Ostorlab documentation

Test, triage and fix every app you ship.

Guides for scanning mobile apps, web apps and APIs, source code and networks, mapping your attack surface, and remediating what Ostorlab finds.

Fail the build on critical findings
$ ostorlab --api-key="$OSTORLAB_KEY" ci-scan run \
    --scan-profile=full_scan \
    --break-on-risk-rating=high \
    android-apk app-release.apk
✓ Scan created
⋯ Static, dynamic and backend analysis
✓ Scan done. Risk rating: MEDIUM
✓ Build passes (threshold: HIGH)

Developers

Build on Ostorlab

Automate scanning and triage from your own code, or let an AI assistant work with your findings directly.

Integrations

Scan on every build

Add Ostorlab to your CI/CD pipeline, fail builds on risky findings, and sync tickets with Jira, Linear or ServiceNow.

All integrations

Watch the platform walkthrough