# WASViking® Documentation > Public product documentation for the WASViking platform: getting started, concepts, one page per capability, the Sentinel agent, integrations, the REST API, compliance mapping, the Partner Console and the security of the platform itself. Every page listed here is public and rendered from the same Markdown source as https://docs.wasviking.com/. The full text of all pages is published in one file at https://docs.wasviking.com/llms-full.txt. The company page map lives at https://wasviking.com/llms.txt and the platform brief at https://wasviking.com/llms-full.txt. ## Introduction - [Welcome to WASViking](https://docs.wasviking.com/introduction/welcome/): What WASViking is, what it covers, and how to find your way around these docs. - [Platform overview](https://docs.wasviking.com/introduction/platform-overview/): What sits inside WASViking, how the pieces fit together, and what you get out. ## Getting Started - [Create your account](https://docs.wasviking.com/getting-started/create-account/): How WASViking accounts are provisioned, from first contact to first sign-in. - [Inviting your team](https://docs.wasviking.com/getting-started/inviting-your-team/): Pick the right role, send the invitation, track its state, and manage active and inactive users. - [Your first scan](https://docs.wasviking.com/getting-started/first-scan/): Add your first asset, pick a scan template and profile, configure preferences, and read findings. - [Activate your modules](https://docs.wasviking.com/getting-started/activate-your-modules/): One checklist that takes your organization from the first scan to every purchased module running, with the portal path and the verification step for each. - [Authenticated scanning](https://docs.wasviking.com/getting-started/authenticated-scanning/): Carry credentials into every analyzer through one shared session, without locking out the test account. - [WASViking Sentinel Tunnel](https://docs.wasviking.com/getting-started/sentinel-tunnel/): Scan the applications that never touch the internet. Install the Sentinel agent inside your network, register it with a one-time token, and let it open an outbound mTLS tunnel that you can rotate or revoke at any time. - [CI/CD DAST with GitHub Actions](https://docs.wasviking.com/getting-started/github-actions-dast/): Run automated DAST scans inside your GitHub Actions pipeline with the WASViking Sentinel. Scans the app on localhost over an ephemeral mTLS tunnel, runs authenticated scans with a token minted in the pipeline, prioritizes the endpoints you list, fails the build on real findings, and publishes results to the GitHub Security tab. - [CI/CD SCA, SBOM & Secrets with GitHub Actions](https://docs.wasviking.com/getting-started/github-actions-sca-sbom/): Generate a CycloneDX SBOM and scan for hard-coded secrets in your GitHub Actions pipeline with the WASViking Sentinel. Enriches with OSV and CISA KEV, submits over HTTPS, fails the build on known-vulnerable dependencies or leaked credentials, and publishes to the GitHub Security tab. - [CI/CD SCA, SBOM & Secrets with Bitbucket Pipelines](https://docs.wasviking.com/getting-started/bitbucket-pipelines-sca-sbom/): Run the WASViking Sentinel inside Bitbucket Pipelines to build a CycloneDX SBOM, check dependencies against OSV and CISA KEV, scan the working tree and git history for hard-coded credentials, and stop a vulnerable release before it reaches your main branch. - [Set up Code Security (SAST, SCA, secrets and SBOM)](https://docs.wasviking.com/getting-started/connected-repositories/): Connect GitHub or Bitbucket once and let WASViking clone and assess the repositories you choose on its own, with SAST, dependency analysis, secret detection and SBOM generation, on your plan's cadence and on every push. No CI change and no agent to install. - [Triage your first SAST finding](https://docs.wasviking.com/getting-started/triage-your-first-sast-finding/): Open the first weakness WASViking found in your source code, read the evidence down to the file and line, decide what to do with it and confirm it closes on its own after the fix. - [CI/CD DAST with Bitbucket Pipelines](https://docs.wasviking.com/getting-started/bitbucket-pipelines-dast/): Run an automated WASViking Sentinel DAST scan