Skip to content

AI Engine

The AI engine generates scan summaries and provides tailored recommendations with exact change for the identified vulnerabilities.

Vulnerability Recommendation

The AI engine can examine discovered vulnerabilities in an application, understand their types, degrees of severity, and potential effects on the application's security, and then offer useful suggestions for how to address them.

Scan summary

The AI engine can also generate a concise and informative scan summary. This summary provides an overview of the vulnerabilities found, highlighting their criticality and providing a high-level understanding of the security posture of the application.

Summaries can be customized by adding more context for the AI Engine to update its recommendation.

To enable the AI Engine:

  • Navigate to the "Settings" menu, click on "Organisation".
  • Scroll down to "Features", click on "Enable AI Engine", then hit "Save".

FAQ

Below are answers to common questions regarding the usage of AI features within Ostorlab:

  1. What is the primary function of AI in Ostorlab? AI is employed for various functions, including vulnerability detection, enhancing application crawling processes, and generating insightful recommendations.

  2. Does Ostorlab use AI to improve over time? Yes, Ostorlab continuously enhances its capabilities by leveraging feedback regarding the benefits and accuracy of specific features, such as reducing false positives and improving application coverage.

  3. Is user data utilized in training Ostorlab's AI models? No, user data from both free and paid plans is never used to train AI models, ensuring complete privacy and security.

  4. Does Ostorlab share AI model insights or data with third parties? No, Ostorlab does not share any data or AI model insights with third parties in any form.

  5. How accurate are the AI-driven analyses compared to manual assessments? The accuracy of AI models varies by use case. In production-enabled scenarios, AI-driven systems have been verified to surpass human analysis in performance.

  6. How frequently are the AI models updated or reviewed? AI models and their integrations are regularly updated, with continuous improvements aimed at enhancing their effectiveness.

  7. Are there any known limitations or challenges with using AI in Ostorlab? While certain models have limitations based on specific use cases, continuous improvements are made. For example, initial challenges in supporting multiple languages during mobile application crawling have now been addressed.

  8. Can AI recommendations be overridden or manually adjusted? Currently, Ostorlab does not provide direct options to modify AI-driven outcomes, though it offers ways to enhance these systems further.

  9. How does Ostorlab approach ethical considerations in AI deployment? Ethical considerations, including privacy and security, are evaluated during the design phase of AI features to ensure responsible deployment.

  10. What steps does Ostorlab take to comply with data protection regulations (like GDPR)? Ostorlab incorporates privacy compliance as part of the feature design process and reviews its practices through SOC2 audits. The team is also trained on respecting privacy-first principles.

  11. How transparent is the AI's decision-making process to end-users? Ostorlab aims to ensure transparency in AI-driven processes by clearly distinguishing AI-powered features within the platform. Users are informed about the AI’s role in generating specific outcomes where applicable. Additionally, ongoing efforts are made to provide further insights into the decision-making process for complex analyses, allowing users to better understand how conclusions are reached. This transparency helps users to trust and effectively engage with AI-enhanced functionalities.