# Documentation

Products, Services, User manual, API Docs and more... \[r2025-11-25]

{% embed url="<https://vimeo.com/1030381503>" fullWidth="false" %}
Our Credo
{% endembed %}

## Aquila<mark style="color:blue;">X</mark> AI Documentation

<figure><img src="/files/IwAw2vgVsGIsQTksZqdt" alt="AquilaX Scanners"><figcaption><p>AquilaX Scanners</p></figcaption></figure>

## Jump right in?

<table data-view="cards"><thead><tr><th></th><th></th><th></th><th data-card-target data-type="content-ref"></th><th data-hidden data-card-cover data-type="files"></th></tr></thead><tbody><tr><td><code>Portal</code></td><td></td><td></td><td><a href="https://aquilax.ai">https://aquilax.ai</a></td><td><a href="/files/Tm0oDmotfpbo9kpL4486">/files/Tm0oDmotfpbo9kpL4486</a></td></tr><tr><td><code>Status Page</code></td><td></td><td></td><td><a href="https://status.aquilax.ai">https://status.aquilax.ai</a></td><td><a href="/files/pz5Qt9yhPOZSwqfi2QMv">/files/pz5Qt9yhPOZSwqfi2QMv</a></td></tr><tr><td><code>LinkedIn</code></td><td></td><td></td><td><a href="https://www.linkedin.com/company/aquilax-ai/">https://www.linkedin.com/company/aquilax-ai/</a></td><td><a href="/files/k4QqgdiQQACxYEiBG2GA">/files/k4QqgdiQQACxYEiBG2GA</a></td></tr><tr><td><code>GitHub</code></td><td></td><td></td><td><a href="https://github.com/AquilaX-AI">https://github.com/AquilaX-AI</a></td><td><a href="/files/hYfkTrHBHaWUQX7efUVW">/files/hYfkTrHBHaWUQX7efUVW</a></td></tr><tr><td><code>Blog</code></td><td></td><td></td><td><a href="https://aquilax-security.medium.com/">https://aquilax-security.medium.com/</a></td><td><a href="/files/9VyfY0b01AbfLKW2Mdhw">/files/9VyfY0b01AbfLKW2Mdhw</a></td></tr><tr><td><code>Product Roadmap</code></td><td></td><td></td><td><a href="https://aquilax.featurebase.app/roadmap">https://aquilax.featurebase.app/roadmap</a></td><td><a href="/files/hWgg8YQNaYIoUVHAoddj">/files/hWgg8YQNaYIoUVHAoddj</a></td></tr><tr><td><code>Release Notes</code></td><td></td><td></td><td><a href="https://aquilax.featurebase.app/changelog">https://aquilax.featurebase.app/changelog</a></td><td><a href="/files/6rwzAWhDeIz9xvnUelOJ">/files/6rwzAWhDeIz9xvnUelOJ</a></td></tr><tr><td><code>Advantages</code></td><td></td><td></td><td><a href="https://aquilax.ai/key-differences">https://aquilax.ai/key-differences</a></td><td><a href="/files/WIOWlyxdxivZrO5T8Jlf">/files/WIOWlyxdxivZrO5T8Jlf</a></td></tr><tr><td><code>AI-Driven Accuracy</code></td><td></td><td></td><td><a href="https://aquilax.ai/ai-driven-accuracy-in-security-reviews">https://aquilax.ai/ai-driven-accuracy-in-security-reviews</a></td><td><a href="/files/viCFsjbXPJBdrCJDVrPm">/files/viCFsjbXPJBdrCJDVrPm</a></td></tr></tbody></table>


# Products and Services

What AquilaX does and offers

AquilaX is a pioneering product in deep source code assessment, designed to identify vulnerabilities. It is the **first on the market to offer an AI Engine capable of reasoning like a security engineer** conducting a manual code review.

{% content-ref url="/pages/aepWhJAM1zrc9R1dKukt" %}
[Demo](/products-and-services/demo)
{% endcontent-ref %}

{% content-ref url="/pages/AFYIWWrg6ix7WqpjCPND" %}
[Products](/products-and-services/products)
{% endcontent-ref %}

{% content-ref url="/pages/G83LMK10LCYAdEdhuN2V" %}
[Services](/products-and-services/services)
{% endcontent-ref %}


# Demo

See AquilaX in action

## Product Demo

{% embed url="<https://vimeo.com/974581556>" %}
AquilaX Product Demo #1
{% endembed %}

## Using AquilaX to Scan your Git

{% embed url="<https://www.youtube.com/watch?v=FCsxO6ySf4Q>" %}
AquilaX Product Demo #2
{% endembed %}


# Security Engineer - Assistant

Securitron by AquilaX AI - Findings Review

🚨 Imagine this…\
You click on a security finding from your scanner and—boom 💥—you instantly get:

1️⃣ Crystal-clear instructions on how to fix it 🔧\
2️⃣ Not sure if it’s legit? Too lazy to check? Just ask your friendly neighborhood AI to verify it for you 🤖💁‍♂️

And here’s the kicker… it all runs locally. Yep, on your CPU, no cloud magic or heavy lifting required. 🖥️💨

What more could you possibly want? A coffee machine integration? ☕😄\\

{% embed url="<https://vimeo.com/1072365619?share=copy>" %}


# Security Engineer - Chat

Securitron by AquilaX AI - ChatBot Assistant

Still jumping between dashboards, logs, and a sea of metrics to understand your app’s security posture? 😩

What if you could just… ask?

No noise, no fluff—just a straight answer from your locally running AI Security Engineer. 🤖

🧠 It knows your environment.

🔐 It understands code.

⚙️ It thinks like a security expert.

And it lives *right on your machine*—no cloud dependency, no delays.

This is AppSec reimagined.

Why waste time when you can have an AI that triages findings, explains risks, and recommends fixes—in seconds.

🚀 The new paradigm isn’t more dashboards—it’s an AI that is your security team.

{% embed url="<https://vimeo.com/1072373982?share=copy#t=0>" %}


# Scan code Snippet

🚨 Scan Your Code Snippets in Seconds with AquilaX!

Got a few lines of code? Paste them into AquilaX and let our AI-powered engine uncover hidden vulnerabilities instantly. 💡

🔍 Backed by 10 scanners and trained on *billions* of code examples, AquilaX Securitron filters out the noise and gives you true positives only—plus remediation tips that make fixing security issues a breeze.

{% embed url="<https://vimeo.com/1084242694?share=copy>" %}

🛡️ Start scanning today and make secure coding your superpower.

👉 [Try it now at aquilax.ai](https://aquilax.ai)


# Product Demo - English

AquilaX Security Product Demo in English

{% embed url="<https://vimeo.com/1128163914?fl=ip&fe=ec>" %}


# Product Demo - Italian

AquilaX Security Product Demo in Italian

{% embed url="<https://vimeo.com/1128167377?fl=ip&fe=ec>" %}


# Products

Products from AquilaX Platform

List of products offered by AquilaX platform in relation to the plan selected

<table><thead><tr><th width="261">Product</th><th width="92" data-type="checkbox">Free</th><th width="110" data-type="checkbox">Premium</th><th width="105" data-type="checkbox">Ultimate</th><th data-type="content-ref">Read More</th></tr></thead><tbody><tr><td>Compliance Check</td><td>true</td><td>true</td><td>true</td><td><a href="https://aquilax.ai/compliance">https://aquilax.ai/compliance</a></td></tr><tr><td>Secret Scanner</td><td>true</td><td>true</td><td>true</td><td><a href="https://aquilax.ai/secret-identification">https://aquilax.ai/secret-identification</a></td></tr><tr><td>PII Scanner</td><td>true</td><td>true</td><td>true</td><td><a href="https://aquilax.ai/pii-scanner">https://aquilax.ai/pii-scanner</a></td></tr><tr><td>SAST Scanner</td><td>false</td><td>true</td><td>true</td><td><a href="https://aquilax.ai/static-application-security-testing">https://aquilax.ai/static-application-security-testing</a></td></tr><tr><td>SCA Scanner</td><td>false</td><td>true</td><td>true</td><td><a href="https://aquilax.ai/software-composition-analysis">https://aquilax.ai/software-composition-analysis</a></td></tr><tr><td>Container Scanner</td><td>false</td><td>true</td><td>true</td><td><a href="https://aquilax.ai/container-scanning">https://aquilax.ai/container-scanning</a></td></tr><tr><td>IaC Scanner</td><td>false</td><td>true</td><td>true</td><td><a href="https://aquilax.ai/iac-scanning">https://aquilax.ai/iac-scanning</a></td></tr><tr><td>API Scanner</td><td>false</td><td>false</td><td>true</td><td><a href="https://aquilax.ai/api-security">https://aquilax.ai/api-security</a></td></tr><tr><td>Malware Identification</td><td>false</td><td>false</td><td>true</td><td><a href="https://aquilax.ai/malware-identification">https://aquilax.ai/malware-identification</a></td></tr><tr><td>Securitron AI (FP Removal)</td><td>false</td><td>false</td><td>true</td><td><a href="https://aquilax.ai/ai-driven-accuracy-in-security-reviews">https://aquilax.ai/ai-driven-accuracy-in-security-reviews</a></td></tr><tr><td>Remediation Feeds</td><td>false</td><td>false</td><td>true</td><td></td></tr><tr><td>Dynamic End-Point Scanning (DAST)</td><td>false</td><td>false</td><td>true</td><td></td></tr></tbody></table>

{% hint style="info" %}
The free plan is limited to a maximum of 10 users per organization
{% endhint %}

For price please visit <https://aquilax.ai/#pricing>

Are you looking for a new feature or functionality? Have your say here: <https://aquilax.featurebase.app/>


# Services

Services from AquilaX Platform

List of services offered by AquilaX platform in relation to the plan selected

<table><thead><tr><th width="314">Service</th><th width="141" data-type="checkbox">Free</th><th width="148" data-type="checkbox">Premium</th><th data-type="checkbox">Ultimate</th></tr></thead><tbody><tr><td><a href="/pages/BYBzWDSWGClwu8F9PVA5#multi-tenant">Multi tenant (SaaS)</a></td><td>true</td><td>true</td><td>true</td></tr><tr><td><a href="/pages/BYBzWDSWGClwu8F9PVA5#single-tenant">Single tenant (Isolated Instance)</a></td><td>false</td><td>true</td><td>true</td></tr><tr><td><a href="/pages/BYBzWDSWGClwu8F9PVA5#private-cloud-on-prem">Private Cloud (your own Cloud)</a></td><td>false</td><td>true</td><td>true</td></tr><tr><td><a href="/pages/BYBzWDSWGClwu8F9PVA5#private-cloud-on-prem">On-Prem</a></td><td>false</td><td>true</td><td>true</td></tr><tr><td><a href="/pages/a1qJvJbVo0WzjBVjfrP4">Manual vulnerability trigging</a></td><td>false</td><td>false</td><td>true</td></tr><tr><td><a href="/pages/X4bMZxBKDTwAY9QjgkDA">Training (remote/in presence)</a></td><td>false</td><td>false</td><td>true</td></tr><tr><td><a href="/pages/12Zpoml3YEfj4FaF2pFW">Security Consultation</a></td><td>false</td><td>false</td><td>true</td></tr><tr><td><a href="/pages/ld9Y3gjjNowrADKB7eet">DevSecOps Consultation</a></td><td>false</td><td>false</td><td>true</td></tr><tr><td><a href="/pages/375bHQm2O3SvDhmKUBtX">3rd party Integration</a></td><td>false</td><td>false</td><td>true</td></tr><tr><td><a href="/pages/keTyIZW8RYE8p1JJnyMy">Auto Triaging</a></td><td>false</td><td>false</td><td>true</td></tr></tbody></table>

{% hint style="info" %}
The free plan is limited to a maximum of 10 users per organization.
{% endhint %}

For price list please visit: <https://aquilax.ai/#pricing>


# Vulnerability Triaging

We check every vulnerability manually

#### AquilaX: Delivering Contextualized, Developer-Centric Security Insights

At AquilaX, we go beyond the capabilities of traditional source code scanners by focusing on providing **valuable, contextualized findings** that truly matter to developers. Our goal is not just to detect vulnerabilities but to ensure that the information we deliver is meaningful and actionable, empowering development teams to improve the security of their codebases efficiently.

To achieve this, we offer an enhanced service for our customers who opt for the **Ultimate version** of AquilaX. This includes a **manual review** of each finding by our dedicated security engineering team. Our process ensures that every vulnerability is thoroughly vetted, offering deeper insights and actionable steps for remediation. Here's how we make it happen:

1. **Review and Triage**\
   Our security engineers carefully review and triage each vulnerability identified by the scanner. This human-led process ensures that no critical issue is overlooked, and the findings are accurately prioritized.
2. **Classify as False Positive or True Positive**\
   Each finding is meticulously evaluated and categorized as a **false positive** or **true positive**, ensuring developers aren't burdened with unnecessary alerts or irrelevant information.
3. **Provide Additional Context**\
   In cases where the scanner might fall short, our team adds **additional details and context** to the findings. This extra layer of insight helps developers fully understand the security risks and the necessary actions to mitigate them.
4. **Optimize Future Scans**\
   We continuously **tune and optimize** the scanning engine based on our findings, improving accuracy for future scans and ensuring that subsequent results align with our high standards of security review.

While other providers may offer similar services as a **managed service**, at AquilaX, we view this as an essential part of delivering real value to the **developer community**. Our focus is on providing security insights that are not only accurate but also highly relevant and actionable, making the process of securing code more efficient and developer-friendly.

By combining the power of **automated scanning** with expert **manual review**, AquilaX offers a holistic approach to software security, ensuring that developers can trust the findings and act on them with confidence.


# AppSec Training

We deliver training tailored to AquilaX and Application Security

At AquilaX, we believe in going the extra mile for our customers, which is why **product training** and **service support** are offered **free of charge** for all customers on our **Premium** and **Ultimate license plans**. We are committed to ensuring that our clients not only use our products but truly love them. Your success is our success, and we stand by you every step of the way.

In addition to standard product training, we offer **tailored AppSec (Application Security) training** delivered by our seasoned security engineering team. With years of experience providing **top-tier security services and consulting** for leading firms, our team is uniquely equipped to offer comprehensive, customized training that fits your organization’s needs. Our sessions cover a wide range of topics, including:

1. **Fundamentals of Application Security (AppSec)**
2. **OWASP Top 10 Vulnerabilities**
3. **NIST Top 25 Security Vulnerabilities**
4. **Best Practices for Writing Secure Software**
5. **Top 10 Common Software Vulnerabilities**
6. **Hands-on Vulnerability Reviews and Secure Coding Training**

Rather than taking a one-size-fits-all approach, we collaborate with our customers to fully understand their specific training needs. Based on these discussions, we develop a **customized training agenda** and organize sessions that are relevant, practical, and highly impactful. Our goal is to empower your team with the knowledge and skills they need to create more secure software and proactively address security challenges.

At AquilaX, we don’t just deliver products; we deliver expertise, and we’re here to help you every step of the way.


