For security & GRC teams
Organization security assessment in one API call
POST /v1/org-assessment merges URL scan, optional agent artifact, and boundary trace into one gate with SARIF and executive brief exports.
Requirements before you submit
- Production URL you own or are authorized to test.
- Consent — checkbox on the form maps to
consent:truein the API. - Optional agent artifact — skill text,
mcp.json, or Cursor rules for supply-chain coverage. - Share — org assessment shares by default; exports include SARIF, brief, and JSON report.
After submit — artifacts for GRC
- Gate verdict:
pass/warn/failon unified posture. GET /v1/reports/{id}/sariffor GitHub Advanced Security.GET /v1/reports/{id}/brief.mdfor audit packet narrative.- Framework tags on findings are mapping — not SOC 2 certification.