Authorized assessment workspace

Security evidence,
under one run.

Give TriZap a URL, repository, container image, or source bundle. One agent coordinates deterministic scanners and returns a report you can inspect, export, and reproduce.

4
scanner paths
SARIF
normalized export
Local
operator control
assessment / checkout-api running

00:00:02 Workspace prepared

00:00:07 Agent mapped assessment inputs

TRIVY Scanning container layers
18 / 26

Next: correlate Semgrep and passive ZAP evidence

One controlled sequence

From input to evidence trail.

Every stage stays visible. The agent coordinates; the scanner output remains the source of truth.

  1. 01

    Define scope

    Submit only targets and artifacts you are authorized to assess.

  2. 02

    Run in isolation

    HTTP checks, Trivy, Semgrep, and passive ZAP run through constrained adapters.

  3. 03

    Correlate findings

    Duplicate signals are joined while confidence and scanner coverage stay explicit.

  4. 04

    Export evidence

    Review the narrative, raw JSON, and normalized SARIF from the same run.

What it covers

Code. Images. Reachable surfaces.

01 / CODE

Semgrep

Static rules with normalized locations and SARIF ingestion.

02 / SUPPLY CHAIN

Trivy

Dependencies, secrets, misconfiguration, filesystem, and image findings.

03 / WEB

ZAP baseline

Spidering and passive alerts without active exploitation.

04 / CONTEXT

Agent synthesis

A readable report grounded in completed deterministic evidence.

Ready when you are

Start with a target you control.

Enter the workspace