# DevSecOps Consultation

Hands on service to design together the best DevSecOps pipeline

#### DevSecOps: Building a Secure SDLC with AquilaX

**DevSecOps**, or more formally the **Secure Software Development Lifecycle (SDLC)**, is the practice of seamlessly integrating security into every phase of the DevOps pipeline. This involves embedding both **security scanners** and **manual or automated services** throughout the entire SDLC to ensure continuous security across development, testing, and deployment.

At AquilaX, we offer a comprehensive suite of **DevSecOps solutions** that work with any code repository, whether you’re using **GitHub, GitLab, BitBucket**, or other platforms. Our scanners are designed to integrate effortlessly into any DevOps environment, adapting to your existing setup and providing robust security coverage at every stage.

For customers on our **Ultimate plan**, we go even further. We offer expert consultation to help design and engineer the ideal **Secure SDLC platform** for your organization. Our approach is collaborative and unbiased—while we provide top-notch security solutions, we work closely with your engineers to determine the most suitable tools and environment for seamless security integration. If needed, we recommend the best-fit tools and services, even beyond our own offerings, to ensure your **security controls** are frictionless and fully aligned with your **development lifecycle**, from writing code to running your application in production.

At AquilaX, our goal is to ensure that **security** becomes an integral, unobtrusive part of your development process, helping your organization achieve both **high-quality software** and robust **security standards**.


# Deployment Options

How to consume AquilaX

During both the PoV and regular operation, AquilaX offers three deployment modes to suit the specific needs of your organization:

### Multi tenant

A shared deployment, hosted and maintained by AquilaX (via <https://app.aquilax.ai>), where data separation is handled at the permission level. This option provides a quick, easy setup and offloads maintenance to the AquilaX team, offering a hassle-free solution.

### Single tenant

A dedicated, isolated instance of AquilaX services is deployed exclusively for your organization. This setup ensures full control and isolation while leveraging AquilaX’s capabilities.

### Private Cloud (On-Prem)

Similar to the Single-Tenant option, but deployed within your organization’s infrastructure, whether on-premises or in your own cloud environment. This setup allows for complete internal control and maintenance.


# Security Consultation

AquilaX Security Consultation Services: Comprehensive Solutions for Your Cybersecurity Needs

#### AquilaX Security Consultation Services: Comprehensive Solutions for Your Cybersecurity Needs

At AquilaX, while our core focus is on delivering innovative and effective security products, we recognize that many organizations require expert guidance to build a solid security foundation. This is where our **Security Consultation Services** come in. We offer a broad range of consultation services to help you navigate the complexities of modern cybersecurity, ensuring your systems are secure from development through to production and beyond.

To deliver these services, we partner with leading **third-party security experts** to provide our customers with the highest quality of consulting available on the market. Although security consultation is not AquilaX's primary offering, we understand its critical importance and are committed to providing comprehensive solutions whenever our clients need them.

Here’s an overview of our **Security Consultation Services**:

**1. Security Architecture**

We help organizations design and implement robust security architectures that align with their business needs. This includes planning and structuring systems to minimize risks and protect critical assets.

**2. Security Engineering**

Our team collaborates with you to build and enhance secure systems. We provide hands-on support to implement security controls and integrate security best practices across your infrastructure.

**3. Advisory Services**

Our security experts offer strategic advice tailored to your organization, helping you stay ahead of evolving threats and comply with industry standards and regulations.

**4. Design and Implementation of Secure SDLC Programs**

We work with your development teams to design and implement a **Secure Software Development Lifecycle (SDLC)**, embedding security throughout the development process to ensure code integrity and reduce vulnerabilities from the start.

**5. Design and Installation of Network Perimeter Controls**

Our team designs and installs effective network perimeter controls, protecting your systems from unauthorized access and external threats while maintaining the integrity of your network traffic.

**6. Penetration Testing**

We conduct thorough penetration testing to identify vulnerabilities in your systems before attackers can exploit them. This includes web applications, networks, and mobile platforms.

**7. Red Teaming**

Our **Red Teaming** services simulate real-world cyberattacks to test your organization's detection and response capabilities, providing insights into how to strengthen your defenses.

**8. Secure Code Review**

We perform comprehensive secure code reviews to ensure your software is free of security vulnerabilities. Our reviews focus on identifying and remediating issues early in the development cycle, helping you deliver secure code to production.

**9. Cloud Implementation**

We assist in securing your cloud environments, whether you’re using **AWS, Azure**, or **Google Cloud**. Our services ensure that your cloud infrastructure is configured securely, and data is protected from unauthorized access.

**10. WAF Installation**

We design and install **Web Application Firewalls (WAFs)** to protect your web applications from common threats like SQL injection, cross-site scripting (XSS), and other attacks targeting web vulnerabilities.

**11. Cybersecurity Controls**

We help implement comprehensive cybersecurity controls that address risks across your organization. This includes everything from data protection to access controls, ensuring your systems are secure at every level.

**12. Virtual CISO (vCISO)**

For organizations needing executive-level security leadership, we offer **virtual CISO** services. Our experienced security professionals provide guidance on security strategy, compliance, and risk management without the need for a full-time hire.

#### Why Choose AquilaX for Security Consultation?

Although security consultation is not the primary core value of AquilaX, we recognize its essential role in helping our clients build secure and resilient systems. When our customers seek additional support, we provide expert consultation services in collaboration with trusted **third-party partners**. This ensures that your organization benefits from the best available solutions, tailored to your specific needs.

At AquilaX, we’re committed to making sure our clients have access to top-tier expertise, whether it’s through our **security products** or **consultation services**. Our mission is to provide holistic solutions that address every facet of your organization’s security posture, from **designing secure architectures** to **managing cloud implementations**.

If you’re looking for comprehensive security consultation services that go beyond software solutions, AquilaX and our partners are here to help. Let’s work together to strengthen your security and protect your organization from evolving cyber threats.


# Integrations

3rd Party tool integrations

#### AquilaX: Seamless Integrations for Enhanced Software and Product Security

At AquilaX, we set ourselves apart in the market by delivering innovative solutions for **software** and **product security**. However, we recognize that to truly serve our customers—whether they’re paid clients or not—we need to provide seamless integrations with popular third-party tools. These integrations allow our users to fully leverage the power of our **security and AI engines** within their existing workflows.

Here are some of the key tools we integrate with:

* **GitHub, GitLab, BitBucket, Azure DevOps** – These integrations enable **source code scanning** and **remediation** directly within your version control systems, allowing for secure development without disrupting your workflow.
* **JIRA** – For efficient **issue tracking**, our integration with JIRA ensures that security vulnerabilities are automatically reported and tracked alongside other project tasks, making it easy to prioritize and resolve issues.
* **GitHub Actions and GitLab Jobs** – We integrate with these CI/CD platforms to automate **security controls** in your continuous integration and delivery pipelines, ensuring secure code deployment at every stage.

These are just a few examples of the integrations we've developed, but we are always open to collaborating with our customers to build new integrations based on their specific needs—**at no additional cost**!

## 3rd party security tools

At AquilaX, our mission isn’t just to build the next "best" SAST tool or yet another AppSec solution. Instead, we aim to revolutionize how application security is approached entirely. Our core value lies in seamlessly integrating a wide range of established and proven AppSec solutions in the market and putting these capabilities directly into the hands of software and security engineers.

What sets us apart is our proprietary AI model, tailored not only to AquilaX but also to each individual customer. This AI doesn't just identify vulnerabilities—it empowers developers to understand and mitigate them effectively. Bold? Absolutely. But we believe the future of AppSec demands bold thinking.

To demonstrate our commitment, we offer **FREE integration** with any AppSec tools your organization already uses—whether it’s Checkmarx, Black Duck, Snyk, or others. By coupling these tools with AquilaX, you unlock the full potential of your security scanning efforts, transforming fragmented tools into a unified, value-driven approach to secure software development.

If you're looking for a tailored integration or want to learn more about how AquilaX can enhance your security efforts, [**contact us**](https://aquilax.ai) today!

Are you looking for a new feature or functionality? Have your say here: <https://aquilax.featurebase.app/>


# Company Principles


# Engineering Principles

Engineering Principles Driving AquilaX's Application Security Excellence

### 1 - Open Source Everything

* Principle: We open-source everything we develop, engineer, or R\&D, aside from the intellectual property of the business.
* Application: Share our code, designs, and innovations with the community to foster collaboration and transparency.

### 2 - Eat Your Own Dog Food

* Principle: We engineer solutions for engineers, therefore we must be the first to use our own products.
* Application: Use our tools and systems in our daily workflows to ensure they meet the highest standards of usability and functionality.

### 3 - Everyone Writes Code

* Principle: From the CEO to the junior engineer, everyone must write code.
* Application: Maintain a culture where all team members contribute to the codebase, ensuring a deep understanding of our products across all levels.

### 4 - Keep It Simple, Stupid (KISS)

* Principle: Keep it simple, extremely simple. Compromise functionality for simplicity if ROI is reasonable.
* Application: Design systems and write code that is straightforward and easy to understand, avoiding unnecessary complexity.

### 5 - Self-Explanatory Code

* Principle: No comments; the code must speak for itself.
* Application: Write clear, readable, and self-documenting code that does not rely on comments to be understood.

### 6 - No Hacks

* Principle: No hacks in the code. If needed, add an issue to be fixed later.
* Application: Avoid temporary or quick fixes that compromise code quality. Log issues and address them properly.

### 7 - Individual Coding Styles with Code Reviews

* Principle: No peer-programming. Each engineer has their own style, but we enforce PR (Pull Request) on every change.
* Application: Encourage individual creativity and coding styles while ensuring code quality and consistency through mandatory code reviews.

### 8 - Iterative Improvement

* Principle: Continuously improve our systems and processes through regular review and iteration.
* Application: Implement iterative testing and feedback loops to enhance the quality and functionality of our products.

### 9 - Customer Experience First

* Principle: Customer is the aim; we must always keep in line with customer experience in what we build.
* Application: Prioritize the needs and feedback of our customers in all design and development decisions to ensure a positive user experience.

### 10 - Embrace Latest Technologies

* Principle: We use the latest technologies where possible, including heavy use of AI products to be faster and more efficient.
* Application: Integrate cutting-edge technologies and AI solutions into our workflows to enhance productivity and innovation.


# AI Principles

Core AI Principles at AquilaX: Enhancing Privacy, Security and Usability

Many organizations are integrating Artificial Intelligence (AI) into their operations, often by building wrappers around existing solutions like ChatGPT from OpenAI. However, this approach can introduce significant business risks and data confidentiality concerns.

At AquilaX, we take a different approach. AI is a flagship feature in our application security suite, and before launching our first service, we aligned our business and engineering objectives with core principles for AI usage:

* **Customer Information Protection**: Ensuring that customer data is never shared with third parties.
* **In-House AI Engines**: Operating our AI engines exclusively within AquilaX-owned data centers.
* **Open Source Compliance**: Utilizing open-source models when licenses allow, but never sharing internally gathered intelligence with any third-party datasets, whether open or proprietary.
* **Data Deletion Rights**: Providing customers with the right to delete some or all of their information from our systems.
* **Cybersecurity Focus**: Tailoring our AI models specifically for the cybersecurity space to reduce noise and computational demands.
* **Efficiency**: Designing AI models and engines to be CPU-friendly for on-premises installations when needed.

These principles are crucial for ensuring that our services meet the high standards we set for our business and for enabling us to scale our AI models into powerful security engineering consultants.

However, our vision for application security through AI goes beyond these principles. At AquilaX, we believe in leveraging our proprietary AI model to revolutionize the field of application security. Our model is meticulously designed to address the unique challenges of cybersecurity, offering unparalleled precision and efficiency. By focusing our AI exclusively on cybersecurity, we minimize irrelevant data and enhance the system's ability to detect and respond to threats swiftly.

Our proprietary AI model not only enhances the security of applications but also empowers our clients by providing them with a robust, intelligent defense mechanism that evolves with emerging threats. The ability to operate our AI engines within our own data centers ensures that we maintain full control over the data and the AI's learning process, thereby safeguarding our clients' sensitive information.

Furthermore, our commitment to open source compliance and data privacy ensures that our clients benefit from cutting-edge technology without compromising their data security. We understand that each client has unique needs, which is why we offer the flexibility to tailor our AI solutions to specific requirements, whether for on-premises installations or cloud-based deployments.

In summary, AquilaX is dedicated to pushing the boundaries of application security through innovative AI solutions. Our proprietary model is at the forefront of this effort, setting new standards for efficiency, security, and customer trust. Stay tuned for more information and an upcoming white paper release from our AI engineering team, where we will delve deeper into our technology and vision for the future of cybersecurity.


# AquilaX Mission

AquilaX: A Vision Beyond Profit

Like 99.99% of legal organizations, AquilaX operates for the benefit of its stakeholders. However, profit alone is not the driving force behind everything we do. Success in the cybersecurity SaaS market could be our sole focus—but we aim higher. Our work is driven by a vision that fuels our daily efforts, and while it may seem idealistic or even a bit boastful, it’s ultimately about creating real value for everyone—whether you're a stakeholder, employee, customer, or even a developer using our platform for free.

<figure><img src="/files/GXhffZwm2UNOGV66ZAfb" alt=""><figcaption></figcaption></figure>

At AquilaX, we believe in **building and running a company with a meaningful purpose**. While we aren’t creating solutions to combat climate change or solve geopolitical issues, we are deeply invested in reshaping the status quo of cybersecurity—specifically in strengthening software and application resilience against malicious threats from untrusted users.

Our company’s credo is simple yet bold: **We will develop Application Security bots that surpass the abilities of even the best human security engineers**. This isn’t a goal we take lightly. Achieving it won’t happen overnight—it will take time, patience, and countless coding marathons. But this mission is what drives us each day, pushing the boundaries of engineering to create a meaningful impact in the industry.

By "meaningful impact," we don’t just mean the products and services we offer. Our ultimate aim is to look back and see that AquilaX has transformed an entire industry, ushering in a new era of software security paradigms.

We ask for your patience as we work toward this vision. We aren’t here to be just another AppSec product—so please, don’t compare us to typical ASPM solutions. Our mission is to challenge the way engineers approach, manage, and ultimately resolve software security issues.

Join us in reshaping the future of application security.


# Proof of Value (PoV)

Tests your organization code base for vulnerabilites

## Proposal

To demonstrate the impact AquilaX can have on identifying and eliminating software security vulnerabilities, we offer a Proof of Value (PoV). This allows your organization to test AquilaX’s capabilities before fully integrating it into your development and CI pipelines. Unlike a standard installation, the PoV focuses on showcasing core features with minimal disruption. It runs transparently in your existing development environment, enabling quick and easy testing without complex setup or deep DevOps integration. This streamlined approach helps developers and leadership assess its value without altering workflows.

