Coverage

Does apPosture cover your stack?

Every language, ecosystem, cloud and integration our engines support - grounded in what the platform does today, and running entirely inside your infrastructure.

Code and dependencies

The source, its libraries and its secrets.

SAST

Inter-procedural taint tracking that follows the real data flow from source to sink.

PythonJavaScriptTypeScriptJavaGoC#RubyPHP

SCA

Dependency CVEs with offline reachability across every major package ecosystem.

npmPyPIMavenGradleGo modulesComposerRubyGemsNuGetCargopub (Flutter)HexSwift

Secrets

Twenty-plus provider detectors plus entropy, with optional git-history scan and live validation.

AWSGitHubGitLabGoogleSlackStripeOpenAIAzureTwilioPrivate keysJWTDB URIsHigh-entropy
Runtime, web and APIs

The application as it actually runs.

DAST

Proof-based dynamic testing of running web apps, with authenticated crawl.

RESTOpenAPI 3.xSwagger 2.0Form login (CSRF-aware)BearerCookieHeaderOAuth2 / OIDC

API Security

Endpoint inventory, contract diff and one risk score across protocols.

OpenAPI importGraphQLgRPCHTTP/2h2cREST

Runtime verification (IAST)

In-process instrumentation correlates runtime behaviour with static findings.

PythonNode.jsJava.NET
Cloud, containers and infrastructure

Where the application is deployed.

Cloud posture (CNAPP)

CIS-aligned posture across the big three, snapshot-based and fully offline.

AWS (CIS v3.0 + FSBP)GCP (CIS)Azure (CIS)IdentityStorageNetworkLoggingDatabaseEncryption

Kubernetes posture

Cluster and workload posture, scored and deduplicated into your risk view.

WorkloadsRBACPrivileged / hostPathCapabilitiesSecretsCIS-aligned

Container images

Offline image CVEs from the OS package database, plus config and EOL checks.

Debian / Ubuntu (dpkg)Alpine (apk)Image config (CIS)Base-image EOL

Infrastructure as Code

Misconfiguration checks that also ground your threat model.

TerraformKubernetes manifestsCloudFormationDockerfileDocker Compose
Compliance and integrations

Where the findings go, and what they map to.

Compliance mapping

Findings mapped deterministically to the frameworks you report on.

OWASP Top 10PCI-DSS v4ISO 27001SOC 2NIST 800-53HIPAAGDPR

Source control

Connect the repositories you already use, cloud or self-managed.

GitHubGitHub EnterpriseGitLabGitLab self-managedBitbucketAzure DevOps

CI/CD and gating

A fail-closed gate and commit-status decoration in your pipeline.

GitHubGitLabJenkinsAzure DevOpsBitbucketMonitor to Block

Ticketing

Two-way issue sync into the tracker your team lives in.

Jira (Cloud + DC)ServiceNowGitHubGitLabAzure DevOpsCustom REST

Notifications

Route alerts to the channels on-call already watches.

EmailSlackMicrosoft TeamsTelegramPagerDutyOpsgenieWebhook (HMAC-signed)
Self-hosted

All of it runs in your environment

Every engine above scans inside your infrastructure with a local model - no source, findings or cloud snapshots leave your boundary. Coverage grows release over release; if your stack is not listed, ask.

See it on one of your own apps - live in 30 minutes

From discovery to a proven attack chain. A PoC in your own environment.