Platform at a Glance
Offload Security is organized into modules that each own a domain of security work — and all feed the same correlated data model, or data lake. This page is a map: what each module does, and where to read more.
How the modules connect
Findings from every source converge in Vulnerability Management, resolve against the Asset Inventory, promote into the Risk Register, update Compliance controls, and generate Evidence and Reports — with AI assisting throughout and Integrations pushing to the systems you already run.
The modules
Detection & scanning
| Module | What it does | Read more |
|---|---|---|
| Cloud Security (CSPM) | Continuous misconfiguration assessment of AWS, Azure and GCP, identity and network analysis, real-time cloud events, a remediation queue. | Cloud Security |
| Application Security | Web (OWASP ZAP, Nuclei), API, network (Nmap), and SSL/TLS testing of your applications and services. | App & Infrastructure Scanning |
| SAST & Code Security | Static analysis, secrets detection, and IaC scanning of your source and pipelines. | API & Code Scanning |
| SBOM & License Scanning | Software bill-of-materials generation and open-source license compliance across code and container images. | Container Security |
| Container Security | Registry discovery and image scanning across ECR, GCR / Artifact Registry, ACR, Docker Hub and private registries, with SBOMs and image policies. | Container Security |
| Kubernetes Security | Cluster onboarding and scanning, a fleet heat map, grouped findings and compliance reports. | Kubernetes Security |
| On-Premises | The whole platform self-hosted; network and private URL/API scanning of internal targets, Wazuh endpoint telemetry synced in, Greenbone / OpenVAS connected — for assets that never leave your network. | On-Premises |
Unify, prioritize & govern
| Module | What it does | Read more |
|---|---|---|
| Vulnerability Management | The unified queue: triage, risk scoring, deduplication, SLA tracking, and remediation guidance across every source. | Vulnerability Management |
| Asset Inventory | A live catalog of resources across clouds, accounts, regions, and the internal network. | Asset Inventory |
| Risk Register | An enterprise risk register auto-minted from findings, with treatment plans and SLAs. | Risk Register |
| Compliance & GRC | Framework tracking (SOC 2, ISO 27001, NIST CSF, PCI-DSS, and more), guided assessments, and drift detection. | Compliance |
| Evidence Management | An auditable evidence vault, captured as work happens and mapped to controls. | Evidence Hub |
| Alerts | Centralized, deduplicated alerting across sources, routed to Slack, Teams, email, PagerDuty and webhooks. | Alerts |
Act, prove & extend
| Module | What it does | Read more |
|---|---|---|
| Reports | Executive dashboard, scheduled reports and a catalog of exports (PDF, HTML, Word, CSV, XLSX) from live data. | Reports & AI |
| Knowledge Base | A searchable store of policies, standards, and answers that powers questionnaire auto-fill and AI guidance. | Knowledge Base |
| Security Command Center | Agents that triage (rule-based, LLM-assisted when configured), prepare fixes, correlate incidents and answer posture questions; an approval-gated Auto-Fix Engine. | Security Command Center |
| Threat Intelligence | Nine curated feeds (CISA KEV, URLhaus, OTX, Feodo Tracker, PhishTank and more) fetched hourly, IOC correlation against your assets, KEV-weighted CVE prioritisation, ATT&CK coverage. | Threat Intelligence |
| Integrations | Slack, Teams, email and PagerDuty for alerts; Jira two-way ticketing; Wazuh, SonarQube and Jenkins pulling data in; signed webhook subscriptions for any SIEM or automation. | Integrations |
Solutions by industry
Offload Security maps these modules to the outcomes specific sectors need — from PCI-DSS and audit evidence in banking and financial services to data-protection and internal-network coverage in healthcare and manufacturing. See Solutions by Industry.