## Deployment Options

During both the PoV and regular operation, AquilaX offers three deployment modes to suit the specific needs of your organization:

### Multi tenant

A shared deployment, hosted and maintained by AquilaX (via <https://app.aquilax.ai>), where data separation is handled at the permission level. This option provides a quick, easy setup and offloads maintenance to the AquilaX team, offering a hassle-free solution.

### Single tenant

A dedicated, isolated instance of AquilaX services is deployed exclusively for your organization. This setup ensures full control and isolation while leveraging AquilaX’s capabilities.

### Private Cloud (On-Prem)

Similar to the Single-Tenant option, but deployed within your organization’s infrastructure, whether on-premises or in your own cloud environment. This setup allows for complete internal control and maintenance.

In case of Private or On-prem installation, there is requirements for these VMs

<table><thead><tr><th width="210">Components</th><th width="163">Value</th><th>Reasons</th></tr></thead><tbody><tr><td>VMs</td><td>4</td><td>Server (x1) + Worker (x2) + GenAI (x1)</td></tr><tr><td>CPU</td><td>v16</td><td>GenAI and multi-scanning</td></tr><tr><td>RAM</td><td>v32</td><td>AI Models required enough RAM</td></tr><tr><td>Inbound</td><td>HTTPS/443</td><td>Access for internal the organization</td></tr><tr><td>Outbound / Internet</td><td>Via Proxy https</td><td>For installation and updates</td></tr><tr><td>Intercommunication</td><td>Yes (VLAN)</td><td>For communication between the servers</td></tr><tr><td>Access to Internal Git</td><td>Via HTTPS</td><td>For accessing the code</td></tr></tbody></table>

## Scanning Capabilities

AquilaX integrates a suite of software scanners within its core engine, including:

<figure><img src="/files/3DcxgNgAEtgSpiFOrFc0" alt=""><figcaption><p>AquilaX Scanners</p></figcaption></figure>

### Integration

We offer multiple scanning integrations, including periodic scans, CICD pipelines, and CLI-based scans. However, for the PoV, we recommend starting with a straightforward approach: granting AquilaX access to your source code environment (e.g., GitHub, GitLab, BitBucket). AquilaX will perform a one-time scan of all repositories, without limitations, and the results will be available on the dashboard for review. This method allows you to quickly assess the value of AquilaX before moving on to deeper integrations with CICD tools like GitHub Actions or CircleCI.

<figure><img src="/files/NnOGkMPUIen0MGYapkIU" alt=""><figcaption><p>AquilaX DevOps / DevSecOps</p></figcaption></figure>

### Triaging and fine tuning

After the scans are completed, AquilaX security engineers will conduct triaging and fine-tuning at no cost to remove irrelevant findings that don't align with your context. This service is complimentary during both the PoV and throughout the duration of your contract. It ensures that you get the most value from the product by allowing your engineering team to focus on critical issues that truly matter, while we handle the noise. This service is customized for your organization, enabling the AI models to become organization-specific by learning from your unique environment. Over time, the engine continuously improves, making future scans more intelligent, accurate, and actionable.\
\\

<figure><img src="/files/45nDhugtq0s8OIN5GMOw" alt=""><figcaption><p>AquilaX - Secure SDLC Full Flow</p></figcaption></figure>

## Start a PoV

If you're interested in conducting a PoV for your organization and have the budget allocated for Application Security improvements, we will need to schedule a 30-minute meeting to gather the following information:

1. Preferred deployment option
2. Codebase and main tech stack in use
3. Success criteria for the PoV
4. Start and end dates for the PoV, along with any required paperwork
5. Primary decision-maker and technical point of contact

## Book a Call with AquilaX

{% embed url="<https://calendly.com/aquilax/30min>" %}


# SLO/SLA/SLI

Service Level Objective Agreement and Indicator for AquilaX

## Service Level Objective (SLO), Agreement (SLA), and Indicators (SLI)

At AquilaX, we are committed to delivering top-tier software security solutions. Every product and service we offer is guided by the following Service Level Objectives (SLOs), Agreements (SLAs), and Indicators (SLIs), ensuring comprehensive security coverage throughout the software development lifecycle.\\

### Service Level Objective (SLO)

Our primary objective is to provide robust and reliable tools that empower engineering teams, security professionals, and stakeholders to:

1. **Identify and Remediate Vulnerabilities**: We ensure that our scanning tools detect security vulnerabilities in the code with high accuracy and minimal false positives.
2. **Lifecycle Coverage**: Our solutions are designed to be integrated throughout the entire software development lifecycle (SDLC), from code development, testing, and deployment to maintenance.
3. **Continuous Improvement**: Regular updates and improvements are part of our commitment to staying ahead of new security vulnerabilities and emerging threats.

These objectives guide the design and functionality of our security scanning products, ensuring they meet the evolving needs of our clients.

### Service Level Agreement (SLA)

We have established the following service agreements to ensure transparency and accountability:

1. **Availability**: Our scanners will be available 99.9% of the time, ensuring constant access for critical security assessments. Downtime for scheduled maintenance will be communicated at least 48 hours in advance.
2. **Response Time**: The average response time for our scanners to complete a vulnerability scan is within 10 seconds and up to 24 hours ( based on code base). In the event of a system issue or technical support request, our team will respond to high-priority tickets within 12 hours and resolve them within 24 hours.
3. **Update Cycle:** We commit to regular updates, including security issue, at least once per week, with immediate patches for critical security updates within 48 hours of discovery.
4. **Support**: We offer 24/7 customer support for all Ultimate clients, ensuring that any issues are addressed promptly.
5. **Bug fixing**: Any bug identified by the customer (all plans) or by the engineering team of AquilaX, is going to be addressed within 72h (faster if is dimmed critical)

If any of the agreed service is breached, the customers have the right to not be charged for the period or the miss-service received.

### Service Level Indicators (SLI)

To measure the effectiveness of our products and services, we track the following key performance indicators:\\

1. **False Positive Rate**: We strive to keep false positive rates below 5%, ensuring the relevance and accuracy of the issues reported for customers on Ultimate plan
2. **Scan Completion Time**: The average time to complete a full scan across standard-sized codebases will be under 2 minutes, depending on the product version and codebase size.
3. **Patch Deployment Time**: Critical security patches will be deployed within 48 hours of vulnerability detection, ensuring minimal exposure to potential threats.
4. **Uptime**: We maintain an uptime of 99.9%, with system availability tracked continuously, and publicly available at: <https://status.aquilax.ai/>

By adhering to these objectives, agreements, and indicators, AquilaX ensures that our products deliver the best security practices, protecting our clients’ code and infrastructure against threats while enhancing their security posture throughout the software lifecycle.


# Security Scanners

Scanners used within AquilaX AI

At AquilaX, we believe a top-notch Application Security and DevSecOps program should leverage the best of today’s trusted, mature open-source scanners. We openly showcase each scanner we use, allowing our clients to see exactly how we’re protecting their code. And for those needing more, we also integrate and offer a full range of both private and open-source scanners to cover all bases in application security.

<table><thead><tr><th>Logo</th><th width="163" data-type="content-ref"></th><th width="119">License</th><th>Used for</th></tr></thead><tbody><tr><td><img src="/files/c0Z1sxVF1p79Crvsws3l" alt="" data-size="original"></td><td><a href="https://github.com/bridgecrewio/checkov">https://github.com/bridgecrewio/checkov</a></td><td>Apache 2.0</td><td>Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.</td></tr><tr><td><img src="/files/SaFgJgAP8P9meqRhqz37" alt="" data-size="original"></td><td><a href="https://github.com/securego/gosec">https://github.com/securego/gosec</a></td><td>Apache 2.0</td><td>Go security checker</td></tr><tr><td><img src="/files/cKSjxr2gE9XVMav5zC7p" alt="" data-size="original"></td><td><a href="https://github.com/aquasecurity/trivy">https://github.com/aquasecurity/trivy</a></td><td>Apache 2.0</td><td>Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more</td></tr><tr><td><img src="/files/eTKeNmshZVfHs1b13LjM" alt="" data-size="original"></td><td><a href="https://github.com/finos/CatchIT">https://github.com/finos/CatchIT</a></td><td>Apache 2.0</td><td>Source code secret scanner by Goldman Sachs and FINOS</td></tr><tr><td><img src="/files/DliWddyJEluFfGObd9i1" alt="" data-size="original"></td><td><a href="https://github.com/anchore/syft">https://github.com/anchore/syft</a></td><td>Apache 2.0</td><td>CLI tool and library for generating a Software Bill of Materials from container images and filesystems</td></tr><tr><td><img src="/files/lvL5XKrS5X4mNecdsV9T" alt="" data-size="original"></td><td><a href="https://docs.npmjs.com/cli/v9/commands/npm-audit">https://docs.npmjs.com/cli/v9/commands/npm-audit</a></td><td></td><td>The audit command submits a description of the dependencies configured in your project to your default registry and asks for a report of known vulnerabilities.</td></tr><tr><td><img src="/files/EyLSiPDYNPfBC5S5UTcm" alt="" data-size="original"></td><td><a href="https://github.com/gitleaks/gitleaks">https://github.com/gitleaks/gitleaks</a></td><td>MIT</td><td>Protect and discover secrets using Gitleaks 🔑</td></tr><tr><td><img src="/files/0A4y7iaoGldwKHWtOiYq" alt="" data-size="original"></td><td><a href="https://github.com/Yelp/detect-secrets">https://github.com/Yelp/detect-secrets</a></td><td>Apache 2.0</td><td>An enterprise friendly way of detecting and preventing secrets in code.</td></tr><tr><td><img src="/files/Wmy7DC82qL9snKTTWzY0" alt="" data-size="original"></td><td><a href="https://github.com/prowler-cloud/prowler">https://github.com/prowler-cloud/prowler</a></td><td>Apache 2.0</td><td>Prowler is an Open Source Security tool for AWS, Azure, GCP and Kubernetes to do security assessments, audits, incident response, compliance, continuous monitoring, hardening and forensics readiness. Includes CIS, NIST 800, NIST CSF, CISA, FedRAMP, PCI-DSS, GDPR, HIPAA, FFIEC, SOC2, GXP, Well-Architected Security, ENS and more</td></tr><tr><td><img src="/files/6AybplRpmJ34dOqB4FJE" alt="" data-size="original"></td><td><a href="https://github.com/aquasecurity/chain-bench">https://github.com/aquasecurity/chain-bench</a></td><td>Apache 2.0</td><td>An open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software Supply Chain benchmark.</td></tr><tr><td><img src="/files/4QjOKGqkCkWxAJ3vgYyJ" alt="" data-size="original"></td><td><a href="https://github.com/Checkmarx/kics">https://github.com/Checkmarx/kics</a></td><td>Apache 2.0</td><td>Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.</td></tr><tr><td><img src="/files/b44J0tIZ58TPW7sxZVbQ" alt="" data-size="original"></td><td><a href="https://github.com/PyCQA/bandit">https://github.com/PyCQA/bandit</a></td><td>Apache 2.0</td><td>Bandit is a tool designed to find common security issues in Python code.</td></tr><tr><td><img src="/files/QV0CqpHsHej1i6zd6kb9" alt="" data-size="original"></td><td><a href="https://github.com/facebook/pyre-check">https://github.com/facebook/pyre-check</a></td><td>MIT</td><td>Performant and security type-checking for python.</td></tr><tr><td><img src="/files/YOZrvPqc9nlw0VbYLB0k" alt="" data-size="original"></td><td><a href="https://github.com/controlplaneio/kubesec">https://github.com/controlplaneio/kubesec</a></td><td>Apache 2.0</td><td>Security risk analysis for Kubernetes resources</td></tr><tr><td><img src="/files/BfAWvE4BIuNc0iBoBb0h" alt="" data-size="original"></td><td><a href="https://github.com/jeremylong/DependencyCheck">https://github.com/jeremylong/DependencyCheck</a></td><td>Apache 2.0</td><td>OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.</td></tr><tr><td><img src="/files/tehaiROLhxkwNifaPQVc" alt="" data-size="original"></td><td><a href="https://github.com/ZupIT/horusec">https://github.com/ZupIT/horusec</a></td><td>Apache 2.0</td><td>Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.</td></tr><tr><td><img src="/files/s2IV14EvBTHV2sDaPSHJ" alt="" data-size="original"></td><td><a href="https://github.com/nccgroup/sobelow">https://github.com/nccgroup/sobelow</a></td><td>Apache 2.0</td><td>Sobelow is a security-focused static analysis tool for Elixir &#x26; the Phoenix framework.</td></tr><tr><td><img src="/files/3jSrHTqD3ye4INW4kMKu" alt="" data-size="original"></td><td><a href="https://github.com/Nullify-Platform/attack-surface-scanner">https://github.com/Nullify-Platform/attack-surface-scanner</a></td><td>MIT</td><td>Web application attack surface scanner by Nullify</td></tr><tr><td><img src="/files/RqQRGnQivlxmfgaKdC2K" alt="" data-size="original"></td><td><a href="https://google.github.io/osv-scanner/">https://google.github.io/osv-scanner/</a></td><td>Apache 2.0</td><td>Vulnerability scanner written in Go which uses the data provided by <a href="https://osv.dev/">https://osv.dev</a><br></td></tr><tr><td><div><figure><img src="/files/ljpCWcpzD7eWahVaLXX1" alt=""><figcaption></figcaption></figure></div><p></p></td><td><a href="https://vulnix0.com/">https://vulnix0.com/</a></td><td>Proprietary </td><td>Offensive Security Platform<br><a href="https://vulnix0.com/">https://vulnix0.com/</a></td></tr><tr><td><div><figure><img src="/files/hEBqMgGgsisxbU0YJ84f" alt=""><figcaption></figcaption></figure></div><p></p></td><td><a href="https://github.com/opengrep/opengrep">https://github.com/opengrep/opengrep</a></td><td>LGPL-2.1 license</td><td>Static code analysis engine to find security issues in code.</td></tr></tbody></table>


# Supported Languages

What AquilaX can scan and identify security vulnerabilites

We are supporting more than 30 different programming languages and coding frameworks, some of them here below, but if we miss any of them, we will love to hear you, please fire a request here <https://aquilax.featurebase.app/> and I can ensure you we will make it work!

<figure><img src="/files/w78Zc8lb7yan9IK5yz1x" alt=""><figcaption><p>Supported Languages by AquilaX</p></figcaption></figure>


# What is AquilaX

AquilaX: Next-Generation AI-Powered Application Security

## Overview

AquilaX is an advanced AI-driven security platform designed to seamlessly integrate into the software development lifecycle, providing developers and security teams with highly accurate, context-aware vulnerability detection and remediation. Unlike traditional AppSec solutions, AquilaX does not rely on generic AI models but instead offers a self-learning system that continuously trains on the customer’s unique codebase and business context.

## Key Features

### AI-Powered Security Code Scanning

• Runs multiple security scanners simultaneously, including Static Application Security Testing (SAST), Software Composition Analysis (SCA), Secret Scanning, and Infrastructure as Code (IaC) analysis.

• Eliminates false positives through machine learning models that continuously refine detection accuracy.

