Skip to main content

Offload Security

Offload Security is a unified CNAPP, vulnerability management and compliance platform that consolidates findings across cloud, code, containers, Kubernetes, applications, on-premises infrastructure and Wazuh-monitored endpoints into one governed risk view. It brings cloud security, vulnerability management, container and Kubernetes security, code and supply-chain security, compliance and risk (GRC), threat intelligence, and AI-driven security operations together in a single, multi-tenant platform — so your team works from one source of truth instead of a dozen disconnected tools.

This documentation helps you onboard, configure, and operate the platform end to end — whether you're connecting your first cloud account or rolling it out across a security organization.

New here?

What you can do with it

Offload Security is organized into five areas that map directly to the product's left-hand navigation. Each line links to the section of these docs that covers it.

🛡️ Core Security

Run and review security testing from one place.

  • Dashboard — security posture, metrics and top risks at a glance; the Executive Dashboard tab for leadership — Reports & AI.
  • Scanning — web (OWASP ZAP, Nuclei), network (nmap), SSL/TLS (testssl.sh), security headers, API security testing and domain reconnaissance — App & Infrastructure Scanning.
  • Code Command Center — SAST, secrets detection, dependency (SCA) and IaC scanning, SBOMs with licence compliance, fix pull requests — Code Security.
  • Vulnerability Management — one triage queue across every source, risk scoring, SLA tracking, deduplication, remediation guidance — Vulnerabilities & Risk.
  • Security Command Center — agents that triage, prepare fixes and answer posture questions, with an approval-gated Auto-Fix Engine — Security Command Center.
  • Alerts — the unified alert stream from every module, with routing to Slack, Teams, email and PagerDuty — Alerts.

☁️ Cloud & Infrastructure

Continuously assess everything you run in the cloud.

  • Cloud Security (CSPM) — AWS, Azure and GCP misconfiguration scanning, identity and network analysis, real-time cloud events, remediation queue — Cloud Security.
  • Container Security — registry discovery and image scanning (ECR, GCR / Artifact Registry, ACR, Docker Hub, private registries) with SBOMs and image policies — Container Security.
  • Kubernetes Security — cluster onboarding, scanning, fleet heat map and compliance — Kubernetes Security.
  • Asset Inventory — a live catalog of cloud resources, clusters, repositories and Wazuh endpoints across accounts and regions — Asset Inventory.
  • Attack Path Analysis — graph-based discovery of exploitable paths to high-value assets — Attack Paths.

📋 Compliance & Risk

Turn findings into audit-ready governance.

  • Compliance Posture — frameworks (SOC 2, ISO 27001, PCI DSS, NIST CSF, SEBI CSCRF, DPDP and more) on one SCF control library, with continuous scoring, evidence and drift detection — Compliance & GRC.
  • Risk Management — a risk register with treatment plans, controls, appetite and KRIs, promoted from findings or imported — Risk Management.
  • Assessments — guided, scored questionnaires (OWASP ASVS, NIST CSF 2.0, NIST SSDF, SOC 2, SAMM, ISO 27001 and others) with SCF-based auto-fill — Assessments.
  • Audit Reports & DPDP Compliance — controls, findings, drift and remediation exports for auditors; India's DPDP Act module with DPIAs, breach workflow and audit pack — Audit Reports · DPDP.

🧠 Threat & Intelligence

Add context and automation to detection.

  • Threat Intelligence — nine curated feeds (CISA KEV, URLhaus, OTX, Feodo Tracker, PhishTank and more) fetched hourly, IOC correlation against your assets, KEV-weighted CVE prioritisation, ATT&CK coverage — Threat Intelligence.
  • AI Governance — a registry of your AI systems with risk assessments, incidents, discovery in your cloud and code (AIBOM), prompt-injection tests and an ISO 42001 posture — AI Governance.
  • Knowledge Base — your policies as a searchable library that answers questions and fills security questionnaires — Knowledge Base.

⚙️ Management

Configure, integrate, and administer.


Who this is for

AudienceWhere to focus
Security engineers & analystsScanning, Vulnerability Management, Container / Kubernetes, Security Command Center, Threat Intelligence
CISOs & security leadersExecutive Dashboard, Risk Management, Compliance, Reports & AI
Compliance officers & auditorsCompliance Posture, Assessments, Audit Reports
DevSecOps teamsCLI & CI/CD integration, Code Command Center, Container Security
Platform operators (self-hosting)On-Premises, Platform Administration, Production configuration

Start here

  1. Quickstart — sign in, connect your first cloud account, and reach your first reviewed finding in about 30 minutes.
  2. First 7 Days — a day-by-day plan that turns the first scan into an operating program: baseline, prioritization, SLAs, compliance, shift-left, and executive reporting.
  3. Follow your role — the Security Engineer or Compliance Officer journey walks the docs in the order that persona needs them.
  4. Harden it — check your setup against the Recommended Production Configuration, and wire scans into your pipeline with CLI & CI/CD integration.
A note on accuracy

This documentation describes capabilities that exist in the platform today. Where a feature requires specific configuration, prerequisites, or permissions, those are called out explicitly so you can plan accordingly.

Need help?

Frequently asked questions

What is Offload Security?

Offload Security is a unified CNAPP, vulnerability management and compliance platform that consolidates findings across cloud, code, containers, Kubernetes, applications, on-premises infrastructure and Wazuh-monitored endpoints into one governed risk view.

Is Offload Security SaaS or on-premises?

Both. Offload Security runs as a multi-tenant SaaS platform or can be deployed fully on-premises / self-hosted, so regulated organisations can keep data inside their own environment.

What does Offload Security consolidate?

Cloud security (CSPM), code and supply-chain security, container and Kubernetes security, vulnerability management, compliance and risk (GRC), threat intelligence, and the endpoint telemetry from a Wazuh you connect — all into one deduplicated, risk-scored view.