Assets (projects & targets)
The specific things you scan — a repo, a site, an API, a cloud account.
Overview
An asset represents one thing you want to secure: a repository, a website, an API, a mobile app or a cloud account. Scans, findings and history attach to the asset so context stays together over time.
Assets live inside a workspace, giving you a tidy hierarchy from organisation down to the individual target.
How it works
When you run a scan you choose (or create) the asset it belongs to, and every result is filed under it.
Each asset exposes the relevant engines (SAST, SCA, DAST, API, mobile, container, CSPM, KSPM, VAPT) for that target type.
How to use it
- 1Open Assets from the sidebar.
- 2Create an asset for the target you want to secure.
- 3Open the asset and run the relevant scans against it.
- 4Track findings and re-scan over time from the same place.
When to use it
- Keeping all scans and history for one application together.
- Organising many targets within a single client engagement.
Tips & best practices
- Use consistent asset names so reports and trends are easy to read.
FAQ
- Can one asset have multiple scan types?
- Yes — an asset can be scanned by every engine relevant to its type.