• Provides human-validated security insights, reducing unnecessary noise for developers.

### Self-Learning AI Model

• Unlike one-size-fits-all AI solutions, AquilaX builds a dedicated security model for each organization.

• Learns from real-world security reviews conducted by engineers, ensuring that recommendations are tailored and reliable.

• Adapts to new programming languages and business contexts, ensuring evolving security needs are met.

### Seamless Developer Experience

• Integrates directly with GitHub, GitLab, Bitbucket, and other repository platforms for effortless security scanning.

• Offers simple CLI-based scans, API integration, and automated workflows for CI/CD pipelines.

• Prioritizes usability, allowing developers to address security issues without disrupting their workflow.

### Intelligent Risk-Based Prioritization

• Analyzes vulnerabilities based on business impact, reducing alert fatigue.

• Provides actionable remediation steps, ensuring security issues are resolved efficiently.

• Aligns with industry standards and compliance frameworks to streamline audits and security assessments.

### Flexible Deployment Options

• Cloud-Based (Multi-Tenant) – Hosted and maintained by AquilaX for ease of use.

• Dedicated Cloud (Single-Tenant) – A fully isolated instance for enhanced security and compliance.

• On-Premises – Deployed within the customer’s infrastructure, ensuring full control over data and operations.

## Why AquilaX?

### A Smarter Approach to AI in Security

While many AppSec vendors incorporate AI, their models typically offer generic recommendations. AquilaX takes a different approach by enabling organizations to auto-train AI models specific to their environment, ensuring more precise and relevant security insights.

### Beyond Scanning – Continuous Improvement

AquilaX is more than just a security scanner. It learns from security engineers’ manual reviews, improving over time to offer increasingly accurate assessments. This means that over time, organizations benefit from an AI-powered security expert that continuously refines its understanding of their codebase.

### Cost-Effective and Scalable

By design, AquilaX is 20-30% more cost-effective than traditional security solutions while offering additional services that enhance security coverage. The solution is optimized to run efficiently on CPU instances, ensuring accessibility even for organizations without GPU infrastructure.

## Future Roadmap

• AI-Powered Auto-Remediation – Currently in development, ensuring automated fixes are reliable before release.

• Expanded Language & Framework Support – Continuous improvements to support new programming languages and security requirements.

• Enhanced Developer Education & Awareness – Built-in security guidance to help developers write secure code from the start.

## Get Started

AquilaX is designed for any company that develops software—from startups to enterprises—helping them bridge the expertise gap and enhance security without hiring full-time security specialists.\\


# Success Cases

How AquilaX have help software houses to secure their software


# RemoteEngine

Case Study: Enhancing Security with AquilaX at RemoteEngine.

### Case Study: Enhancing Security with AquilaX at RemoteEngine

RemoteEngine, a global AI-driven hiring platform, connects companies with highly skilled, pre-vetted developers. Given the nature of the business, ensuring security is a top priority to protect both company data and client information. However, maintaining security manually across the entire development lifecycle was becoming increasingly challenging. To address these challenges, RemoteEngine integrated AquilaX, an advanced security automation platform, into its software development process.

***

### Challenges

Before implementing AquilaX, RemoteEngine encountered several security roadblocks that hampered efficiency and posed potential risks:

* Security scans and vulnerability assessments were done manually, leading to delays in product releases and increased workload for the security team.
* Engineers had difficulty identifying and prioritizing security risks in a timely manner, which meant vulnerabilities could persist unnoticed.
* The security team struggled with inconsistent reporting and inefficient remediation workflows, making it harder to maintain high-security standards.
* Ensuring that all developers followed secure coding practices was a challenge, as manual checks were neither scalable nor foolproof.

***

### Solution: AquilaX Implementation

To overcome these challenges, RemoteEngine adopted AquilaX, focusing on four key areas:

#### **Fast Onboarding & CI/CD Integration**

AquilaX was quickly integrated into RemoteEngine’s Continuous Integration and Continuous Deployment (CI/CD) pipeline with minimal disruption. Within hours, automated security checks were running on every new code commit, ensuring that potential vulnerabilities were caught early in the development cycle.

#### **Automated Validation and Smart Vulnerability Triaging**

Previously, engineers spent excessive time filtering through security scan results, distinguishing between real threats and false positives. With AquilaX’s AI-powered scanner, vulnerabilities are automatically validated and prioritized based on severity. This significantly reduces noise and allows engineers to focus only on genuine security threats.

#### **Efficient Reporting & Compliance**

One of the major pain points for RemoteEngine was preparing security reports manually. AquilaX solved this issue by generating detailed and easy-to-understand security reports that provided a clear overview of detected vulnerabilities, their severity, and recommended fixes. These reports helped in ensuring compliance with industry security standards and made audit processes more efficient.

#### **Hands-Off Usage & Continuous Monitoring**

AquilaX operates in a “set it and forget it” mode, where security is continuously monitored without requiring engineers to manually intervene. Whenever a new security threat emerges, the system provides real-time alerts and remediation guidance, ensuring that vulnerabilities are addressed before they can be exploited.

***

### Results

The adoption of AquilaX led to significant improvements in RemoteEngine’s security posture and development efficiency:

* **80% Reduction in Vulnerability Remediation Time** – Engineers now resolve security issues much faster, thanks to automated validation and prioritization.
* Developers can focus on writing high-quality code without being bogged down by lengthy security reviews.
* Automated reporting made it easier to meet regulatory security standards and conduct internal security reviews.
* AquilaX’s AI-driven monitoring ensures that RemoteEngine is protected against newly discovered security threats.

***

### Conclusion

By leveraging AquilaX, RemoteEngine successfully automated its application security, making it more efficient, scalable, and reliable. The integration of AquilaX into the CI/CD pipeline not only improved security but also allowed engineers to work more productively without compromising safety.

***

### Future Plans

Looking ahead, RemoteEngine aims to deepen its integration with AquilaX and further enhance its security processes. The key focus areas for the future include:

* Expanding AquilaX security solutions across more internal projects, including mobile applications, third-party integrations, and cloud-based microservices.
* Implementing more AI-driven security policies to detect anomalies, predict potential attack vectors, and apply necessary security patches automatically.
* Using AquilaX’s security insights to develop structured training programs for engineers, including case studies, interactive workshops, and hands-on exercises.
* Automating security compliance checks for regulations like **GDPR, ISO 27001, and SOC 2** to ensure adherence to global security standards.
* Publishing security case studies, conducting webinars, and participating in industry events to share best practices and insights gained from using AquilaX.
* Refining and enhancing security automation strategies by monitoring performance metrics, customizing security rules, improving dashboard visualizations, and integrating new security frameworks as they emerge.

With AquilaX, RemoteEngine is poised to maintain a proactive security stance while enabling its engineers to build innovative solutions without compromising safety.

PDF Report

{% file src="/files/zG5w08RIVKa1tUwO2wiI" %}
PDF Report - Case Study
{% endfile %}

[Anand Prakash](https://www.linkedin.com/in/anandhost/overlay/about-this-profile/) @ [RemoteEngine](https://remoteengine.co/)


# Almotech: Fast-Track to Secure Software

Discover key metrics, practical results, and the next steps Almotech is taking to reach zero critical vulnerabilities and full coverage for every release — all without slowing down engineering.

[Almotech](https://almotech.co/), a mid-sized software house in Europe, relies on GitHub to build, host, and deploy software for a diverse client base. With more than 15 engineers working across multiple technologies, securing their codebase was always a challenge. Few tools could handle such a varied stack without slowing things down. That changed when they integrated AquilaX to boost their security posture without adding friction.

<figure><img src="/files/AK2KZuao8uKRGTAuoYL7" alt=""><figcaption></figcaption></figure>

Key results achieved with AquilaX:

* From decision to first scan: **under 24 hours** — seamless onboarding with no workflow disruptions.
* Scan time for critical components: **under 4 minutes**, even without parallel runs.
* Noise reduction: **over 35% fewer false positives**, letting engineers focus on real issues instead of endless triage.
* **Ongoing protection**: scans now run periodically, ensuring no vulnerability slips through undetected.
* Key security issues were uncovered — all critical items were resolved quickly, and the remaining ones are tracked on an active fix roadmap.

**What’s next for the team:**

1️⃣ Enable automatic scanning via GitHub Actions to cover every commit and pull request.

2️⃣ Roll out auto-remediation for third-party dependencies (SCA) and infrastructure-as-code (IaC).\\

The goal is clear: achieve zero HIGH or CRITICAL vulnerabilities and extend this level of security coverage to 100% of Almotech’s released software.

This is a success story about speed of adoption and meaningful noise reduction, showing that robust security can be simple, fast, and developer-friendly.


# AquilaX License Model

AquilaX offers three subscription tiers—Free, Premium, and Ultimate—designed to scale with your security needs.

AquilaX offers three subscription tiers—Free, Premium, and Ultimate—designed to scale with your security needs. All tiers provide robust functionality for modern DevSecOps workflows and continuous application security.

***

### 🔓 Free Plan

**What You Get**:

* Scanners: **Secrets**, **Git Compliance**, **PII Data**
* Core Features:
  * ✅ Unlimited scans
  * ✅ CI/CD integration
  * ✅ Reporting dashboard
  * ✅ API access
  * ✅ CLI & IDE tools

**Limits**:

* 🚫 Max **10 users per organization**
* 🚫 No advanced scanners (e.g., Malware, AI Code Scan)

***

### 💼 Premium Plan

**What You Get**:

* All **Free Plan** features
* Additional Scanners:
  * ✅ SAST (Static Application Security Testing)
  * ✅ SCA (Software Composition Analysis)
  * ✅ IaC (Infrastructure-as-Code)
  * ✅ Container & API Scanning

**Limits**:

* ✅ No user limit
* 🚫 No **Malware** or **AI-based Scanning**

***

### 🚀 Ultimate Plan

**What You Get**:

* All **Premium Plan** features
* Plus:
  * ✅ **Malware Scanning**
  * ✅ **AI Code Scanning** with Securitron
  * ✅ **AI Auto-Triage**
  * ✅ **AI Assistant** support
  * ✅ Full deployment flexibility:
    * Multi-tenant SaaS
    * Single-tenant (dedicated)
    * **On-Prem** or **Your Cloud**

**Limits**:

* ✅ No user or scan type limits

***

### 🔢 License Calculation

A **license** is counted as:

* Every **active committer** in the past 30 days **plus**
* Every user with **platform access**

**Example**:

> If 8 out of 10 developers committed code last month and 1 security engineer accessed the platform, you need **9 licenses**.

***

### ✅ Common Features in All Plans

| Feature           | Available in All Plans |
| ----------------- | ---------------------- |
| Unlimited Scans   | ✅                      |
| CI/CD Integration | ✅                      |
| Reporting         | ✅                      |
| API Access        | ✅                      |
| CLI & IDE Tools   | ✅                      |

***

🔗 **Learn more**: <https://aquilax.ai/#start-here>


# Compliance Report

AquilaX Consolidated Security Reporting

AquilaX provides a unified reporting framework that aggregates multiple industry-standard security assessments into a consistent and centralized format. This enables engineering, security, and governance teams to understand their application’s risk posture without correlating data from multiple independent tools or dashboards.<br>

This document describes how AquilaX generates these reports, how they are structured, and why consolidation is technically important in modern Secure SDLC workflows.

***

### Available Reports

AquilaX currently supports consolidated reporting for the following widely recognized security classifications:

#### OWASP Top 10

<figure><img src="/files/QIMThQpSzvPiXHkpHDLL" alt="" width="375"><figcaption></figcaption></figure>

AquilaX identifies vulnerabilities and maps them to the latest OWASP Top 10 categories. Each mapped finding includes risk classification, technical evidence, affected components, exploitability indicators, and recommended remediation steps.

#### CWE Top 25

<figure><img src="/files/UTfAzlqB66MdbQlRsmmF" alt="" width="375"><figcaption></figcaption></figure>

AquilaX analyzes code and runtime data to detect weaknesses listed under the CWE Top 25. Reports highlight structural coding patterns, insecure design issues, and recurring implementation weaknesses.

#### CVE Exposure

<figure><img src="/files/z1Lf7cBXYf09zhTJAyZU" alt="" width="375"><figcaption></figcaption></figure>

AquilaX inspects dependency graphs, package versions, and third-party components to detect exposure to public CVEs. Each issue includes CVSS scoring, affected versions, exploit maturity, and patch availability.

#### PCI DSS Alignment

<figure><img src="/files/UJu7waU2Rx1pC0x9OYfY" alt="" width="375"><figcaption></figcaption></figure>

For applications handling payment data, AquilaX evaluates relevant areas against applicable PCI DSS security controls. This helps teams identify gaps in encryption, access control, logging, and secure data handling requirements.

***

### How AquilaX Generates These Reports

AquilaX integrates into multiple layers of the Secure SDLC and collects:

* Static code analysis results
* Dependency/SBOM data
* Runtime events and telemetry
* Container and orchestration metadata
* Build pipeline outputs
* Configuration and infrastructure parameters<br>

All signals are normalized into a unified internal model. Each finding is enriched with:

* a unique issue identifier
* mapped classification (OWASP, CWE, CVE, PCI DSS)
* impacted file, component, or resource
* severity scoring and risk indicators
* supporting evidence (logs, traces, code snippets)
* recommended remediation actions

This creates a consistent report structure even when findings originate from different scanners, languages, or platforms.

***

### Why Consolidation Is Important

Modern applications generate security findings from many disparate tools—SAST, SCA, container scanning, IaC analysis, runtime detections, and manual reviews. Without consolidation, teams face duplicated data, inconsistent severity scoring, and long analysis cycles.

#### 1. Removes Duplicate Findings

Multiple scanners may report the same weakness differently. Consolidation identifies equivalences and merges them into a single technical issue.

#### 2. Normalized Severity Model

Each report uses its own scoring system (CVSS, CWE relevance, OWASP risk). AquilaX unifies these into a consistent severity framework, improving prioritization.

#### 3. Faster Root-Cause Analysis

Engineers can trace how:

* a CVE maps to a CWE pattern
* a code issue aligns with OWASP categories
* a vulnerability affects PCI DSS compliance

This reduces context switching and accelerates remediation cycles.

#### 4. Stronger Governance and Audit Readiness

Consolidated reports provide a single source of truth for:

* historical findings
* remediation timelines
* audit evidence
* compliance coverage
* risk acceptance and documentation

This simplifies internal audits and regulatory assessments.

#### 5. Consistent Developer Experience

Developers interact with a single interface instead of learning multiple tools. Findings follow a predictable format independent of the underlying scanner.

***

### Report Access and Delivery

AquilaX provides consolidated reports through:

* The AquilaX web platform
* REST API (JSON output)
* CI/CD integrations
* Export formats such as PDF, CSV, and SBOM extensions<br>

Each export maintains traceability back to the original finding and associated metadata.

