Coverage
Match security coverage
to your application stack.
Assess your source repositories, container components and AI inventory with the modules that apply to each project. Our experts help confirm the supported inputs for your evaluation.
| Asset surface | Assessment scope | Important boundary |
|---|---|---|
| Source repository | SBOM, SAST, Secrets and applicable IaC | Assessment coverage depends on the repository languages, manifests and configuration formats. |
| Container image | Supported package inventory and vulnerability assessment | A linked repository is needed for source-code assessment. An image is distinct from a Dockerfile. |
| AI component inputs | Supported AIBOM inventory workflows | Inventory is distinct from behavioural, prompt-injection or runtime model testing. |
Validate coverage for your stack.
Exact supported languages, frameworks, package ecosystems, manifests and artifact formats are confirmed during early-access scope review. We will agree the applicable assessments before onboarding.
Language and format support varies by assessment. Your onboarding review confirms which checks apply to your repositories and artifacts.
Register for Early AccessUnderstand your assessment coverage.
- Check the assessed target and version.
- Review scan status, coverage and freshness.
- Keep partial, failed and unassessed states visible.
- Review findings and AI guidance before action.
- Compare reassessment scope after changes.
No findings is not proof that an application is secure.
Find the right assessments for your stack.
| Capability | Inputs to review | What we confirm with you |
|---|---|---|
| SBOM | Repository dependency manifests, lockfiles or supported container artifacts | Package ecosystems, version resolution, dependency and license coverage. |
| SAST | Repository language, framework and build layout | Supported rules and files; any prerequisites or exclusions for that stack. |
| IaC | Infrastructure definition files and relevant configuration | Supported formats, resources and checks; live-environment differences remain outside source assessment. |
| Secrets | Repository content and intended assessment scope | Supported detectors, excluded locations and how redacted evidence will be reviewed. |
| AIBOM | AI component declarations or supported inventory inputs | Which components and relationships can be recorded; missing or unsupported inputs. |
Our experts confirm language, framework and artifact support during your early-access scope review, so your team knows which assessments apply before setup.
Questions to resolve during onboarding
- Which project, asset and revision are being assessed?
- Which modules and inputs are supported?
- What was excluded, unavailable or only partially assessed?
- When did the assessment complete, and is it current?
- What evidence will validate the result after remediation?