Frequently asked questions
Find answers to the most common questions about SecureOps.
What is SecureOps?
SecureOps is an application security platform to scan websites and APIs, track results over time, and automate controls. It combines on-demand scans, scheduled scans, history, exports, and a public API for CI/CD integration.
How does the vulnerability scan work?
The scanner runs asynchronous jobs on your target URL (single URL or multi-URL within the same domain), then aggregates results into a score and actionable recommendations. Depending on the selected mode (passive, intrusive, destructive, or custom), checks range from security posture to active testing.
Is my data secure?
Yes. Access is protected with authentication (Cognito JWT or API keys depending on endpoints), traffic is served over HTTPS, and security headers are enforced (CSP, HSTS, and related policies). Account and scan history data are isolated per user.
Do I need to create an account to use the scanner?
Yes for most advanced usage: history, scheduled scans, PDF/CSV/JSON exports, preferences, quota management, and protected endpoints. Some public flows may remain available without an account, but automation and tracking require authentication.
What types of vulnerabilities are detected?
SecureOps covers posture checks (TLS/HTTPS, headers, cookies, exposed files, directory listings, information leakage), API-oriented checks, and active scenarios depending on the selected scan mode. Results include detailed findings, severity, and remediation guidance.
How often can I run scans?
You can run scans on demand and schedule recurring scans daily, weekly, or monthly with configurable time and timezone. Scheduled executions respect your quota, and exact limits are visible in your My Account space.
Didn't find the answer to your question? Contact us