inside Bitbucket Pipelines against the app you bring up on localhost, over an ephemeral mTLS tunnel. The app is never exposed publicly, the build fails on real findings, and results land in the portal with SARIF and JSON as build artifacts. - [CI/CD Mobile Security with GitHub Actions](https://docs.wasviking.com/getting-started/github-actions-mobile/): Assess the Android or iOS package your build produces inside your GitHub Actions pipeline with the WASViking Sentinel. Uploads the artefact over HTTPS, runs the static assessment against OWASP MASVS and MASTG, fails the build on new findings with a baseline diff, and publishes results to the GitHub Security tab. - [SBOM Evidence Bundles](https://docs.wasviking.com/getting-started/sbom-evidence-bundles/): Answer a customer audit request with a signed, password-protected SBOM evidence package. Generate the bundle in the portal, deliver the link and the password through separate channels, and track every download. - [Posture Shares](https://docs.wasviking.com/getting-started/posture-shares/): Share a read-only, password-protected view of your security posture with an auditor, a customer, or an investor. Create the link, choose how much detail the recipient sees, and keep the access log. - [Edge Threat Radar (Cloudflare)](https://docs.wasviking.com/getting-started/cloudflare/): Connect your Cloudflare account so the Edge Threat Radar can correlate adversary traffic with your posture. Read-only by default; one Edit scope for the optional approval-gated blocklist. - [Edge Threat Radar (Google Cloud Armor)](https://docs.wasviking.com/getting-started/google-cloud-armor/): Connect Google Cloud Armor so the Edge Threat Radar can correlate adversary traffic with your posture. Read-only by default; one optional role for the approval-gated IP blocking. - [WASViking AI Guardian](https://docs.wasviking.com/getting-started/ai-guardian/): Roll out the WASViking AI Guardian on employee laptops and desktops. Enable it in the portal, install the agent and the managed browser extension, validate detection and the first policy block, then operate it day to day (updates, identity mapping, advanced detection). - [Set up Infrastructure Defense](https://docs.wasviking.com/getting-started/set-up-infrastructure-defense/): Enroll your first servers step by step. Create an activation key, install the Sentinel Host agent on Windows, Linux or macOS (including MSI mass deployment), meet your fleet on the Assets screen, and set the policies that govern assessment and patching. - [Set up Sentinel Probes](https://docs.wasviking.com/getting-started/sentinel-probes/): Bring the network view to Infrastructure Defense. A Sentinel Probe is a virtual scanner appliance that discovers every device on the networks you authorize and checks it for exposure, with no agent on the target. This guide covers what it is, why it satisfies PCI DSS internal scanning, and how to install, scope and read it. - [Set up Header Advisor](https://docs.wasviking.com/getting-started/header-advisor/): Add one report-only header at your edge or origin, let the browsers of your users teach WASViking what the application loads, then approve and roll out the Content Security Policy in two moves. - [Endpoint protection exclusions for Sentinel Host](https://docs.wasviking.com/getting-started/endpoint-protection-exclusions/): What to exclude in your antivirus, endpoint detection and TLS inspection products so the Sentinel Host agent can register, report and update. Covers the domains, folders, processes and ports the agent uses, the check that names the product in the way, and where the setting lives in the most common products. - [Bring your internet-facing assets under management](https://docs.wasviking.com/getting-started/attack-surface-coverage/): Cross the Attack Surface with Infrastructure Defense. See which of the internet-facing assets you own are served by a host you manage, which are not, and take each unmanaged one from "we found this exposed" to "this is now under control" in a few clicks. - [Roll back a change that misbehaved](https://docs.wasviking.com/getting-started/roll-back-a-change/): Undo a completed security update job from WASViking Resolve. Each package returns to the version it had before, the change goes