Coverage
Know what was assessed.
Know what remains unknown.
Coverage follows the linked asset, supported input and configured assessment. A project does not automatically enable every module.
| Asset surface | Assessment scope | Important boundary |
|---|---|---|
| Source repository | SBOM, SAST, Secrets and applicable IaC | Language, manifest and configuration support must match the release. |
| Container image | Supported package inventory and vulnerability assessment | A linked repository is needed for source-code assessment. An image is distinct from a Dockerfile. |
| AI component inputs | Supported AIBOM inventory workflows | Inventory is distinct from behavioural, prompt-injection or runtime model testing. |
Validate coverage for your stack.
Exact supported languages, frameworks, package ecosystems, manifests and artifact formats are confirmed during early-access scope review. We will agree the applicable assessments before onboarding.
Language support varies by module. A package ecosystem appearing in an inventory filter does not establish full SAST support for that language.
Register for Early AccessRead the result in context.
- Check the assessed target and version.
- Review scan status, coverage and freshness.
- Keep partial, failed and unassessed states visible.
- Review findings and AI guidance before action.
- Compare reassessment scope after changes.
No findings is not proof that an application is secure.
Agree the supported inputs before setup.
| Capability | Inputs to review | What we confirm with you |
|---|---|---|
| SBOM | Repository dependency manifests, lockfiles or supported container artifacts | Package ecosystems, version resolution, dependency and license coverage. |
| SAST | Repository language, framework and build layout | Supported rules and files; any prerequisites or exclusions for that stack. |
| IaC | Infrastructure definition files and relevant configuration | Supported formats, resources and checks; live-environment differences remain outside source assessment. |
| Secrets | Repository content and intended assessment scope | Supported detectors, excluded locations and how redacted evidence will be reviewed. |
| AIBOM | AI component declarations or supported inventory inputs | Which components and relationships can be recorded; missing or unsupported inputs. |
A verified release-specific language, framework and format matrix is not yet published here. We confirm your stack during suitability review. A demonstration project or inventory filter is not a guarantee of full support.
Your assessment scope should answer
- Which project, asset and revision are being assessed?
- Which modules and inputs are supported?
- What was excluded, unavailable or only partially assessed?
- When did the assessment complete, and is it current?
- What evidence will validate the result after remediation?