Skip to content
CyberArmorApplication security engineering

We turn the output of your tools into the report you hand your client.

The platform reads your scanner output and hands back the executive report already drafted.

SARIFCYCLONEDXNESSUS XMLCSV
198code rules across 14 languagesTaint tracking runs on JavaScript and TypeScript only, inside a single function, and it ships off by default. Everywhere else it is line-by-line pattern matching.
93ISO/IEC 27001:2022 controls loaded, plus 47 SOC 2 criteria and 90 OWASP SAMM v2 activitiesThese are catalogues loaded into the product, not certifications we hold. We hold neither ISO 27001 nor SOC 2. A finding is suggested to a control by keyword match, with the confidence of that guess recorded, for you to confirm or reject.
183infrastructure-as-code rulesCoverage is lopsided. 111 rules for AWS, 16 for Azure, none for Google Cloud.
Our work

What we deliver

Three product fronts and one staffed front. All of them run in the same workspace.

  • DevSecOps

    The pipeline your clients already ship from

    Scanner output lands in one findings table. The finding identity survives a reformat. And the CycloneDX 1.6 SBOM comes out of the tree the SCA already resolved. See DevSecOps

  • InfraSec

    The machines and the cloud they run on

    CIS benchmarks in an agent for Windows, Linux and macOS. Infrastructure-as-code and container rules run before the machine is ever built. See InfraSec

  • GRC

    The compliance spreadsheet nobody can audit

    Every finding is suggested to a control from ISO/IEC 27001:2022, SOC 2 or OWASP SAMM v2. What you accept becomes dated evidence. See GRC

  • Services

    One of our consultants inside your workspace

    Scanning, triage, compliance mapping and report writing. Billed by scope and service level. See services

The problem

One risk, the way four tools report it today

This scene is in every assessment you deliver.

  1. SCA

    A critical CVE in a dependency.

    Ticket one.

  2. CSPM

    A container role with write access to production storage.

    Ticket two.

  3. CSPM

    A load balancer open to the internet.

    Ticket three.

  4. GRC

    Control A.8.9 reported as in place.

    No ticket at all.

Together they are one path from a public IP address to your client’s data.

Every finding is correct, and on its own each one is unremarkable. Joining them means reading code, cloud and controls in the same query. None of the four tools reads all three.

The platform does not join them either, today. It does the step before that, and that step is what comes next.

How it works

From raw scanner output to a signed report

The last mile of the assessment. It is the part you actually bill for.

  1. Four formats land in one table

    Today you open one file at a time, in one format at a time.

  2. The same flaw seen by two scanners becomes one finding

    With both sources hanging off it. Today you deduplicate by hand.

  3. A retest does not reopen what you already accepted

    Finding identity ignores line numbers. The mark survives when someone reformats the file.

  4. The executive report comes out already drafted

    You review, correct and sign. Today it starts from scratch every time.

The numbers

What the engines cover

One connection covers the repository, the image, the infrastructure code and the machine. Under each number is where that number stops.

100container rules across Dockerfile and composeOS packages generate CVEs for Debian, Ubuntu and Alpine only. RedHat and RPM are out of scope, stated so in the source.
8dependency ecosystems, read from lock files and the transitive treeThe dependency engine reads no operating-system packages at all. Those only come out from inside a container image.
1,501CIS benchmark rules in an endpoint agent that runs on Windows, Linux and macOSThat is the count. Real-time process blocking is not in it, and it will not become a headline before it is.
31secret patternsPattern matching finds the 31 formats it knows. A credential in a format of your own making has no pattern to match.
Next step

Do you have an assessment to close this month?

The platform is not live yet. There is no signup and no trial to click. Write in and tell us which scanners you run, and an engineer here answers.

Talk to a specialist