***

### Summary

AquilaX delivers a unified, technically consistent approach to application security reporting. By consolidating OWASP, CWE, CVE, and PCI DSS assessments, teams gain clearer visibility, faster investigation paths, and stronger governance over their security posture. The result is reduced fragmentation, improved engineering efficiency, and a more reliable risk management process throughout the Secure SDLC.


# Security Rating

Security Rating Score for AppSec Scan

Every scan performed within AquilaX generates a significant volume of data — including scanner types, identified findings, severity levels, and the validation status of each result. To reduce this information overload and improve usability, AquilaX introduces the Security Rating mechanism.

This feature provides a consolidated summary of scan results through a single, intuitive interface. The Security Rating offers a high-level overview, enabling users to quickly assess the security posture of their application before diving into individual findings.

The rating is visualized as shown in the image below, with each rating tier mapped to a specific score range, as detailed in the following sections of this document.<br>

<figure><img src="/files/sTym5nMgobTDOSwbeAZQ" alt="" width="375"><figcaption></figcaption></figure>

Each repository begins with a baseline Security Score of 100. As issues are identified during scans, score deductions are applied based on the severity and classification of each finding. These deductions are calculated using a predefined scoring model that weighs the impact of vulnerabilities and misconfigurations.

The resulting score — after all deductions — is what determines the final Security Rating, as represented in the visual scale introduced above.

<table><thead><tr><th width="147.9921875">Issue</th><th width="298.5390625">Score Deduction</th><th>Notes</th></tr></thead><tbody><tr><td>Lines of Code</td><td>1 score x 1k Lines of Code</td><td>Upper limit 3 total. The reason behind score deduction on this is to cover TN not detected via automated-scan that is depended on the code size </td></tr><tr><td>Findings (Confirmed)</td><td>5 score per HIGH or CRITICAL<br>2 score per MEDIUM<br>0.5 score per LOW</td><td></td></tr><tr><td>Findings (Not-confirmed)</td><td>2 score per HIGH or CRITICAL<br>0.5 score per MEDIUM<br>0.1 score per LOW</td><td></td></tr><tr><td>Non Confirmed</td><td>1 score per each 10 findings not validated / confirmed yet</td><td>Penalize findings not triaged yet</td></tr><tr><td>License</td><td>5 scores for Free<br>3 scores for Premium<br>0 Scores for Ultimate</td><td>Penalized for reduced scanning capacity</td></tr><tr><td>Scanners</td><td>5 Score for each disabled scanner</td><td>Penalized for reduced scanning capacity</td></tr></tbody></table>


# Integrations

List of Integrations covered in AquilaX

> List of integrations supported by AquilaX across all deployment models — including On-Premises, Cloud (SaaS), and Single-Tenant instances

<table><thead><tr><th width="323.73828125">Integration</th><th>Category<select><option value="OU5R6GKK8x29" label="PROD" color="blue"></option><option value="KqrSlJtKbGCk" label="LIVE" color="blue"></option><option value="6wVBmq3CNXW8" label="IDE" color="blue"></option><option value="4GOCR5vyWA1I" label="CICD" color="blue"></option><option value="0cy7Z92rjkLN" label="Git Access" color="blue"></option></select></th><th>Roadmap</th></tr></thead><tbody><tr><td><img src="/files/14U0KjHW6yfcDbgqp51m" alt="" data-size="line">  VSCode</td><td><span data-option="6wVBmq3CNXW8">IDE</span></td><td>Live</td></tr><tr><td><img src="/files/anKzstM2qQWSoF6iOSc9" alt="" data-size="line"> IntelliJ IDEA</td><td><span data-option="6wVBmq3CNXW8">IDE</span></td><td>Live</td></tr><tr><td><img src="/files/bbfSDgQuvjyAdrKdEKbA" alt="" data-size="line"> PyCharm</td><td><span data-option="6wVBmq3CNXW8">IDE</span></td><td>Live</td></tr><tr><td><img src="/files/yl9qo7sjkTRGZUh5iajP" alt="" data-size="line"> GitHub Actions</td><td><span data-option="4GOCR5vyWA1I">CICD</span></td><td>Live</td></tr><tr><td><img src="/files/hyxTJaWnzynlpQNMIYoC" alt="" data-size="line"> GitLab CI/CD</td><td><span data-option="4GOCR5vyWA1I">CICD</span></td><td>Live</td></tr><tr><td><img src="/files/UBMWGGo1mxrR9jXMjIyD" alt="" data-size="line"> CLI</td><td><span data-option="4GOCR5vyWA1I">CICD</span></td><td>Live</td></tr><tr><td><img src="/files/0zy4M13EcHjUElQ10FEG" alt="" data-size="line"> Jenkins</td><td><span data-option="4GOCR5vyWA1I">CICD</span></td><td>Live</td></tr><tr><td> <img src="/files/SdgeF0ykBnppPMsd52Fj" alt="" data-size="line"> GitHub</td><td><span data-option="0cy7Z92rjkLN">Git Access</span></td><td>Live</td></tr><tr><td><img src="/files/aMMPDevBIw5GeaDSyJN3" alt="" data-size="line"> GitLab</td><td><span data-option="0cy7Z92rjkLN">Git Access</span></td><td>Live</td></tr><tr><td><img src="/files/mKiicWsRiU6JdkkjQVyC" alt="" data-size="line"> BitBucket</td><td><span data-option="0cy7Z92rjkLN">Git Access</span></td><td>Live</td></tr><tr><td><img src="/files/c0QANTz4OEkSkxeAEfAo" alt="" data-size="line"> Azure DevOps</td><td><span data-option="0cy7Z92rjkLN">Git Access</span></td><td>Live</td></tr><tr><td><img src="/files/rTiWfDDXkpxPUNwWSJOc" alt="" data-size="line"> CircleCI</td><td><span data-option="4GOCR5vyWA1I">CICD</span></td><td>Q2 2026</td></tr><tr><td><img src="/files/Dc38FpaAlLeNjzKBTEHu" alt="" data-size="line"> Travis CI</td><td><span data-option="4GOCR5vyWA1I">CICD</span></td><td>Q2 2026</td></tr></tbody></table>


# Cloud Security Posture Managment

AquilaX Cloud Security Posture Management (CSPM)

AquilaX CSPM extends the AquilaX platform from code and IaC into your live cloud accounts. It continuously audits AWS, Azure, GCP, and Kubernetes against industry benchmarks, detects drift between your IaC and what's actually deployed, surfaces real attack paths through identity, and streams runtime threats — all correlated into the same finding model and dashboard you already use for code.

This document covers what the module does, how it works under the hood, what you need to set up, and how it integrates with the rest of the AquilaX platform.

> **Availability.** CSPM is an additional service available exclusively on the **Ultimate** plan. It is **not** included in the base Ultimate subscription and is licensed separately under a dedicated CSPM License Model. It is not available on Free, or Premium plans. Enterprise customers receive CSPM through their custom contract terms.

***

### 1. What problem this solves

AquilaX has always scanned your code, dependencies, containers, and IaC before they reach production. That covers a lot — but it doesn't see what's actually running in your cloud account once it's deployed.

Three concrete gaps:

1. **Drift.** Someone clicks in the AWS console and opens a security group. Your Terraform still shows it closed. AquilaX IaC scans don't catch this.
2. **Identity risk.** A Lambda role accumulates permissions over six months. No single change is flagged, but the cumulative blast radius is now severe.
3. **Runtime threats.** A container starts a reverse shell, an EC2 instance begins cryptomining, a service principal logs in from a new geography. Static scanners can't see any of this.

CSPM closes those gaps. AquilaX CSPM does it without you running six separate tools, six separate dashboards, and six separate severity models.

***

### 2. What's covered

| Surface             | Provider                             | Coverage                                                       |
| ------------------- | ------------------------------------ | -------------------------------------------------------------- |
| Cloud config audit  | AWS, Azure, GCP                      | CIS, NIST 800-53, PCI DSS, ISO 27001, HIPAA, SOC 2 controls    |
| Asset inventory     | AWS, Azure, GCP, Kubernetes          | Full resource graph, queryable                                 |
| Drift detection     | All four                             | Field-level diff between IaC source and live state             |
| IAM least-privilege | AWS (Azure, GCP in beta)             | Privilege escalation paths, unused permissions, risky policies |
| Kubernetes posture  | EKS, AKS, GKE, self-hosted           | NSA/CISA hardening, MITRE ATT\&CK mapping, RBAC analysis       |
| Runtime threats     | Containers, K8s, cloud control plane | eBPF kernel events, CloudTrail/Activity Log/Audit Log streams  |
| Auto-remediation    | AWS, Azure, GCP                      | Policy-driven, opt-in, fully audited                           |

***

### 3. Architecture

AquilaX CSPM is built on a wrapper-and-correlate model. We don't reinvent scanners that already work; we run best-in-class open-source engines, normalize their output into the AquilaX finding schema, and pass everything through Securitron AI for false-positive elimination — the same pipeline your code findings already use.

#### 3.1 The engines under the hood

| Engine              | What it does in AquilaX                            | Why we picked it                                                          |
| ------------------- | -------------------------------------------------- | ------------------------------------------------------------------------- |
| **Prowler**         | Live cloud config audit across AWS/Azure/GCP/K8s   | Broadest control coverage in OSS, native compliance framework mapping     |
| **Steampipe**       | Asset inventory and drift queries                  | SQL-over-cloud-APIs is the cleanest model for ad-hoc and scheduled checks |
| **Cloud Custodian** | Policy-as-code enforcement and remediation actions | Mature, multi-cloud, runs serverless, real production track record        |
| **Falco**           | Runtime threat detection                           | CNCF graduated, eBPF-based, plugin model covers cloud audit logs too      |
| **Cloudsplaining**  | AWS IAM policy analysis                            | Identifies least-privilege violations with concrete CWE mapping           |
| **Kubescape**       | Kubernetes posture management                      | NSA/CISA + MITRE control coverage, in-cluster operator                    |

You don't interact with any of these directly. They're implementation detail. You see findings, scores, and graphs in the AquilaX dashboard.

#### 3.2 The correlation model

Every cloud finding lands in the same resource graph as your code and IaC findings.

```
            ┌──────────────────┐
            │   IaCDefinition  │  (your Terraform / Helm / CFN)
            └────────┬─────────┘
                     │ defined_by
                     ▼
┌─────────┐    ┌──────────┐     ┌──────────────┐
│Identity │───▶│ Resource │◀────│ RuntimeEvent │
└─────────┘    └────┬─────┘     └──────────────┘
  can_assume       │ has_finding
                   ▼
              ┌─────────┐
              │ Finding │  (from any source: IaC, Prowler, Falco, etc.)
              └─────────┘
```

Concretely, this means:

* An IaC finding from a PR scan and a Prowler finding on the same live S3 bucket merge into **one finding** with `sources: [iac, prowler]` — not two duplicate alerts.
* A Falco runtime alert on a pod links back to the Helm chart that defined the pod and to the Kubescape posture findings on the same workload.
* A Cloudsplaining IAM finding combines with a Prowler "publicly exposed RDS" finding to produce an attack path: `compromised_role → assume_admin → access_db`.

Resources are matched in this order: cloud-native ID (ARN, resourceId, self-link) → AquilaX tag → name+region+account fallback.

#### 3.3 False positive elimination

Cloud findings go through Securitron AI before they reach your dashboard, exactly like code findings. Two reasons this matters:

1. **Cross-finding context.** Prowler may flag an internet-facing load balancer as critical. If Securitron sees that the upstream service has no sensitive data, no privileged IAM, and is documented as a public endpoint, it deprioritizes. Standalone Prowler can't do this.
2. **Per-tenant learning.** Findings you mark as accepted-risk teach the model. Over weeks, your noise floor drops without you writing a single suppression rule.

Industry-standard CSPMs typically generate large volumes of findings; AquilaX's review layer cuts that aggressively, in line with the \~93.5% false-positive elimination rate Securitron achieves on code.

***

### 4. The four sub-views

The Cloud section in the AquilaX dashboard has four tabs.

#### 4.1 Posture

Score per cloud account, broken down by compliance framework. Pick CIS AWS 1.5.0, ISO 27001:2022, SOC 2, NIST 800-53, PCI DSS, DORA, NIS2 — same framework picker as the rest of the platform.

For each control, you see pass/fail, affected resources, and a one-click drill-down into the underlying findings. Posture data updates after every scheduled scan (default 24h, configurable down to 1h).

#### 4.2 Resources

Full live inventory of everything in your connected accounts. Search by type, region, tag, or property. Click any resource to see:

* Findings on it (from any source, deduplicated)
* The IaC definition that created it (if any) — clickable through to your repo
* Identities that can act on it
* Recent runtime events

This view is built on Steampipe's queryable cloud data, but you don't write SQL — the platform does.

#### 4.3 Attack Paths

Graph visualization of identity-and-exposure chains. The engine looks for paths like:

```
external_user
  → (compromise)
  → assume role with iam:PassRole
  → pass to lambda with admin policy
  → access internet-exposed RDS with PII
```

Top 10 paths per account by length × max severity, ranked. You fix the *node* that breaks the most paths first — the UI tells you which one.

#### 4.4 Runtime

Live stream of Falco events from your clusters and cloud control planes. Filterable by severity, namespace, account, rule. Each event links to the resource node in the graph and to any pre-deployment findings on that workload.

For cloud-only customers (no K8s), this view shows CloudTrail/Activity Log/Audit Log threat detections via Falco's plugin system — anomalous IAM changes, console logins from new geos, suspicious API call patterns.

***

### 5. Licensing and availability

CSPM is **not** part of the standard AquilaX scanner suite. It is a separately licensed add-on, governed by its own License Model, and only available to customers on the Ultimate plan or above.

#### 5.1 Plan eligibility

| Plan         | CSPM access                                                 |
| ------------ | ----------------------------------------------------------- |
| Free         | Not available                                               |
| Premium      | Not available                                               |
| **Ultimate** | **Available as a paid add-on** under the CSPM License Model |
| Enterprise   | Included or negotiated under custom contract terms          |

Existing AquilaX scanners (SAST, SCA, Secrets, IaC, Container, DAST, API, PII, Malware, Vibe Code, Compliance) continue to work on every plan as before. CSPM is purely additive — it does not change the entitlements of your base subscription.

#### 5.2 The CSPM License Model

CSPM is sold under a **dedicated license** distinct from your AquilaX seat-based subscription. Key terms:

* **Unit of licensing.** Per connected cloud account (AWS account, Azure subscription, GCP project) and per Kubernetes cluster.
* **Tiering.** Volume tiers apply once you connect more than 5, 25, or 100 accounts/clusters. Multi-cloud organizations get a blended rate.
* **Term.** Annual commitment, monthly or quarterly billing. No month-to-month option for CSPM.
* **Runtime add-on.** Falco-based runtime detection is licensed separately within the CSPM License Model — you can take the posture-only tier and add runtime later.
* **Auto-remediation.** Included in all CSPM tiers; no additional cost for the Cloud Custodian-driven action engine.
* **On-premises.** Same License Model applies; on-prem deployments receive the CSPM container images via the same private registry as the rest of the platform.

