Offload Security
Offload Security is a unified CNAPP, vulnerability management and compliance platform that consolidates findings across cloud, code, containers, Kubernetes, applications, on-premises infrastructure and Wazuh-monitored endpoints into one governed risk view. It brings cloud security, vulnerability management, container and Kubernetes security, code and supply-chain security, compliance and risk (GRC), threat intelligence, and AI-driven security operations together in a single, multi-tenant platform — so your team works from one source of truth instead of a dozen disconnected tools.
This documentation helps you onboard, configure, and operate the platform end to end — whether you're connecting your first cloud account or rolling it out across a security organization.
- Understand the "why" → Introduction: what Offload Security is, the problem it solves, and why to choose it over fragmented tools.
- Cover your private infrastructure → On-Premises & Private Infrastructure: internal-network visibility, OpenVAS scanning, and the Wazuh integration.
- See it for your sector → Solutions by Industry, including a detailed Banking & Financial Services breakdown.
- Just get running → jump straight to Quickstart.
What you can do with it
Offload Security is organized into five areas that map directly to the product's left-hand navigation. Each line links to the section of these docs that covers it.
🛡️ Core Security
Run and review security testing from one place.
- Dashboard — security posture, metrics and top risks at a glance; the Executive Dashboard tab for leadership — Reports & AI.
- Scanning — web (OWASP ZAP, Nuclei), network (nmap), SSL/TLS (testssl.sh), security headers, API security testing and domain reconnaissance — App & Infrastructure Scanning.
- Code Command Center — SAST, secrets detection, dependency (SCA) and IaC scanning, SBOMs with licence compliance, fix pull requests — Code Security.
- Vulnerability Management — one triage queue across every source, risk scoring, SLA tracking, deduplication, remediation guidance — Vulnerabilities & Risk.
- Security Command Center — agents that triage, prepare fixes and answer posture questions, with an approval-gated Auto-Fix Engine — Security Command Center.
- Alerts — the unified alert stream from every module, with routing to Slack, Teams, email and PagerDuty — Alerts.
☁️ Cloud & Infrastructure
Continuously assess everything you run in the cloud.
- Cloud Security (CSPM) — AWS, Azure and GCP misconfiguration scanning, identity and network analysis, real-time cloud events, remediation queue — Cloud Security.
- Container Security — registry discovery and image scanning (ECR, GCR / Artifact Registry, ACR, Docker Hub, private registries) with SBOMs and image policies — Container Security.
- Kubernetes Security — cluster onboarding, scanning, fleet heat map and compliance — Kubernetes Security.
- Asset Inventory — a live catalog of cloud resources, clusters, repositories and Wazuh endpoints across accounts and regions — Asset Inventory.
- Attack Path Analysis — graph-based discovery of exploitable paths to high-value assets — Attack Paths.
📋 Compliance & Risk
Turn findings into audit-ready governance.
- Compliance Posture — frameworks (SOC 2, ISO 27001, PCI DSS, NIST CSF, SEBI CSCRF, DPDP and more) on one SCF control library, with continuous scoring, evidence and drift detection — Compliance & GRC.
- Risk Management — a risk register with treatment plans, controls, appetite and KRIs, promoted from findings or imported — Risk Management.
- Assessments — guided, scored questionnaires (OWASP ASVS, NIST CSF 2.0, NIST SSDF, SOC 2, SAMM, ISO 27001 and others) with SCF-based auto-fill — Assessments.
- Audit Reports & DPDP Compliance — controls, findings, drift and remediation exports for auditors; India's DPDP Act module with DPIAs, breach workflow and audit pack — Audit Reports · DPDP.
🧠 Threat & Intelligence
Add context and automation to detection.
- Threat Intelligence — nine curated feeds (CISA KEV, URLhaus, OTX, Feodo Tracker, PhishTank and more) fetched hourly, IOC correlation against your assets, KEV-weighted CVE prioritisation, ATT&CK coverage — Threat Intelligence.
- AI Governance — a registry of your AI systems with risk assessments, incidents, discovery in your cloud and code (AIBOM), prompt-injection tests and an ISO 42001 posture — AI Governance.
- Knowledge Base — your policies as a searchable library that answers questions and fills security questionnaires — Knowledge Base.
⚙️ Management
Configure, integrate, and administer.
- Account Setup (Connecting Cloud Accounts), Integrations (Slack, Teams, email, PagerDuty, Jira, Wazuh, webhooks — Integrations), Unified Scheduler, and, from the account menu, Team Management, API Keys and MFA (Platform Security). Pipelines use the CLI and GitHub Action — CLI & CI/CD.
Who this is for
| Audience | Where to focus |
|---|---|
| Security engineers & analysts | Scanning, Vulnerability Management, Container / Kubernetes, Security Command Center, Threat Intelligence |
| CISOs & security leaders | Executive Dashboard, Risk Management, Compliance, Reports & AI |
| Compliance officers & auditors | Compliance Posture, Assessments, Audit Reports |
| DevSecOps teams | CLI & CI/CD integration, Code Command Center, Container Security |
| Platform operators (self-hosting) | On-Premises, Platform Administration, Production configuration |
Start here
- Quickstart — sign in, connect your first cloud account, and reach your first reviewed finding in about 30 minutes.
- First 7 Days — a day-by-day plan that turns the first scan into an operating program: baseline, prioritization, SLAs, compliance, shift-left, and executive reporting.
- Follow your role — the Security Engineer or Compliance Officer journey walks the docs in the order that persona needs them.
- Harden it — check your setup against the Recommended Production Configuration, and wire scans into your pipeline with CLI & CI/CD integration.
This documentation describes capabilities that exist in the platform today. Where a feature requires specific configuration, prerequisites, or permissions, those are called out explicitly so you can plan accordingly.
Need help?
- Visit offloadsecurity.com for the platform.
- See the Glossary for key terms used throughout this documentation.
Frequently asked questions
What is Offload Security?
Offload Security is a unified CNAPP, vulnerability management and compliance platform that consolidates findings across cloud, code, containers, Kubernetes, applications, on-premises infrastructure and Wazuh-monitored endpoints into one governed risk view.
Is Offload Security SaaS or on-premises?
Both. Offload Security runs as a multi-tenant SaaS platform or can be deployed fully on-premises / self-hosted, so regulated organisations can keep data inside their own environment.
What does Offload Security consolidate?
Cloud security (CSPM), code and supply-chain security, container and Kubernetes security, vulnerability management, compliance and risk (GRC), threat intelligence, and the endpoint telemetry from a Wazuh you connect — all into one deduplicated, risk-scored view.