CYBERVOC / Documentation

From your first scan
to your next fix.

A practical guide to connecting your code, testing your application and working with the results.

01 / Getting started

Your first scan

  1. Create your account and complete the verification steps.
  2. Add a project with its repository URL. Provide repository access if the code is private.
  3. Select the scan types. Add your application URL to include DAST.
  4. Launch your scan and open its details to review progress and results.

Your free trial includes one complete scan with critical vulnerability results. Scan coverage depends on the files and endpoints available to the scanner.

02 / Repositories

Connect GitHub or GitLab

Use the HTTPS URL of your repository and select the branch to scan. For private code, enable private repository access and provide a token with the required read permissions.

Use a token limited to the repositories you intend to scan. Never put a token in the repository URL or a public report. Revoke tokens you no longer use.

03 / Automation

Make scanning a recurring check

Configure the project scan schedule, select your scan types and branch, then save the settings. For scheduled DAST scans, the project must also have an application URL.

Results are available in CYBERVOC after each run. The Developer plan allows one complete scan per day for 30 days; configure your schedule within that allowance.

04 / Web applications

Test what is actually running

Provide the HTTP(S) URL of a reachable application. Dynamic testing examines accessible pages, responses and endpoints for security weaknesses, regardless of the language behind them.

Only test applications you own or have explicit authorization to assess. Active scans can affect application behaviour. Prefer a suitable test environment, agree on the scope and ensure your target is available during the scan.

Explore DAST coverage →

05 / Coverage

Match the scan to your stack

SAST
Source-code analysis for languages including JavaScript, TypeScript, Python, Java, Go, C#, PHP and Ruby. Detection depends on enabled rules and language support.
SCA
Known vulnerabilities in supported dependency manifests and lockfiles: npm, Yarn, pnpm, pip, Poetry, Maven, Gradle, Go modules, NuGet, Composer, Bundler and Cargo. Results depend on the package and version information available.
IaC security
Misconfigurations in supported Terraform files, Kubernetes manifests, Helm charts, Dockerfiles and CloudFormation templates.
Secret detection
Recognizable API keys, access tokens, private keys and credentials in the scanned repository files. This is not a guarantee that every secret will be detected.
SBOM generation
A software component inventory with identified names and versions, giving you a view of what your application depends on.
DAST
Dynamic checks against reachable HTTP(S) application endpoints. Coverage depends on what the scan can discover and access.

06 / Findings to fixes

Export a PDF. Bring the context.

Open a scan and select Export PDF. Save the report as a PDF using the browser print dialog. The report includes finding details and remediation guidance when available.

Share the report with your team or an external AI coding agent to help investigate and propose fixes. Before sharing, review it for sensitive file paths, URLs and credentials. Your external agent has its own data handling policies.

CYBERVOC does not automatically change your code. Review generated changes, test them and run another scan to check the result.

07 / Plans

A clear starting point

Free: one complete scan with critical vulnerability results.

Developer: €9.99 excluding VAT for 30 days, with one complete scan per day, recurring scans and PDF reporting.

Start with your free scan