through the same approval and window as the update did, the reassess measures the risk that came back, and the returned updates stay out of the recommendations until you decide otherwise. ## Concepts - [Targets and assets](https://docs.wasviking.com/concepts/targets-and-assets/): How WASViking represents what you scan, and the difference between a target you declare and an asset the engine discovers. - [Findings and Risk Score](https://docs.wasviking.com/concepts/findings-and-risk-score/): What a finding is, how WASViking ranks it, and how the workflow keeps the team operating on the highest risk first. - [Scan profiles and templates](https://docs.wasviking.com/concepts/scan-profiles-and-templates/): How WASViking selects which analyzers run, and how to lock a baseline your whole team uses. - [Environment Profile](https://docs.wasviking.com/concepts/environment-profile/): The per-host fingerprint that lets WASViking analyzers adapt to your stack instead of firing a static catalog. - [Exploit Path Graph](https://docs.wasviking.com/concepts/exploit-path-graph/): How WASViking materializes attack chains across findings and ranks them by chokepoint. ## Capabilities - [External DAST](https://docs.wasviking.com/capabilities/external-dast/): Coverage, analyzers, and how WASViking calibrates payloads to the environment. - [Modern API Security](https://docs.wasviking.com/capabilities/modern-api-security/): GraphQL, SOAP/WSDL, WebSocket, and JWT analyzers in one platform, with shared discovery and shared session. - [Out-of-Band Validation (OAST)](https://docs.wasviking.com/capabilities/out-of-band-validation/): How WASViking confirms blind vulnerabilities with its own out-of-band collaborator, and how to review captured interactions in the portal. No third-party data path. - [Software Supply Chain (SBOM, SCA, KEV)](https://docs.wasviking.com/capabilities/software-supply-chain/): Four coordinated layers that answer OWASP A06, from cloud-side detection to a signed Evidence Bundle. - [Supply Chain Intel (Continuous Watch)](https://docs.wasviking.com/capabilities/supply-chain-intel/): Daily cross-reference of every submitted SBOM against OSV and CISA KEV, prioritized by EPSS exploitability, with formal risk acceptance, OpenVEX attestation, and a branded Exploitability Report. - [Supply-chain IOC (Manual Indicators)](https://docs.wasviking.com/capabilities/supply-chain-ioc/): Operator-supplied indicators (package + version range) cross-referenced against every submitted SBOM. Dry-run before apply, full audit history. - [Secrets Detection](https://docs.wasviking.com/capabilities/secrets-detection/): Find leaked credentials on disk, in git history, and in public web responses. AI classifier triages matches before promotion. Verified-live secrets flagged for immediate rotation. - [Exposure Intelligence](https://docs.wasviking.com/capabilities/exposure-intelligence/): Monitor credential and identity exposure on domains you own. Domain ownership verified via DNS TXT. Explicit customer consent required. Sensitive fields masked by default; reveal actions audited. - [Edge Threat Radar](https://docs.wasviking.com/capabilities/edge-threat-radar/): Correlate adversary traffic at your CDN edge with your own findings, with real risk amplification. - [Certificate Monitoring](https://docs.wasviking.com/capabilities/certificate-monitoring/): Continuous SSL/TLS certificate health monitoring with expiration alerts, protocol/cipher inspection, and auto-discovery across subdomains. - [Sensitive Port Monitoring](https://docs.wasviking.com/capabilities/sensitive-port-monitoring/): Continuous monitoring of risky and customer-specified network ports on your public assets, with findings in the report and alerts when a port that should not be exposed appears on the internet. - [Scan Schedules](https://docs.wasviking.com/capabilities/scan-schedules/): Predictable, operator-defined recurring scans with locked-template compliance windows, per-schedule preferences, and explicit enable/disable state. - [AI Scan Planner](https://docs.wasviking.com/capabilities/ai-scan-planner/): Daily portfolio review that picks which targets to scan today and explains why. Contestable by the operator at every step. Complements Scan Schedules and manual scans. - [WASViking