- Primeros pasos
- Cómo encaja Ostorlab
How Ostorlab fits together
Ostorlab scans mobile apps, web apps, networks and source code for vulnerabilities, and it discovers and tracks your attack surface. It turns findings into tickets that you can assign on the platform or sync with your ticketing system.
How organisations, assets, scans and tickets connect
The objects below are listed in the order you meet them. Each paragraph links to the page that owns the detail.
-
Organisation and users. An organisation is the group your users belong to. Its members see all of its scans, vulnerability data and tickets, unless Owner-Based RBAC restricts access. Each user has a role, such as Admin, User or Reader, and only admins can add users. To keep data apart, create separate organisations and switch between them from the upper menu. See Create an organisation, User roles and Add users. For team-based access, see Owner-Based RBAC.
-
Assets and the attack surface. An asset is something Ostorlab tracks and scans, such as a domain, an IP address or a mobile app. Each asset has an owner, the team in charge of its fixes. Attack surface discovery proposes potential assets, and you confirm or reject them. Confirmed assets form your inventory. See Attack surface discovery, Add assets and Discover assets. A monitoring rule scans assets on a schedule or when they change.
-
Scans and scan profiles. A scan tests assets. You choose the asset type, then a scan profile, which sets the depth and techniques of the test. Deep Agentic, multi-asset, Mobile Shielding and source code scans also need an AI provider: Cyber Models tokens or your own key (BYOK). Fast, Full and Exhaustive scans use no AI tokens. The profiles for each asset type are in the table below. See Supported scan profiles and Cyber Models overview.
-
Findings and risk ratings. A scan reports findings, which the scan page lists as vulnerabilities. Each finding has a risk rating. High, Medium and Low findings are confirmed; Potentially findings are not. You can change a rating that does not fit your context. See Understand scan results, Risk rating and Change risk rating. The IDE shows the evidence behind a finding.
-
Tickets and remediation. Each finding is tracked in a ticket. Ostorlab creates a ticket for a newly detected issue and aggregates later occurrences of the same vulnerability into it. A ticket has a priority from P0 to P3 and can be assigned. When you mark a ticket as fixed, a later scan verifies the fix or re-opens the ticket. A patching policy sets deadlines, and streams group tickets. See Ostorlab remediation system and Ticket aggregation.
-
Automation: integrations and the API. The CI/CD guides run scans from your pipeline. Jira, Linear and ServiceNow sync tickets, Slack receives notifications, and Vanta receives vulnerability findings. SAML provides single sign-on. The GraphQL API and the MCP server let scripts and AI assistants work with scans, vulnerabilities, tickets and assets. The MCP server needs an API key. The GraphQL API accepts an API key or a user token. See Integrate and automate, GraphQL API, MCP server and API keys.
Which scan type for which asset
The table lists what each asset type covers and the profiles available for it. For a full comparison, see Scan types comparison.
| Asset type | What you can scan | Scan profiles | Page |
|---|---|---|---|
| Mobile | Android (.apk, .aab), iOS (.ipa), store URLs, TestFlight | Full Scan, Fast Scan, Mobile Deep Agentic Scan, Mobile Single Vulnerability Assessment, Mobile Shielding Scan, Privacy Scan | Mobile scan profiles |
| Web and API | Web apps, single page apps, REST, GraphQL, OpenAPI | Full Web Scan, Web Exhaustive Scan, Web Deep Agentic Scan, Web Single Vulnerability Assessment | Web scan profiles |
| Network | Single IPs, CIDR blocks, hostnames, network services | Full Network Scan, IP Exhaustive Scan, Network Deep Agentic Scan, Network Single Vulnerability Assessment | Network scan profiles |
| Attack surface | Domains, subdomains, IP ranges, public cloud footprints | Attack Surface Exhaustive Scan, Attack Surface KEV Scan | Attack surface scan profiles |
| Source code | Git repositories (GitHub, GitLab, Bitbucket, Azure DevOps), ZIP archives | Code Repository Scan, Repository Archive Scan | Source code scan profiles |
| Several assets | A mobile app, web apps, network ranges, code and files in one scan | Multi Asset Deep Agentic Scan | Multi Asset scan profile |