CYBERVOC / Documentation
From your first scan
to your next fix.
A practical guide to connecting your code, testing your application and working with the results.
01 / Getting started
Your first scan
- Create your account and complete the verification steps.
- Add a project with its repository URL. Provide repository access if the code is private.
- Select the scan types. Add your application URL to include DAST.
- Launch your scan and open its details to review progress and results.
Your free trial includes one complete scan with critical vulnerability results. Scan coverage depends on the files and endpoints available to the scanner.
02 / Repositories
Connect GitHub or GitLab
Use the HTTPS URL of your repository and select the branch to scan. For private code, enable private repository access and provide a token with the required read permissions.
Use a token limited to the repositories you intend to scan. Never put a token in the repository URL or a public report. Revoke tokens you no longer use.
03 / Automation
Make scanning a recurring check
Configure the project scan schedule, select your scan types and branch, then save the settings. For scheduled DAST scans, the project must also have an application URL.
Results are available in CYBERVOC after each run. The Developer plan allows one complete scan per day for 30 days; configure your schedule within that allowance.
04 / Web applications
Test what is actually running
Provide the HTTP(S) URL of a reachable application. Dynamic testing examines accessible pages, responses and endpoints for security weaknesses, regardless of the language behind them.
Only test applications you own or have explicit authorization to assess. Active scans can affect application behaviour. Prefer a suitable test environment, agree on the scope and ensure your target is available during the scan.
Explore DAST coverage →05 / Coverage
Match the scan to your stack
- SAST
- Source-code analysis for languages including JavaScript, TypeScript, Python, Java, Go, C#, PHP and Ruby. Detection depends on enabled rules and language support.
- SCA
- Known vulnerabilities in supported dependency manifests and lockfiles: npm, Yarn, pnpm, pip, Poetry, Maven, Gradle, Go modules, NuGet, Composer, Bundler and Cargo. Results depend on the package and version information available.
- IaC security
- Misconfigurations in supported Terraform files, Kubernetes manifests, Helm charts, Dockerfiles and CloudFormation templates.
- Secret detection
- Recognizable API keys, access tokens, private keys and credentials in the scanned repository files. This is not a guarantee that every secret will be detected.
- SBOM generation
- A software component inventory with identified names and versions, giving you a view of what your application depends on.
- DAST
- Dynamic checks against reachable HTTP(S) application endpoints. Coverage depends on what the scan can discover and access.
06 / Findings to fixes
Export a PDF. Bring the context.
Open a scan and select Export PDF. Save the report as a PDF using the browser print dialog. The report includes finding details and remediation guidance when available.
Share the report with your team or an external AI coding agent to help investigate and propose fixes. Before sharing, review it for sensitive file paths, URLs and credentials. Your external agent has its own data handling policies.
CYBERVOC does not automatically change your code. Review generated changes, test them and run another scan to check the result.
07 / Plans
A clear starting point
Free: one complete scan with critical vulnerability results.
Developer: €9.99 excluding VAT for 30 days, with one complete scan per day, recurring scans and PDF reporting.
Start with your free scan