AI Guardian](https://docs.wasviking.com/capabilities/ai-guardian/): AI exposure monitoring on employee endpoints. Detects sensitive data sent to public AI tools, enforces organization policy at paste time, and reports activity per user, device, and AI application. - [Mobile Security Assessment](https://docs.wasviking.com/capabilities/mobile-security/): Static security assessment of Android and iOS application packages against the OWASP Mobile Application Security Verification Standard, with SBOM, contextual risk scoring, and release-to-release comparison. - [Infrastructure Defense](https://docs.wasviking.com/capabilities/infrastructure-defense/): Security posture for your infrastructure. The Sentinel Host agent inventories each machine and the Sentinel Probe scans the networks around them, the cloud correlates vulnerabilities and misconfigurations, the Viking Exposure Score prioritizes them, and Resolve executes approved fixes with a measured risk reduction. - [Header Advisor](https://docs.wasviking.com/capabilities/header-advisor/): Learn the Content Security Policy an application really needs from the browsers of its own users, deploy it with confidence, and keep it current as the application changes. - [Code Security](https://docs.wasviking.com/capabilities/code-security/): Connect your GitHub or Bitbucket repositories and let WASViking assess the source continuously with static application security testing (SAST), AI / LLM security review, dependency analysis, secret detection and SBOM generation, with every risk and its remediation context in one place. ## Sentinel agent - [Sentinel architecture](https://docs.wasviking.com/sentinel/architecture/): How the agent dials outbound mTLS to open a tunnel, and why no inbound port is ever required. - [Installing the Sentinel agent](https://docs.wasviking.com/sentinel/installation/): Register an agent in the portal, install the signed package, register on the host to fetch certificates, and start the service. mTLS to your tenant, no inbound ports. - [Internal scanning](https://docs.wasviking.com/sentinel/internal-scanning/): Run a WASViking scan against an internal target through the agent tunnel. - [wasviking-sentinel sbom](https://docs.wasviking.com/sentinel/sentinel-sbom/): Generate a CycloneDX 1.5 SBOM on-premises, enrich with OSV and CISA KEV, and submit to your tenant. - [wasviking-sentinel secrets](https://docs.wasviking.com/sentinel/sentinel-secrets/): Find leaked secrets on disk and in git history, optionally verify them live, with raw secrets never leaving the host. - [wasviking-sentinel mobile](https://docs.wasviking.com/sentinel/sentinel-mobile/): Submit an Android or iOS application package from any pipeline for a static assessment against OWASP MASVS and MASTG, with a baseline diff and deterministic exit codes. - [wasviking-sentinel in CI/CD](https://docs.wasviking.com/sentinel/sentinel-ci/): Drop the same Go binary in your pipeline for SBOM, secrets, mobile assessment, and policy-driven cloud scans. Independent gates, one preflight, deterministic exit codes. ## Integrations - [Notification Channels](https://docs.wasviking.com/integrations/notification-channels/): The central place to configure automated security alert delivery across Slack, Microsoft Teams, API Webhook, and Email, with a shared event subscription model. - [Slack and Teams](https://docs.wasviking.com/integrations/slack-teams/): Route findings, SLA breaches, and supply chain alerts to your team's channel. - [Run scans from Slack](https://docs.wasviking.com/integrations/run-scans-from-slack/): Connect your Slack workspace and start a scan from any channel with /wasviking scan, then get the results posted back when the scan finishes. - [Webhooks](https://docs.wasviking.com/integrations/webhooks/): Subscribe to signed JSON events for SIEM ingestion, automation, or anything that doesn't fit a built-in integration. - [Jira](https://docs.wasviking.com/integrations/jira/): Step by step setup of the Atlassian Jira integration, from the API token to the first synced issue. - [Jira labels](https://docs.wasviking.com/integrations/jira-labels/): The complete catalog of labels WASViking writes on Jira issues, the rules the sync follows, and a playbook for organizing boards, automation