The license is governed by a separate Order Form referencing the AquilaX Master Subscription Agreement. The CSPM-specific addendum covers data handling for cloud telemetry, runtime event retention, and the elevated-privilege scenarios required for auto-remediation.

#### 5.3 How to activate

1. Confirm you are on Ultimate (or above). If not, upgrade first.
2. Contact your AquilaX account manager or `sales@aquilax.ai` to scope the number of accounts/clusters and select posture-only vs. posture+runtime.
3. Sign the CSPM Order Form.
4. The Cloud section appears in your dashboard within one business day of activation.
5. Proceed to setup Section 6.

Trial licenses are available for evaluation — typically 30 days, scoped to up to 3 cloud accounts. Trial activations skip the Order Form step.

***

### 6. Setup

CSPM is enabled per tenant once the license is active. The base Ultimate subscription does not provision the Cloud section; only a valid CSPM license entitlement does.

#### 6.1 Connecting a cloud account

Each cloud needs read-only access. AquilaX never gets write access unless you explicitly opt into auto-remediation.

**AWS.** Cross-account IAM role. AquilaX provides a CloudFormation template; you deploy it in each account you want scanned. The role grants the AWS-managed `SecurityAudit` and `ViewOnlyAccess` policies plus a small set of additional read permissions Prowler needs.

**Azure.** Service principal with `Reader` and `Security Reader` at the management group or subscription level. AquilaX provides a Terraform module and a manual portal walkthrough.

**GCP.** Service account with `roles/iam.securityReviewer` and `roles/viewer`, granted at the organization or project level. Workload Identity Federation supported — no static keys needed.

**Kubernetes.** A read-only `ClusterRole` plus the AquilaX scanner manifest. For runtime detection, Falco is deployed as a DaemonSet via the AquilaX Helm chart. Both are bundled in a single `aquilax-cspm` chart you install once per cluster.

Connection takes about 5 minutes per cloud. First scan completes within 15 minutes for typical accounts.

Note: each connected account/cluster counts against your CSPM license entitlement. If you exceed your contracted volume, additional accounts move into a read-only "license pending" state until your Order Form is updated — they are not silently scanned and billed.

#### 6.2 Linking IaC repos

If you already use AquilaX for code scanning, your IaC scans are automatically correlated with cloud findings — nothing extra to configure. The matching uses ARN/resourceId/self-link from Terraform state outputs, with tag-based fallback.

If you use IaC tools we don't directly scan (Pulumi in some languages, CDK), enable the optional `aquilax:resource-id` tag pattern in your code. The setup guide in your dashboard generates the snippet.

#### 6.3 Auto-remediation (optional)

Off by default. To enable:

1. Pick which finding types are eligible (e.g., "public S3 buckets", "security groups open to 0.0.0.0/0").
2. Pick the action policy — alert-only, auto-tag, auto-remediate after N hours, or auto-remediate immediately.
3. Approve the elevated IAM role grant. AquilaX uses a separate, narrower role for remediation than for scanning, scoped to the specific actions you authorized.

Every remediation action is logged with full context: which finding triggered it, what the policy was, what changed, who in your org enabled the rule. Exportable to your SIEM.

***

### 7. How findings are delivered

Same channels as the rest of AquilaX:

* Dashboard — primary view, with filters, severity, status workflow
* Pull request comments — for IaC-rooted findings, AquilaX opens AI-generated fix PRs against the source repo
* SARIF, JSON, CSV, PDF export — same formats as code findings
* SIEM and ticketing — webhook-based, with mapping to the standard finding schema
* Slack / Teams / email — configurable per severity threshold

Severity uses the existing AquilaX scale (Critical/High/Medium/Low/Info) with CVSS where applicable. Compliance framework mapping (CIS control ID, NIST control number, etc.) is on every finding.

***

### 8. What's *not* in CSPM

Worth being explicit about. CSPM in AquilaX covers configuration, identity, and runtime threats. It does **not** cover:

* **Data classification** (DSPM) — what's in your S3 buckets, what's PII, what's regulated. This is a separate AquilaX module on the roadmap.
* **Agent-based workload scanning** — we use snapshot and runtime telemetry, not agents inside VMs. If you need deep in-VM CVE scanning, pair AquilaX CSPM with your existing endpoint tooling.
* **SaaS posture** (SSPM) — Okta, Google Workspace, M365 config. Not in scope.
* **Network traffic analysis** — we read VPC Flow Log misconfigurations but don't do behavioral network anomaly detection.

We'd rather do a smaller scope well than a larger scope poorly. These boundaries will move in future releases.

***

### 9. Deployment options

CSPM is available in all three AquilaX deployment modes:

* **Cloud SaaS (multi-tenant)** — easiest to start; AquilaX hosts everything except the Falco DaemonSet (which runs in your cluster) and the Cloud Connector roles (which live in your cloud accounts).
* **Dedicated Cloud (single-tenant)** — fully isolated AquilaX instance, useful for regulated industries.
* **On-premises** — full self-hosted via Docker Compose or Kubernetes Helm. CSPM containers ship via the AquilaX private registry once your CSPM license is active. No data leaves your environment.

In all modes, the underlying OSS engines (Prowler, Steampipe, Cloud Custodian, Falco, Cloudsplaining, Kubescape) are bundled and version-pinned by AquilaX. You don't install or update them yourself.

***

### 10. Compliance reporting

The CSPM module produces audit-ready reports for:

* CIS Benchmarks (AWS, Azure, GCP, Kubernetes)
* NIST 800-53 Rev 5
* ISO 27001:2022
* SOC 2 Type II
* PCI DSS 4.0
* HIPAA Security Rule
* DORA, NIS2 (EU)
* GDPR (control-mapped)

Reports are exportable as PDF and CSV, with control-by-control evidence. The same compliance reporting framework that exists for code findings extends to cloud findings — one report covers both.

***

### 11. Frequently asked questions

**Does AquilaX get write access to my cloud account?** No, unless you explicitly enable auto-remediation, in which case a separate, narrower role is granted, scoped only to the actions you authorized. The default scan role is read-only.

**How often does CSPM scan?** Default 24h for full audits, 1h for inventory refresh, real-time for runtime events. All configurable.

**Will CSPM findings flood my dashboard?** Securitron AI filters before findings reach you. In practice, customers see 10–50 cloud findings per account after filtering, not the thousands raw Prowler output produces.

**Can I write custom rules?** Yes — custom Steampipe queries and Cloud Custodian policies are supported via your AquilaX dashboard. Custom Falco rules are on the roadmap.

**What if I already use Wiz / Orca / Defender CSPM?** You probably don't need both. The case for AquilaX CSPM specifically is when you also want code-to-cloud correlation in one platform — AquilaX shows the IaC line that caused the live misconfiguration, the AI fix PR, and the runtime evidence in one finding. Standalone CSPMs don't do that side.

**Where do I see the underlying tools?** Each finding shows its source engine in the metadata (`source_tool: prowler`, etc.). If you want raw output for a specific scan, the JSON is exportable per scan run.

***

### 12. Getting started

1. Confirm you are on the Ultimate plan and have an active CSPM license - Section 5.
2. Open the AquilaX dashboard, navigate to **Cloud** in the left nav. The section is only visible once your CSPM license is active.
3. Click **Connect a cloud account**, pick your provider, follow the setup wizard.
4. Wait for the first scan (≈15 min).
5. Review findings, set up your notification channels, decide on auto-remediation policy.

Full per-cloud setup guides live in the AquilaX docs portal. The platform's standard SLA and support tiers apply to the CSPM module from day one of license activation.


# User Manual


# Access Tokens

How to create a Personal Access Token (PAT)

## Quick guide

Navigate to <https://app.aquilax.ai/profile>, then in the `Personal Access Tokens (PAT)` you just create a new token.

## Step by step

1. Under the personal profile section Click **"New Access Token" Button**: Find and click the `New Access Token` button to initiate the token creation process. This button is typically located in the Personal Access Tokens section.

<figure><img src="/files/tP7O4Zpq9ZnqzBvYaxhI" alt="" width="375"><figcaption></figcaption></figure>

2. **Fill out the Form**: A form will appear, prompting you to provide a token name and an expiry date. Fill in the required fields and ensure accuracy. This step ensures that your access token is properly identified and has a clear expiration date.\
   \\

<figure><img src="/files/1GxnYP0tgG9UiG2iwGqz" alt="" width="375"><figcaption></figcaption></figure>

3. **Create the Token**: After entering the necessary information, click the "Create" button to generate the access token. Alternatively, if you decide not to proceed, you can click the "Cancel" button to abort the token creation process.
4. **Copy Your Access Token**: Once the token is created, a window will pop up displaying your access token. Click the "Copy" button to copy the token to your clipboard. This ensures that you can easily paste and use the access token in other applications or environments

<figure><img src="/files/Qgda2LcnKWnx1kI1haKB" alt="" width="375"><figcaption></figcaption></figure>

5. **Securely Store Your Token**: Before closing the window, ensure that you securely store your new Personal Access Token (PAT). Once closed, the token cannot be retrieved again, as it is hashed and encrypted on our end. Store the token in a secure location to prevent unauthorized access.

\\


# Scanners

AquilaX Ultimate is a comprehensive software security scanner, designed to detect a wide range of security vulnerabilities in the source code of any application.

<table><thead><tr><th width="137.33333333333331">Scanner</th><th width="523">Description</th><th>Logo</th></tr></thead><tbody><tr><td><strong>Secret</strong></td><td>Identification of passwords, API keys and other highly confidential information in the source code</td><td><img src="/files/x3NFpiqiy7FRF3WFnvdP" alt=""></td></tr><tr><td><strong>PII</strong></td><td>Identification of information related to PII (Personal Identifiable Information) that maybe leaked into a source code</td><td><img src="/files/6sgHI8s6xnhBihs2oOB3" alt="" data-size="original"></td></tr><tr><td><strong>SAST</strong></td><td>Static Application Security Testing - Security scanning for vulnerabilities introduce unintentional by developers during the creation of source code. This also often referred to code-scanning or 1st party code scanning</td><td><img src="/files/56TFnsVlaymlJuFJ6TZT" alt="" data-size="original"></td></tr><tr><td><strong>SCA</strong></td><td>Software Composition Analysis is a technic to identify the usage of 3rd party (usually Open Source libs) that may contain known vulnerabilities</td><td><img src="/files/IioSTCoeq5zcxnwUK03Y" alt="" data-size="original"></td></tr><tr><td><strong>Container</strong></td><td>Container Scanning is a technic that even if is included to SCA, is usually linked to the identification of vulnerable software, rather than vulnerable libraries. Is used during Image creation</td><td><img src="/files/OMnltApzMQ11sBrYtkoB" alt="" data-size="original"></td></tr><tr><td><strong>IaC</strong></td><td>Infrastructure as a Code scanning is linked to identify security misconfiguration in the infrastructure as defined by terraform or cloud formation config files</td><td><img src="/files/uMau4SK4LWmaPwSIiCzb" alt="" data-size="original"></td></tr><tr><td><strong>API</strong></td><td>API scanning is a process of identifying potential security issues based on the definition of the API as from OpenAPI specification</td><td><img src="/files/n46QL0k4cCX5xZyNk59s" alt="" data-size="original"></td></tr><tr><td><strong>Malware</strong></td><td>Malware scanning in the source code (in AquilaX case) is a capability to identify intentional malicious code as backdoors, trojan horses, virus etc.. that maybe injected into the application source code</td><td><img src="/files/GRXcdg5BVYIMbjvblZ2j" alt="" data-size="original"></td></tr></tbody></table>

{% embed url="<https://www.youtube.com/watch?v=g9duRq9B-lQ>" %}
Presented by Cristina, Risk Manager @ AquilaX AI
{% endembed %}

## Scanning Functionalities: <a href="#scanning-functionalities" id="scanning-functionalities"></a>

### **Secret & API Keys Scanning**

AquilaX employs advanced algorithms to scan codebases for hardcoded secrets and API keys. This includes credentials such as passwords, tokens, and sensitive API keys which, if exposed, could lead to security breaches. By identifying these vulnerabilities, AquilaX helps developers secure their applications against unauthorized access.

### **PII & Confidential Data Detection**

Personal Identifiable Information (PII) detection is crucial for compliance with data protection regulations like GDPR and CCPA. AquilaX utilizes pattern matching and machine learning algorithms to detect PII and other confidential data within source code and repositories. This includes sensitive information like social security numbers, credit card details, and personal addresses, helping organizations maintain data privacy and integrity.

### **Static Application Security Testing (SAST)**

SAST is a critical component of secure software development. AquilaX performs static code analysis to identify vulnerabilities, security flaws, and coding errors in applications at an early stage of the development lifecycle. By scanning the source code, AquilaX can detect common security issues such as SQL injection, cross-site scripting (XSS), and buffer overflows, enabling developers to remediate these issues before deployment.

### **Software Composition Analysis (SCA)**

AquilaX conducts dependency checking to identify vulnerable components and libraries within the software stack. By analyzing third-party dependencies and their associated vulnerabilities, AquilaX helps organizations mitigate risks related to outdated or insecure software components, ensuring the integrity and security of the application's dependencies.

### **Container Scanning**

Containerization has become increasingly popular for deploying and managing applications. AquilaX provides container scanning capabilities to assess the security posture of Docker images and containerized environments. By scanning containers for vulnerabilities, misconfigurations, and compliance issues, AquilaX helps organizations maintain the security of their containerized deployments.

### **Infrastructure as Code (IaC) Scanning**

With the rise of Infrastructure as Code (IaC) practices, security vulnerabilities in infrastructure configurations can have significant consequences. AquilaX offers IaC scanning capabilities to analyze configuration files (e.g., Terraform, CloudFormation) and detect misconfigurations, security loopholes, and compliance violations. This ensures that infrastructure deployments adhere to security best practices and compliance standards.

### **API Security**

APIs play a critical role in modern application architectures, but they also introduce security risks if not properly secured. AquilaX specializes in API security testing, identifying vulnerabilities such as insecure authentication mechanisms, excessive data exposure, and insufficient access controls. By assessing the security of APIs, AquilaX helps organizations safeguard their digital assets and prevent API-related security breaches.

### **Uncovering Backdoor Functionalities**

Backdoors represent hidden entry points into a system, often introduced maliciously or inadvertently during development. AquilaX utilizes advanced techniques to uncover backdoor functionalities within source code and binaries. By identifying and mitigating backdoors, AquilaX helps organizations prevent unauthorized access and maintain the integrity of their applications.

