Skip to main content

Applications

Path: /applications · Sidebar: Assets → Applications

Applications are the business-level units that all security data rolls up to. A healthy application inventory is the foundation of accurate posture - every finding, scan and compliance result is ultimately attributed to an application.

The Applications list

The list groups applications by environment, business criticality or risk, and shows per-app KPIs (open findings, exploitable count, posture grade). Use the filters to focus on, say, only Production / Critical apps.

Create an application

  1. Click New Application.
  2. Set:
    • Name - the product or service name.
    • Environment - Production, Staging, Development.
    • Business criticality - Low, Medium, High, Critical. This is a multiplier on risk: a Critical app's High finding outranks a Dev app's High.
    • Description / owner (optional) - team or business owner for routing.
  3. Click Create.

Application detail

Path: /applications/[id]

Open an application to see everything attributed to it:

  • Posture summary - grade, open vs. resolved, exploitable, SLA-breached.
  • Linked targets & repositories - the DAST targets and source repos that feed it.
  • Findings - the unified vulnerabilities for this app, filterable by severity.
  • Coverage - which scan types (DAST/SAST/SCA) have run, and how recently.
  • Compliance - control coverage for this app (see Compliance).

How applications relate to other objects

  • A Target (URL) is linked to one application for DAST.
  • A Repository (source) is linked for SAST/SCA/secrets/IaC.
  • Group related apps/microservices into a Product for portfolio rollups.
Set criticality honestly

Risk prioritisation, SLA deadlines and executive reporting all lean on business criticality. A portfolio where everything is "Critical" produces a flat priority list - reserve it for the apps that truly matter.