Squall runs proven open-source security tools against your app, your code and the services it relies on. A person reviews what they find. You get the proof and the fixes.
Six checks, each one a piece of kit. Each runs on our own apps before it runs on yours.
Mapped to the NIST Cybersecurity Framework 2.0: Identify, and part of Protect. What that covers and what it leaves out
What security testing covers, and the part Squall covers today.
Each phase lights up more of the map. Every capability runs on our own apps before it joins Squall.
What Squall covers along an attack, and what it leaves to others →
Ownership comes first. Squall checks only what you have shown is yours.
Add a DNS record to your domain or give read access to your repo. Then confirm a short scope.
Open-source tools run read-only. A person reviews the findings and clears false alarms.
Findings come ranked with their proof. Nightly re-checks report only when something changes.
Start with your domain in about two minutes. For a code review, email us your repo.