## 3rd party tools

AquilaX acknowledges the significant contributions of other teams in the field by integrating third-party scanners directly into its engine. This approach ensures that customers benefit from a seamless and user-friendly application security (AppSec) scanning experience. In addition to our in-house developed engines, here is a list of the scanners we utilize:

<figure><img src="/files/ZSdohwsgJr36wEJRVH8e" alt=""><figcaption><p>AquilaX 3rd party scanners</p></figcaption></figure>

<table><thead><tr><th width="152">Tool</th><th width="86" data-type="checkbox">Secret</th><th width="59" data-type="checkbox">PII</th><th width="75" data-type="checkbox">SAST</th><th width="69" data-type="checkbox">SCA</th><th width="60" data-type="checkbox">IaC</th><th width="108" data-type="checkbox">Container</th><th width="60" data-type="checkbox">API</th><th data-type="checkbox">Malware</th></tr></thead><tbody><tr><td>AquilaX</td><td>true</td><td>true</td><td>true</td><td>true</td><td>true</td><td>true</td><td>true</td><td>true</td></tr><tr><td>Checkov</td><td>true</td><td>false</td><td>false</td><td>true</td><td>true</td><td>true</td><td>true</td><td>false</td></tr><tr><td>GitLeaks</td><td>true</td><td>false</td><td>false</td><td>false</td><td>false</td><td>false</td><td>false</td><td>false</td></tr><tr><td>Bandit</td><td>false</td><td>false</td><td>true</td><td>false</td><td>false</td><td>false</td><td>false</td><td>false</td></tr><tr><td>Pyre</td><td>false</td><td>false</td><td>true</td><td>false</td><td>false</td><td>false</td><td>false</td><td>false</td></tr><tr><td>CatchIT</td><td>true</td><td>false</td><td>false</td><td>false</td><td>false</td><td>false</td><td>false</td><td>false</td></tr><tr><td>GoSec</td><td>true</td><td>false</td><td>true</td><td>false</td><td>false</td><td>false</td><td>false</td><td>false</td></tr><tr><td>Horusec</td><td>false</td><td>false</td><td>true</td><td>false</td><td>false</td><td>false</td><td>false</td><td>false</td></tr><tr><td>insider</td><td>false</td><td>false</td><td>true</td><td>false</td><td>false</td><td>false</td><td>false</td><td>false</td></tr><tr><td>Syft</td><td>false</td><td>false</td><td>false</td><td>true</td><td>false</td><td>false</td><td>false</td><td>false</td></tr><tr><td>Gypre</td><td>false</td><td>false</td><td>false</td><td>false</td><td>false</td><td>true</td><td>false</td><td>false</td></tr><tr><td><a href="https://github.com/jeremylong/DependencyCheck">Dependency-Check</a></td><td>false</td><td>false</td><td>false</td><td>true</td><td>false</td><td>false</td><td>false</td><td>false</td></tr><tr><td><a href="https://github.com/Yelp/detect-secrets">detect-secrets</a></td><td>true</td><td>false</td><td>false</td><td>false</td><td>false</td><td>false</td><td>false</td><td>false</td></tr><tr><td><a href="https://github.com/nccgroup/sobelow">sobelow</a></td><td>false</td><td>false</td><td>true</td><td>false</td><td>false</td><td>false</td><td>false</td><td>false</td></tr><tr><td><a href="https://kubesec.io/">Kubesec</a></td><td>false</td><td>false</td><td>false</td><td>false</td><td>true</td><td>false</td><td>false</td><td>false</td></tr></tbody></table>


# Secret Scanning

Protect Your Code from Leaked Secrets

Secret Scanning is a vital security measure that detects confidential data, such as API keys, passwords, and tokens, that may accidentally get exposed in your code repositories. These secrets, if leaked, can give malicious attackers direct access to your services, databases, or cloud resources, leading to data breaches or financial losses.

AquilaX AI’s secret scanning leverages machine learning (ML) algorithms to continuously monitor your codebase for these sensitive secrets. By using contextualized analysis, it eliminates false positives and ensures that real risks are flagged promptly. Protecting these secrets is critical for securing your organization’s infrastructure and preventing unauthorized access to your sensitive systems.

**Why Secret Scanning Matters:**

• Prevent unauthorized access to systems.

• Avoid costly data breaches.

• Protect sensitive user and business information.


# PII Scanner

Safeguarding Personally Identifiable Information

PII Scanning refers to the automated identification of personally identifiable information (PII) within your code and data repositories. PII includes sensitive data such as names, addresses, phone numbers, Social Security numbers, and more. If exposed, this data can be exploited by attackers for identity theft, fraud, or phishing.\\

AquilaX AI’s PII Scanner is designed to identify potential leaks or exposure of such sensitive data, reducing the risk of compliance violations (e.g., GDPR, HIPAA) and protecting your customers. By using advanced ML-driven techniques, AquilaX ensures that organizations can proactively address PII exposure before it becomes a liability.

**Why PII Scanning Matters:**

• Ensure compliance with data privacy laws (GDPR, HIPAA).

• Prevent identity theft and fraud.

• Protect your brand from reputational damage.


# SAST

Secure Code with Static Application Security Testing

Static Application Security Testing (SAST) is a method of analyzing source code, binaries, or bytecode to find security vulnerabilities early in the development cycle. SAST tools inspect your codebase before it’s deployed, ensuring that weaknesses like SQL injection, cross-site scripting (XSS), and buffer overflows are identified and mitigated early.\\

AquilaX AI’s SAST offering goes a step further by using ML to eliminate false positives and provide highly contextualized security findings. This empowers developers to remediate security issues quickly and efficiently without disrupting the development workflow.

**Why SAST Matters:**

• Identify vulnerabilities early in development.

• Reduce costs by fixing issues before deployment.

• Enhance application security posture.


# SCA

Keep Track of Vulnerable Dependencies with Software Composition Analysis

**Software Composition Analysis (SCA)** is the practice of identifying, managing, and securing open-source components and third-party libraries used within software projects. These components, while essential for modern development, can introduce vulnerabilities that attackers exploit, resulting in significant security and compliance risks.

AquilaX AI’s SCA takes this a step further by combining **intelligent vulnerability scanning** with **license compliance analysis**. This dual capability allows organizations to not only detect vulnerabilities but also ensure proper use of open-source licenses within their projects. With contextual insights tailored to your application, AquilaX prioritizes the most critical risks, empowering developers to maintain robust security and compliance standards without sacrificing innovation.

#### Why SCA with License Scanning Matters:

* **Proactive Risk Management**: Identify and remediate vulnerabilities in open-source and third-party components before they can be exploited.
* **License Compliance**: Ensure adherence to open-source license requirements, avoiding legal and operational risks tied to improper usage.
* **Contextual Insights**: Understand how vulnerabilities and license conflicts impact your specific project, ensuring targeted remediation efforts.
* **Enhanced Productivity**: Streamline development processes by integrating security and compliance checks directly into the development pipeline.

By incorporating **license scanning** into SCA, AquilaX helps organizations stay secure, compliant, and agile, even as they leverage the power of open-source technologies.


# Container Scanning

Secure Your Containers from Vulnerabilities

Container Scanning is the process of examining container images for security vulnerabilities, misconfigurations, or malware. As containers become more prevalent in modern software development, ensuring their security is paramount to protecting applications in production.\\

AquilaX AI’s Container Scanning uses cutting-edge ML algorithms to analyze both the base images and custom layers of your containers. This scanning ensures that only secure, compliant, and optimized images are deployed, reducing the attack surface of containerized applications.

**Why Container Scanning Matters:**

• Secure your containerized applications.

• Detect vulnerabilities in container layers.

• Ensure compliance and reduce production risks.


# IaC Scanning

Infrastructure-as-Code Security for Modern DevOps

Infrastructure-as-Code (IaC) allows developers to define and manage infrastructure using code, but this can also introduce security risks. Misconfigurations, such as overly permissive access controls or unencrypted storage, can leave your infrastructure vulnerable to attacks.\\

AquilaX AI’s IaC Scanning helps identify these risks early by scanning IaC templates (e.g., Terraform, CloudFormation) for misconfigurations and vulnerabilities. By integrating IaC scanning into the development pipeline, organizations can ensure secure cloud infrastructure from the start, minimizing the risk of exposure.

**Why IaC Scanning Matters:**

• Prevent misconfigurations in cloud infrastructure.

• Secure infrastructure from the codebase level.

• Automate security in DevOps practices.


# API Security

API Scanning involves the examination of application programming interfaces (APIs) for vulnerabilities, misconfigurations, and security flaws. As APIs play a critical role in connecting systems and enabling functionalities, any weaknesses in APIs can be exploited by attackers to gain unauthorized access or launch attacks like injection, denial of service, or data exfiltration.\\

AquilaX AI’s API Scanning focuses on providing deep, contextualized analysis of API endpoints. Using ML, it accurately detects risks and prioritizes fixes, ensuring secure APIs without sacrificing performance or usability.\\

**Why API Scanning Matters:**

• Secure critical communication channels.

• Prevent data leaks and unauthorized access.

• Ensure secure integration between services.


# Malware Scanning

Protect Your Code from Malicious Software

Malware Scanning is the process of detecting malicious software embedded within your codebase or dependencies. Malware can introduce backdoors, compromise sensitive data, or disrupt services, leading to severe financial and reputational damages.

AquilaX AI’s Malware Scanning leverages advanced ML techniques to analyze code, binaries, and third-party libraries for hidden malware. By incorporating this into the security pipeline, organizations can ensure that they are not unknowingly introducing malicious code into their applications.

**Why Malware Scanning Matters:**

• Prevent malware from entering production.

• Protect sensitive systems and data.

• Mitigate risks of backdoors and malicious exploits.\\

AquilaX AI offers a comprehensive suite of modern security tools powered by machine learning, helping organizations eliminate false positives and gain contextualized insights into vulnerabilities. By scanning for secrets, PII, and code vulnerabilities, and ensuring the security of APIs, containers, and infrastructure-as-code, AquilaX AI enables businesses to build secure, resilient applications that stand up to today’s sophisticated cyber threats.


# AI Generated Code

Scanning for AI Generated Code

The rise of generative AI tools, such as code assistants and automated programming frameworks, there is an urgent need to evaluate and mitigate the security risks associated with these advancements. AquilaX aims to address these challenges by developing an code scanner, specifically designed to detect AI-generated source code and its associated vulnerabilities.

#### Introduction

Generative AI tools have revolutionized software development by automating code creation, enabling developers to accelerate workflows, reduce costs, and maintain competitive advantage. However, the integration of AI-generated code into applications <mark style="color:orange;">introduces unique risks</mark> that are not adequately addressed by traditional static application security testing (SAST) tools. This necessitates an approach tailored to the nuances of AI-created code.

#### Importance of Identifying AI-Generated Code

AI-generated source code has specific characteristics that make it different from human-written code. These differences include:

1. **Consistency in Patterns**: AI models tend to generate repetitive structures, which may inadvertently expose systemic vulnerabilities if not adequately reviewed.
2. **Lack of Contextual Awareness**: Generative models may fail to account for the broader application context, potentially introducing logic errors or insecure configurations.
3. **Use of Training Data**: Generated code might include snippets learned from public repositories, potentially leading to legal or security liabilities.

Understanding whether code is AI-generated is critical to implementing effective security reviews and reducing the risk of exploitation.

#### Security Implications

The adoption of AI-generated code introduces a range of security risks that can impact software integrity:

1. **Hidden Vulnerabilities**:
   * AI tools may unintentionally propagate known vulnerabilities present in their training datasets. Examples include SQL injection points or improper validation routines.
   * Systematic vulnerabilities from code patterns that evade human review but are detectable by attackers using similar AI tools​​.
2. **Hardcoded Secrets and Sensitive Data**:
   * AI tools sometimes generate code with embedded API keys or default credentials, increasing the likelihood of accidental exposure​​.
3. **Regulatory and Compliance Risks**:
   * AI-generated code that mishandles sensitive information, such as Personally Identifiable Information (PII), could result in violations of regulations like GDPR or HIPAA​​.
4. **Challenges in Attribution and Accountability**:
   * When errors or vulnerabilities arise in AI-generated code, identifying responsibility becomes challenging, particularly in collaborative projects.

#### The AquilaX Solution

To address these challenges, AquilaX is developing an AI-enabled security scanner that identifies and evaluates AI-generated code. The primary objectives of this solution are:

1. **Detection**:
   * Employ machine learning algorithms to differentiate between human-written and AI-generated code based on patterns, style, and semantic markers​​.
2. **Contextual Analysis**:
   * Analyze the broader application environment to identify vulnerabilities introduced by AI-generated code while considering its usage context.
3. **Risk Mitigation**:
   * Provide actionable remediation steps, such as rewriting vulnerable sections or isolating risky components in sandboxed environments.
4. **Ethical Considerations**:
   * Enable organizations to track the provenance of AI-generated code to ensure compliance with intellectual property and data privacy laws​​.


# License Scanning

AquilaX License Scanning Compliance Process

This documentation describes the AquilaX compliance process for detecting and handling license mismatching violations in software projects. The process is powered by the AquilaX GenAI Application Security Platform, leveraging AI to ensure comprehensive and efficient license compliance.

### **Objective**

To automate and streamline license scanning using AquilaX's platform, identifying mismatched or incompatible licenses across all project dependencies to ensure compliance with organizational and legal standards.

### **Process Overview**

#### **1. Initialization**

The license scanning module in AquilaX begins by integrating with your project's repository, extracting all declared and transitive dependencies, and identifying associated licenses.

#### **2. License Policy Definition**

AquilaX allows organizations to define license compliance policies, which include:

* Approved licenses (e.g., MIT, Apache 2.0).
* Restricted or incompatible licenses (e.g., AGPL, proprietary licenses).
* Exceptions based on use cases or environments.

#### **3. Scanning Process**

The scanning process includes:

1. **Dependency Detection:** Parsing dependency manifests (e.g., `package.json`, `pom.xml`, `requirements.txt`) and lockfiles.
2. **License Identification:** Mapping dependencies to their respective licenses via SPDX metadata or project-specific files.
3. **Policy Matching:** Comparing each dependency license against the defined compliance policy.
4. **Violation Reporting:** Flagging mismatched licenses and providing detailed violation reports.

#### **4. Remediation**

AquilaX provides:

* Suggested remediation steps for replacing non-compliant libraries.
* Automated license override workflows where applicable.


# Dynamic Scan - DAST

AquilaX DAST Integration via Vulnix0 — Technical Documentation

### 1. Overview of DAST in the Vulnix0 Context

AquilaX leverages [Vulnix0](https://vulnix0.com/) as the underlying scanning and attack simulation engine for Dynamic Application Security Testing (DAST). Within the Vulnix0 platform:

* DAST is categorized as one of several automated security modules, alongside Attack Surface Management (ASM), Automated Penetration Testing, and Threat Intelligence.&#x20;
* DAST scans live, running web applications and exposes runtime vulnerabilities and misconfigurations without requiring access to source code.&#x20;

From a technical standpoint, this means AquilaX’s DAST capability conducts black‑box testing — scanning external interfaces, injecting payloads, and observing runtime behaviors to detect exploitable flaws (e.g., XSS, SQLi, missing security headers).&#x20;

***

### 2. Engine Behavior and Scanning Workflow

The DAST scan logic implemented via Vulnix0 includes the following core phases:

#### 2.1 Discovery and Reconnaissance

* Scanning initiates with dynamic reconnaissance: enumerates subdomains and virtual hosts, enumerates endpoints, and maps live application structure.&#x20;
* The engine identifies accessible directories and files (e.g., /dashboard, /sitemap.xml), and collects metadata (security headers, server responses).&#x20;

This preliminary crawl builds an application model used in subsequent attack simulation.

