For security & GRC teams

Organization security assessment in one API call

POST /v1/org-assessment merges URL scan, optional agent artifact, and boundary trace into one gate with SARIF and executive brief exports.

Requirements before you submit

After submit — artifacts for GRC

  1. Gate verdict: pass / warn / fail on unified posture.
  2. GET /v1/reports/{id}/sarif for GitHub Advanced Security.
  3. GET /v1/reports/{id}/brief.md for audit packet narrative.
  4. Framework tags on findings are mapping — not SOC 2 certification.

Back to Shield home