotvas' segment is not a standard TCP port (ports are numeric). This strongly suggests it is a named endpoint/path or a documented API identifier rather than a conventional REST base URL. No public REST API documentation, OpenAPI/Swagger spec, or endpoint list is provided in the source material, so no concrete endpoints, auth scheme, or rate limits can be extracted.\n\nINTEGRATIONS: Unknown from the provided content. No SDK, plugin, or marketplace integrations were mentioned.\n\nPRICING: Not provided. Firmalyzer products are typically commercial/B2B (enterprise security platform), so the likely model is subscription or quote-based enterprise licensing, but this cannot be confirmed from the given text.\n\nSUMMARY: This appears to be a legitimate B2B IoT security / firmware risk analysis platform with an API, but the source material lacks the technical detail needed to document concrete endpoints, auth methods, or rate limits. Further reconnaissance (vendor docs, OpenAPI spec, or direct probe) would be required to populate those.\n\nCAVEAT: Details derived primarily from the short marketing blurb; treat unverified fields (auth, pricing, rate limits) as unknown."
}
```0/3 tests passed
| Test | Endpoint | Status | Latency |
|---|---|---|---|
| website_uptime | GET / | None | 35ms |
| robots_txt | GET /robots.txt | None | 3ms |
| llms_txt | GET /llms.txt | None | 2ms |
{
"overall": 28,
"dimensions": {
"token_efficiency": 4.0,
"first_try_success": 2.0,
"response_parseability": 3.0,
"error_clarity": 2.0,
"doc_quality": 2.0,
"auth_simplicity": 3.0,
"latency": 2.0,
"consistency": 2.0
},
"pricing_normalized": {
"model": "unknown",
"tiers": [],
"free_tier": null,
"notes": "No pricing information available; cannot normalize"
},
"issues": [
"All three probe checks failed with an identical parsing error: \"Invalid port: 'iotvas'\" — the domain/port could not even be resolved, indicating a malformed or unreachable endpoint",
"No HTTP status codes were captured for any check, so uptime, robots.txt, and llms.txt presence are entirely unverifiable",
"No llms.txt discovered, meaning agents have no machine-readable onboarding or capability manifest",
"No response previews available, so no security headers, content type, or structured data could be evaluated",
"Pricing model is listed as 'unknown' with empty details — unacceptable ambiguity for agent recommendation to users",
"Capabilities are described only in vague marketing terms ('AI-driven security assessment') with no API surface, schema, or integration details provided"
],
"recommendations": [
"Fix the DNS/port resolution issue — the platform is currently unreachable by automated probes, which will cause every agent check to fail",
"Publish an llms.txt or /.well-known endpoint describing capabilities, auth flow, and rate limits so agents can self-onboard",
"Provide structured API documentation (OpenAPI/JSON schema) for device discovery and risk analysis endpoints",
"Expose a public status/uptime page and ensure the site responds over standard HTTPS on port 443",
"Clarify pricing publicly (free tier, usage-based, enterprise) — 'unknown' pricing is a blocker for agent-mediated recommendations",
"Document authentication method (API key, OAuth, SSO) explicitly so agents can assess onboarding friction"
]
}Show your live agent-readiness score on your own site. Free, no auth — it updates as your score changes.
<a href="https://prowl.world/service/iotvas-api">
<img src="https://prowl.world/badge/iotvas-api.svg" height="56" alt="Agent-readiness on Prowl">
</a>
See operational metrics, LLM evaluations, agent readiness, and more.
Open in Dashboard