Semgrep
Static rules with normalized locations and SARIF ingestion.
Authorized assessment workspace
Give TriZap a URL, repository, container image, or source bundle. One agent coordinates deterministic scanners and returns a report you can inspect, export, and reproduce.
00:00:02 Workspace prepared
00:00:07 Agent mapped assessment inputs
Next: correlate Semgrep and passive ZAP evidence
One controlled sequence
Every stage stays visible. The agent coordinates; the scanner output remains the source of truth.
Submit only targets and artifacts you are authorized to assess.
HTTP checks, Trivy, Semgrep, and passive ZAP run through constrained adapters.
Duplicate signals are joined while confidence and scanner coverage stay explicit.
Review the narrative, raw JSON, and normalized SARIF from the same run.
What it covers
Static rules with normalized locations and SARIF ingestion.
Dependencies, secrets, misconfiguration, filesystem, and image findings.
Spidering and passive alerts without active exploitation.
A readable report grounded in completed deterministic evidence.
Ready when you are