Ostorlab documentation

Test, triage and fix every app you ship.

Guides for scanning mobile apps, web apps and APIs, source code and networks, mapping your attack surface, and remediating what Ostorlab finds.

Fail the build on critical findings
$ ostorlab --api-key="$OSTORLAB_KEY" ci-scan run \
    --scan-profile=full_scan \
    --break-on-risk-rating=high \
    android-apk app-release.apk
✓ Scan created
⋯ Static, dynamic and backend analysis
✓ Scan done. Risk rating: MEDIUM
✓ Build passes (threshold: HIGH)

Start here

What do you want to do?

Four goals. Each lists the pages to open, in order.

Run a scan

Mobile, web, API, code or network

  1. Run your first scan

    Create an account, open the dashboard and start your first scan.

    Getting Started

  2. Choose a scan

    Compare scan profiles by the assets they cover and what they test.

    Scanning › Scan Profiles

  3. Scan a mobile app

    Find the app in a store by name or package, then pick a Fast or Full scan.

    Scanning › Run a scan

  4. Scan a web app or API

    Enter a URL or domain, pick a profile and submit. Add credentials to scan behind a login.

    Scanning › Run a scan

Fix what a scan found

Results, tickets and policies

  1. Understand scan results

    Tell confirmed findings from potential ones, and see the coverage behind each.

    Scanning › Report

  2. Triage vulnerabilities and tickets

    Assign vulnerabilities and follow their tickets through to a fix.

    Policies & Remediation › Ticketing

  3. Set a patching policy

    Set a schedule for fixing vulnerabilities, based on their risk rating.

    Policies & Remediation › Ticketing

  4. Generate a PDF report

    Generate a PDF report of a scan to keep or send.

    Scanning › Report

Automate it

CI/CD, the API and AI assistants

  1. Scan in your CI/CD pipeline

    Add Ostorlab to GitHub, GitLab, Jenkins and more, and fail the build on risky findings.

    Integrations & API › CI/CD

  2. Create an API key

    Give it a name and an expiry date, then use it in scripts and CI jobs.

    Integrations & API › API

  3. Connect an AI assistant (MCP)

    Let an assistant work with your scans, vulnerabilities and tickets.

    Integrations & API › API

  4. Use the GraphQL API

    Create scans, follow their progress and list vulnerabilities.

    Integrations & API › API

Set up my organisation

Users, sign-in, plans and keys

  1. Add users and manage their access

    Add people to your organisation from the settings menu.

    Organisation › Users

  2. Roles and access

    What Admin, User, Reader and Attack Surface Auditor can do.

    Organisation › Users

  3. Single sign-on (SAML)

    Let members sign in with their work email.

    Integrations & API › SSO

  4. Tokens and BYOK

    Buy tokens, or use your own AI provider key.

    Scanning › Cyber Models

The whole platform

Everything Ostorlab does, in one picture

Five stages take an asset from unknown to fixed. Administration sits under all of them.

  1. Discover

    Find what you own

    Attack Surface
  2. Scan

    Test it

    Scanning
  3. Triage

    Read and rank findings

    Policies & Remediation
  4. Fix

    Assign, patch, verify

    Policies & Remediation
  5. Automate

    Repeat on every build

    Integrations & API

Under every stage

Administer

Organisations, users and roles, sign-in, plans and tokens, API keys, scanners and audit logs.

Around all of it

Security & Privacy

Security guides and checklists, the Knowledge Base, and how Ostorlab handles your data.

Browse

A place for each job

  1. Getting Started

    Create an account, tour the dashboard and run your first scan.

  2. Copilot

    Ask the assistant about the platform, your scans and your vulnerabilities.

  3. Scanning

    Pick a scan profile, run it on an app, source code or network, and read the report.

  4. Attack Surface

    Discover what you own, keep the inventory current and watch it for change.

  5. Policies & Remediation

    Work tickets, group them in streams, and set the policies that decide what gets fixed first.

  6. Organisation

    Create your organisation, add users and roles, and manage settings and access.

  7. Plans

    Add a plan, or transfer plans between organisations.

  8. Security & Privacy

    Security checklists, mobile app security guides, privacy, and the Knowledge Base.

Developers

Build on Ostorlab

Automate scanning and triage from your own code, or let an AI assistant work with your findings directly.

Integrations

Scan on every build

Add Ostorlab to your CI/CD pipeline, fail builds on risky findings, and sync tickets with Jira, Linear or ServiceNow.

All integrations

Watch the platform walkthrough