Introduction
What ScanSuite is, what it scans, and how the platform fits together.
ScanSuite is a security scanning orchestration platform. It takes the things you already have — a repository, a running web application, a range of hosts, a container image — and runs security analysis against them, on self-hosted infrastructure.
Two kinds of engine work side by side. AI agents plan their own work, call tools, and verify what they find against the real system before reporting it. Classic scanners — more than thirty open-source and commercial engines — run in parallel in isolated containers. Both feed the same finding pipeline, so results arrive deduplicated and in one place.
What you can point it at
- Source code archives
- Code repositories, including monitored branches that scan on change
- Web application and API URLs
- Host names, IP addresses and domains
- Container image names
ScanSuite selects the appropriate scanners through pre-configured connectors and invokes them with parameters tuned for the target, rather than asking you to assemble a scan profile yourself.
What comes back
Findings are normalised into a single vulnerability record, deduplicated within the scan and against history, and managed in ScanSuite's own Vulnerabilities section — triaged, assigned an owner and due date, tracked to closure and proven with a runnable exploit, all without leaving the platform. Raw scanner reports and structured parsed results are both available for download.
Bug tracking is built in: the AI-driven scans — AI Native SAST, dependency reachability, AI DAST and AI Pentest — are managed entirely inside ScanSuite. An optional integration with DefectDojo is available for teams that already use it as their bug tracker, where classic-scanner findings can be exported per scanner if you want them. It is not required.
Teams that track remediation in ServiceNow are served differently, and deliberately so: ScanSuite exports a ServiceNow-shaped spreadsheet, and the statuses the ServiceNow workflow sets come back the same way. There is no direct connection, no stored credentials and no outbound calls — the exchange is files, on local terms. See Rescans and fix verification.
Everything runs inside the perimeter. ScanSuite can be deployed on-premises, in a private cloud, or fully offline — source code and findings stay where they are put.
How you reach it
- A web dashboard
- A command-line interface
- CI/CD pipelines
Two editions
| Edition | What it gives you |
|---|---|
| ScanSuite | One installation, shared by everyone who signs in. Users and settings are administered in one place. |
| ScanSuite Teams | Everything above, plus teams. Each team has its own products, scans, findings, assets, credentials and settings, and people hold a role in each team they belong to. It also adds installation administration at /admin, single sign-on, API tokens for automation, and the pipeline build gate. |
Chapters that describe a Teams feature are marked Teams in the sidebar and say so before the first heading.
Start here
If you are new to the platform, read Architecture to understand how the components fit together, then work through installation.
Last reviewed 2026-08-15