One focused workflow
From bounded input to evidence you can review
- Add the source.Accepted inputs are ZIP, TAR, TAR.GZ, TGZ, JSON, YAML, YML. The visible limit is 5 files · 64 MB total.
- Confirm the job.Every assigned source number, selected filename and setting stays visible before the confirmed SHA-256 input hash is accepted. Product-specific mappings remain explicit settings rather than guessed roles.
- Process in isolation.A one-job networkless sandbox receives only this job and cannot access accounts, queues, encryption keys or other customer storage.
- Review exact findings.Review source archives, supplied SBOMs and IaC files for exposed-secret patterns, risky configuration and dependency inventory evidence with pinned offline rules.
- Download the evidence.HTML, SARIF, CycloneDX or SPDX, protected CSV and engine manifest Every output hash is covered by the coordinator-created manifest.
What this product does not claim
This static rules snapshot has no CVE database and never claims vulnerability completeness or that the release is secure.