Skip to content
CyberArmorApplication security engineering
São Paulo, Brasil · Application security engineering

The application security company that publishes its own limits.

We built our own platform to scan code, dependencies, cloud and containers. When a finding has to become a fix, our consultants take it from there. And when the real problem is headcount, we put one of our people inside your team.

SARIFCYCLONEDXNESSUS XMLCSV
198code rules across 14 languagesTaint tracking runs on JavaScript and TypeScript only, inside a single function, and it ships off by default. Everywhere else it is line-by-line pattern matching.
93ISO/IEC 27001:2022 controls loaded, plus 47 SOC 2 criteria and 90 OWASP SAMM v2 activitiesThese are catalogues loaded into the product, not certifications we hold. We hold neither ISO 27001 nor SOC 2. A finding is suggested to a control by keyword match, with the confidence of that guess recorded, for you to confirm or reject.
183infrastructure-as-code rulesCoverage is lopsided. 111 rules for AWS, 16 for Azure, none for Google Cloud.
The problem

The problem was never too few tools.

Here is one risk, the way four tools report it today.

  1. SCA

    A critical CVE in a dependency.

    Ticket one.

  2. CSPM

    A container role with write access to production storage.

    Ticket two.

  3. CSPM

    A load balancer open to the internet.

    Ticket three.

  4. GRC

    Control A.8.9 reported as in place.

    No ticket at all.

Together they are one path from a public IP address to your client data.

Each of those findings is correct. Each one, on its own, is unremarkable. Nothing in the stack draws the line between them, because drawing it means reading code, cloud and controls in the same query.

Neither do we, today, and this page will not pretend otherwise. What exists is the step before the path: the four findings land in the same table, the same flaw seen by two scanners becomes one finding with two sources, and the executive report comes out already drafted. The path is what gets built on top of that table.

The numbers

What runs, and where it stops

One connection, and the scan covers the repository, the image, the infrastructure code and the machine.

100container rules across Dockerfile and composeOS packages generate CVEs for Debian, Ubuntu and Alpine only. RedHat and RPM are out of scope, stated so in the source.
8dependency ecosystems, read from lock files and the transitive treeThe dependency engine reads no operating-system packages at all. Those only come out from inside a container image.
1.501CIS benchmark rules in an endpoint agent that runs on Windows, Linux and macOSThat is the count. Real-time process blocking is not in it, and it will not become a headline before it is.
31secret patternsPattern matching finds the 31 formats it knows. A credential in a format of your own making has no pattern to match.
Limits

What we do not do

  • White label does not exist

    The report carries our brand in the header and footer of every page, not yours. Changing that takes a code change and a rebuild.

  • The report is a PDF

    Not Word, not Excel. If your process ends in a file you open and edit before sending, it still will.

  • The platform is not live yet

    Infrastructure is being rebuilt. There is no signup, no trial and no billing — and you pay for nothing before it exists.

Before and after

Measured against your process today, not against a competitor

The last mile of an assessment: from raw tool output to a signed report.
StepYour process todayWith the platform
Reading four tool outputsFour formats, opened one by oneSARIF, CycloneDX, Nessus XML and vendor CSV in one table
The same flaw seen by two scannersTwo findings, deduplicated by handOne finding with two sources
Retest of an accepted findingReopens, because the line number movedIdentity ignores line numbers; the mark survives
Writing the executive reportFrom scratch, every timeDrafted; you review, correct and sign
Next step

See what the platform does, and where it stops.

There is no signup and no trial to click. What exists today is a technical conversation with the person who wrote the code.

Talk to the engineer