and reporting by team. - [ServiceNow](https://docs.wasviking.com/integrations/servicenow/): Two-way sync of findings with ServiceNow incidents, with state mapping, sync filters, and polling. - [SIEM](https://docs.wasviking.com/integrations/siem/): Ship WASViking findings, audit events, and supply chain alerts into your SIEM. - [SAML 2.0 SSO](https://docs.wasviking.com/integrations/saml-sso/): Federate WASViking with your IdP using SAML 2.0. Attribute mapping, default role policy, and a Google Workspace step-by-step. ## API Reference - [Authentication](https://docs.wasviking.com/api-reference/authentication/): Authenticate to the WASViking REST API with an ApiKey scheme. Bearer is silently rejected. - [Scopes catalog](https://docs.wasviking.com/api-reference/scopes/): Every scope a WASViking API key can carry, what it allows, and which UI surface exposes it. - [Endpoints](https://docs.wasviking.com/api-reference/endpoints/): The core REST endpoints, grouped by resource. Every endpoint requires an ApiKey header. - [Webhook events](https://docs.wasviking.com/api-reference/webhook-events/): The event catalog WASViking emits, the payload shape, and how to verify the signature. - [Rate limits](https://docs.wasviking.com/api-reference/rate-limits/): Per-key limits, how they are signaled, and how to handle 429s correctly. ## Compliance - [Framework mapping](https://docs.wasviking.com/compliance/framework-mapping/): How WASViking maps findings to PCI DSS v4.0, LGPD, GDPR, BACEN, and ISO 27001:2022 controls from one rule table. - [SBOM Evidence Bundle](https://docs.wasviking.com/compliance/evidence-bundle/): The signed artifact your auditor or customer accepts in lieu of a portal access. - [Posture Shares](https://docs.wasviking.com/compliance/posture-shares/): Prove your security posture to a third party without giving them portal access. ## Partner Console - [Partner Console overview](https://docs.wasviking.com/partner-console/overview/): What the partner console is, where it lives, and how it sits next to the customer portal. - [Operating models](https://docs.wasviking.com/partner-console/operating-models/): Customer-managed, co-managed, fully-managed. Same product, three relationship modes, the boundary in code. - [Quote engine and pricing](https://docs.wasviking.com/partner-console/quote-engine/): How the live quote calculator works, how guardrails protect unit economics, and how auto-provisioning fits. - [Customer demos](https://docs.wasviking.com/partner-console/customer-demos/): Provision a populated demo tenant in minutes. Auto-destroy in 24 hours. Zero garbage left behind. - [Billing](https://docs.wasviking.com/partner-console/billing/): Consolidated monthly invoices, annual prepaid, monthly commit, soft-limit overage. How partner billing actually works. ## Security - [Platform architecture](https://docs.wasviking.com/security/platform-architecture/): How WASViking is built and operated. The security posture, the isolation model, and the engineering practices behind the platform. - [Tenant isolation and data handling](https://docs.wasviking.com/security/tenant-isolation/): How WASViking keeps organizations apart, what we encrypt, what we keep, and what never leaves your environment. - [Reporting vulnerabilities](https://docs.wasviking.com/security/reporting-vulnerabilities/): How to report a security issue to WASViking. Coordinated disclosure, safe harbor, response timelines. - [Account closure and data erasure](https://docs.wasviking.com/security/account-closure-and-data-erasure/): How an organization administrator closes a WASViking account, what happens during the 60-day reversible window, what is erased, what is kept and why, and how the erasure is evidenced. ## Optional - [WASViking website](https://wasviking.com/): Product pages, pricing and the partner program. - [Page map for AI assistants](https://wasviking.com/llms.txt): The curated map of WASViking's public pages. - [Platform brief for AI assistants](https://wasviking.com/llms-full.txt): What WASViking is, what each capability does and how to describe it accurately. - [Trust Center](https://wasviking.com/trust-center/): Security practices and every legal document. - [Request a demo](https://wasviking.com/get-a-demo/): Demo and quote requests.