Applications
Path: /applications · Sidebar: Assets → Applications
Applications are the business-level units that all security data rolls up to. A healthy application inventory is the foundation of accurate posture - every finding, scan and compliance result is ultimately attributed to an application.
The Applications list
The list groups applications by environment, business criticality or risk, and shows per-app KPIs (open findings, exploitable count, posture grade). Use the filters to focus on, say, only Production / Critical apps.
Create an application
- Click New Application.
- Set:
- Name - the product or service name.
- Environment -
Production,Staging,Development. - Business criticality -
Low,Medium,High,Critical. This is a multiplier on risk: a Critical app's High finding outranks a Dev app's High. - Description / owner (optional) - team or business owner for routing.
- Click Create.
Application detail
Path: /applications/[id]
Open an application to see everything attributed to it:
- Posture summary - grade, open vs. resolved, exploitable, SLA-breached.
- Linked targets & repositories - the DAST targets and source repos that feed it.
- Findings - the unified vulnerabilities for this app, filterable by severity.
- Coverage - which scan types (DAST/SAST/SCA) have run, and how recently.
- Compliance - control coverage for this app (see Compliance).
How applications relate to other objects
- A Target (URL) is linked to one application for DAST.
- A Repository (source) is linked for SAST/SCA/secrets/IaC.
- Group related apps/microservices into a Product for portfolio rollups.
Risk prioritisation, SLA deadlines and executive reporting all lean on business criticality. A portfolio where everything is "Critical" produces a flat priority list - reserve it for the apps that truly matter.