Skip to main content

Platform at a Glance

Offload Security is organized into modules that each own a domain of security work — and all feed the same correlated data model, or data lake. This page is a map: what each module does, and where to read more.

How the modules connect

Findings from every source converge in Vulnerability Management, resolve against the Asset Inventory, promote into the Risk Register, update Compliance controls, and generate Evidence and Reports — with AI assisting throughout and Integrations pushing to the systems you already run.

The modules

Detection & scanning

ModuleWhat it doesRead more
Cloud Security (CSPM)Continuous misconfiguration assessment of AWS, Azure and GCP, identity and network analysis, real-time cloud events, a remediation queue.Cloud Security
Application SecurityWeb (OWASP ZAP, Nuclei), API, network (Nmap), and SSL/TLS testing of your applications and services.App & Infrastructure Scanning
SAST & Code SecurityStatic analysis, secrets detection, and IaC scanning of your source and pipelines.API & Code Scanning
SBOM & License ScanningSoftware bill-of-materials generation and open-source license compliance across code and container images.Container Security
Container SecurityRegistry discovery and image scanning across ECR, GCR / Artifact Registry, ACR, Docker Hub and private registries, with SBOMs and image policies.Container Security
Kubernetes SecurityCluster onboarding and scanning, a fleet heat map, grouped findings and compliance reports.Kubernetes Security
On-PremisesThe whole platform self-hosted; network and private URL/API scanning of internal targets, Wazuh endpoint telemetry synced in, Greenbone / OpenVAS connected — for assets that never leave your network.On-Premises

Unify, prioritize & govern

ModuleWhat it doesRead more
Vulnerability ManagementThe unified queue: triage, risk scoring, deduplication, SLA tracking, and remediation guidance across every source.Vulnerability Management
Asset InventoryA live catalog of resources across clouds, accounts, regions, and the internal network.Asset Inventory
Risk RegisterAn enterprise risk register auto-minted from findings, with treatment plans and SLAs.Risk Register
Compliance & GRCFramework tracking (SOC 2, ISO 27001, NIST CSF, PCI-DSS, and more), guided assessments, and drift detection.Compliance
Evidence ManagementAn auditable evidence vault, captured as work happens and mapped to controls.Evidence Hub
AlertsCentralized, deduplicated alerting across sources, routed to Slack, Teams, email, PagerDuty and webhooks.Alerts

Act, prove & extend

ModuleWhat it doesRead more
ReportsExecutive dashboard, scheduled reports and a catalog of exports (PDF, HTML, Word, CSV, XLSX) from live data.Reports & AI
Knowledge BaseA searchable store of policies, standards, and answers that powers questionnaire auto-fill and AI guidance.Knowledge Base
Security Command CenterAgents that triage (rule-based, LLM-assisted when configured), prepare fixes, correlate incidents and answer posture questions; an approval-gated Auto-Fix Engine.Security Command Center
Threat IntelligenceNine curated feeds (CISA KEV, URLhaus, OTX, Feodo Tracker, PhishTank and more) fetched hourly, IOC correlation against your assets, KEV-weighted CVE prioritisation, ATT&CK coverage.Threat Intelligence
IntegrationsSlack, Teams, email and PagerDuty for alerts; Jira two-way ticketing; Wazuh, SonarQube and Jenkins pulling data in; signed webhook subscriptions for any SIEM or automation.Integrations

Solutions by industry

Offload Security maps these modules to the outcomes specific sectors need — from PCI-DSS and audit evidence in banking and financial services to data-protection and internal-network coverage in healthcare and manufacturing. See Solutions by Industry.