***

#### 2.2 Runtime Attack Simulation

* DAST actively issues requests that simulate real‑world attack vectors against the running application.
* These probes test for protocol abuses, injection points, and business logic anomalies.

Examples of simulated conditions might include:

* Manipulating cookies and session tokens to test secure flag requirements.
* Suppressing or modifying security headers (e.g., CSP, X‑Frame‑Options) to see if responses indicate exposure.&#x20;

This behavior aligns with the general definition of DAST as external (black‑box) testing against a running target — with no visibility into application internals.&#x20;

***

### 3. Categories of Vulnerabilities Identified

The DAST capability surfaces vulnerabilities across multiple technical vector types:

#### 3.1 Misconfiguration Issues

The scanner checks security controls at the HTTP/TLS layer:

* Verification of header presence/values (e.g., missing HSTS, CSP).
* Detection of insecure cookies lacking HttpOnly/Secure.&#x20;

These checks combine positive validation (security headers correctly implemented) and negative validation (missing/weak controls).

***

#### 3.2 Sensitive Information Exposure

By crawling and probing accessible resources, the engine reports:

* Exposed files or directories that could leak infrastructure insights or policy data (e.g., public security.txt, sitemap data).&#x20;

This includes runtime enumeration of content that may not be known by development teams, effectively functioning as reconnaissance intelligence.

***

#### 3.3 Control Validation

Beyond vulnerability detection, the DAST engine executes tests to verify the effectiveness of existing security controls:

* Validates bot protection by analyzing response codes under automated traffic.
* Confirms proper operation of TLS and HSTS policies.&#x20;

This shows capabilities beyond pure flaw discovery — validating whether deployed mitigation mechanisms actually work under stress.

***

### 4. Data Output and Reports

Scans generate structured output that typically includes:

* Finding metadata — classification, severity, proof evidence.
* Raw scan data — captured request/response traces relevant to the finding (e.g., missing header JSON).&#x20;
* Remediation guidance — concise recommendations for developers or operations teams.

For example, a missing CSP header finding may include raw evidence demonstrating absence (empty value) and suggested policy enforcement.&#x20;

These outputs are consumed by AquilaX for:

* Internal dashboards.
* Integration into CI/CD pipelines (as technical feedback to DevOps).
* Automated ticketing/alerting flows.

***

### 5. Integration in the AppSec Toolchain

AquilaX’s use of DAST via Vulnix0 is positioned as a runtime validation tool in the broader security toolchain:

* Standalone Runtime Testing — DAST runs against deployed or staging environments where the application is live.
* Complement to Static Analysis (SAST) — DAST catches runtime and configuration issues that static code analysis cannot.&#x20;
* Part of CI/CD Gate Checks — scans can be automated as a final quality gate before deployment.

Integration is technical and can be automated via API key authentication (as documented in API docs), supporting scripting or orchestration with DevSecOps pipelines.&#x20;

***

### 6. Operational Considerations

From a security engineering perspective:

#### 6.1 Coverage and Environment

* DAST can run against production or staging environments, though staging is recommended to avoid unintended side effects from aggressive probes.&#x20;
* The scan must be configured with hostnames and credentials (for authenticated scanning) where necessary.

***

#### 6.2 Risk and Control

* Since the engine simulates malicious traffic, control over scan intensity and potential side effects (rate limiting, safe scanning modes) is necessary.
* Outputs require triage by security engineers to prioritize and plan remediation.

***

### 7. Summary — Key Technical Capabilities

AquilaX’s DAST via Vulnix0 provides:

* Automated black‑box runtime testing for web applications.&#x20;
* Attack surface enumeration at HTTP/TLS and resource levels.&#x20;
* Security control validation mechanisms.&#x20;
* Structured scan outputs suitable for DevSecOps automation.&#x20;

<br>

In essence, this integrated DAST service is designed to detect real, exploitable vulnerabilities and configuration flaws at runtime, supplementing source‑code analysis and other AppSec tooling.&#x20;


# How to start a DAST Scan

Step by Step guide how to start a Dynamic scan within AquilaX

1. Signing to AquilaX platform (<https://aquilax.ai)&#x20>;
2. Make sure you select an Organization (top-left) that have ultimate license in it
3. Click on "Security Policy" and and make sure "DAST" is enabled (you need to do this once)
4. Then click on the "New Scan" and set in the end-point field the right domain you want to scan, and click "scan now"

<figure><img src="/files/CZxaM7M5hQ5oRrgZggma" alt="" width="375"><figcaption></figcaption></figure>

5. After the scan is finish you can consult all the finding, similar to SAST, SCA etc... however for dynamic scanning results you should see these findings under the DAST category


# DevTools

Ways to use AquilaX

A series of development tools to get started with AquilaX Functionalities

{% content-ref url="/pages/tRyvv1U1ZHaBhIXVRyKP" %}
[GitLab Integration](/user-manual/devtools/ci-cd/gitlab-integration)
{% endcontent-ref %}

{% content-ref url="/pages/JCyIHAIT9HlctvcFcpHT" %}
[GitHub Integration](/user-manual/devtools/ci-cd/github-integration)
{% endcontent-ref %}

{% content-ref url="/pages/OlaME0BX8zBiv8P6dGDo" %}
[AquilaX CLI](/user-manual/devtools/aquilax-cli)
{% endcontent-ref %}

{% content-ref url="/pages/PpjlnMRpzw6DS6aMR3ge" %}
[Vulnerability Tickets](/user-manual/devtools/vulnerability-tickets)
{% endcontent-ref %}


# AquilaX CLI

AquilaX CLI is a command-line interface for the AquilaX Application Security Platform

**Supported Python Versions:** 3.6+

### Installation

#### Via PyPI

```bash
pip install aquilax
```

#### From Source

```bash
git clone https://github.com/AquilaX-AI/AquilaX-Client.git
cd AquilaX-Client
pip install -e .
```

#### Verification

```bash
aquilax --version
```

### Authentication

#### Login

```bash
aquilax login <token>
```

For self-hosted instances:

```bash
aquilax login <token> --server <url>
```

**Parameters:**

* `<token>`: API authentication token
* `--server`: (Optional) Server URL (default: `https://aquilax.ai`)

#### Logout

```bash
aquilax logout
```

### Configuration

#### Set Default Organization

```bash
aquilax --set-org <org_id>
```

#### Set Default Group

```bash
aquilax --set-group <group_id>
```

#### Configuration File Location

* Linux/macOS: `~/.aquilax/config.json`
* Windows: `%USERPROFILE%\.aquilax\config.json`

**Structure:**

```json
{
  "apiToken": "your_api_token",
  "baseUrl": "https://aquilax.ai",
  "org_id": "507f1f77bcf86cd799439011",
  "group_id": "507f1f77bcf86cd799439012"
}
```

### Available Scanners

| Scanner           | Function                                       |
| ----------------- | ---------------------------------------------- |
| PII Scanner       | Detects personally identifiable information    |
| Secret Scanner    | Identifies exposed credentials and API keys    |
| IaC Scanner       | Analyzes Infrastructure as Code configurations |
| SAST Scanner      | Static application security testing            |
| SCA Scanner       | Software composition analysis for dependencies |
| Container Scanner | Container security analysis                    |
| Image Scanner     | Docker image scanning                          |
| CI/CD Scanner     | Pipeline configuration security review         |

### Commands

#### scan

Initiate a security scan on a Git repository.

```bash
aquilax scan <git_uri> [options]
```

**Options:**

| Flag         | Description                      | Default      |
| ------------ | -------------------------------- | ------------ |
| `--scanners` | Scanners to execute              | All scanners |
| `--branch`   | Target branch                    | `main`       |
| `--sync`     | Real-time monitoring             | Disabled     |
| `--format`   | Output format: `json` or `table` | `table`      |

**Examples:**

```bash
# All scanners, default branch
aquilax scan https://github.com/org/repo

# Specific branch with sync
aquilax scan https://github.com/org/repo --branch develop --sync

# Specific scanners only
aquilax scan https://github.com/org/repo --scanners secret_scanner sast_scanner

# JSON output
aquilax scan https://github.com/org/repo --format json
```

#### ci-scan

CI/CD-optimized scanning with policy enforcement.

```bash
aquilax ci-scan <git_uri> [options]
```

**Options:**

| Flag              | Description                            | Default            |
| ----------------- | -------------------------------------- | ------------------ |
| `--org-id`        | Organization ID                        | Configured default |
| `--group-id`      | Group ID                               | Configured default |
| `--branch`        | Target branch                          | `main`             |
| `--sync`          | Real-time monitoring                   | Disabled           |
| `--fail-on-vulns` | Exit non-zero if vulnerabilities found | Disabled           |
| `--format`        | Output format: `json` or `table`       | `table`            |
| `--output-dir`    | PDF report directory                   | Current directory  |
| `--save-pdf`      | Save PDF report                        | Disabled           |

**Examples:**

```bash
# Basic scan
aquilax ci-scan https://github.com/org/repo

# Fail build on vulnerabilities
aquilax ci-scan https://github.com/org/repo --fail-on-vulns

# Override org/group
aquilax ci-scan https://github.com/org/repo \
  --org-id 507f1f77bcf86cd799439011 \
  --group-id 507f1f77bcf86cd799439012
```

#### pull

Retrieve scan results by ID.

```bash
aquilax pull <scan_id> [options]
```

**Options:**

| Flag         | Description                      | Default            |
| ------------ | -------------------------------- | ------------------ |
| `--org-id`   | Organization ID                  | Configured default |
| `--group-id` | Group ID                         | Configured default |
| `--format`   | Output format: `json` or `table` | `table`            |

**Example:**

```bash
aquilax pull 507f1f77bcf86cd799439013 --format json
```

#### get orgs

List accessible organizations.

```bash
aquilax get orgs
```

#### get groups

List groups within an organization.

```bash
aquilax get groups [--org-id <org_id>]
```

#### get scan-details

Retrieve detailed scan information.

```bash
aquilax get scan-details --scan-id <scan_id> [options]
```

**Options:**

| Flag         | Description                      | Default            |
| ------------ | -------------------------------- | ------------------ |
| `--org-id`   | Organization ID                  | Configured default |
| `--group-id` | Group ID                         | Configured default |
| `--format`   | Output format: `json` or `table` | `table`            |

### Output Formats

#### Table Format

```
╭─────────────────┬──────────────────────┬─────────────────────────┬──────────┬─────────┬────────╮
│ Scanner         │ Path                 │ Vulnerability           │ Severity │ CWE     │ OWASP  │
├─────────────────┼──────────────────────┼─────────────────────────┼──────────┼─────────┼────────┤
│ secret_scanner  │ config/database.yml  │ Hardcoded API Key       │ HIGH     │ CWE-798 │ A02    │
│ sast_scanner    │ app/controllers/...  │ SQL Injection           │ CRITICAL │ CWE-89  │ A03    │
╰─────────────────┴──────────────────────┴─────────────────────────┴──────────┴─────────┴────────╯
```

#### JSON Format

```json
{
  "scan_id": "507f1f77bcf86cd799439013",
  "status": "COMPLETED",
  "findings": [
    {
      "scanner": "secret_scanner",
      "path": "config/database.yml",
      "vuln": "Hardcoded API Key",
      "severity": "HIGH",
      "cwe": ["CWE-798"],
      "owasp": ["A02"]
    }
  ]
}
```

### Security Policy Enforcement

Security policies are configured at the group level. Scans fail when vulnerability counts exceed defined thresholds.

**Threshold Types:**

* `total`: Maximum total vulnerabilities
* `CRITICAL`: Maximum critical severity findings
* `HIGH`: Maximum high severity findings
* `MEDIUM`: Maximum medium severity findings
* `LOW`: Maximum low severity findings

**Example:**

```
Security Policy Thresholds:
  - total: 10
  - CRITICAL: 0
  - HIGH: 2
  - MEDIUM: 5
  - LOW: 10
```

When thresholds are exceeded:

```
Thresholds exceeded: CRITICAL (2) > 0; HIGH (5) > 2
Pipeline failed due to security policy violations.
```

### CI/CD Integration

#### GitHub Actions

```yaml
name: Security Scan
on: [push]

jobs:
  scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v2
      - name: Run AquilaX Scan
        run: |
          pip install aquilax
          aquilax login ${{ secrets.AQUILAX_TOKEN }}
          aquilax ci-scan ${{ github.repository }} --fail-on-vulns
```

#### GitLab CI

```yaml
security_scan:
  stage: test
  script:
    - pip install aquilax
    - aquilax login $AQUILAX_TOKEN
    - aquilax ci-scan $CI_REPOSITORY_URL --branch $CI_COMMIT_BRANCH --fail-on-vulns
```

#### Jenkins

```groovy
stage('Security Scan') {
    steps {
        sh 'pip install aquilax'
        sh 'aquilax login ${AQUILAX_TOKEN}'
        sh 'aquilax ci-scan ${GIT_URL} --fail-on-vulns --format json > scan-results.json'
    }
}
```

#### Azure DevOps

```yaml
- task: CmdLine@2
  inputs:
    script: |
      pip install aquilax
      aquilax login $(AQUILAX_TOKEN)
      aquilax ci-scan $(Build.Repository.Uri) --fail-on-vulns
```

### Troubleshooting

#### Module Import Errors

**Issue:** `ModuleNotFoundError: No module named 'aquilax'`

**Resolution:**

```bash
pip install aquilax
source venv/bin/activate  # Linux/macOS
venv\Scripts\activate     # Windows
```

#### Authentication Errors

**Issue:** `401 Unauthorized`

**Resolution:**

```bash
aquilax logout
aquilax login <correct_token>
```

#### Repository Access Errors

**Causes:**

* Incorrect repository URL
* Insufficient access permissions
* Invalid branch name

**Resolution:**

* Verify repository URL
* Confirm platform has repository access
* Check branch exists: `git branch -a`

#### Connection Issues

**Resolution:**

```bash
# Verify server URL
aquilax login <token> --server https://correct-url.com

# Test connectivity
curl https://your-server.com/health
```

### Environment Variables

```bash
export AQUILAX_SERVER="https://your-instance.com"
```

### Support

* Email: <support@aquilax.ai>
* Website: <https://aquilax.ai>
* Documentation: <https://docs.aquilax.ai>
* Issues: <https://github.com/AquilaX-AI/AquilaX-Client/issues>

{% embed url="<https://vimeo.com/1013653906?share=copy>" %}
AquilaX Sync Scan
{% endembed %}

### More Details

You can simple type `aquilax -h` for more details or you can visit the open source repo of the CLI here: <https://github.com/AquilaX-AI/AquilaX-Client>

If you find any issue or any suggestion for improvement, we love to hear from you: <https://uptime.betterstack.com/report/QK1Vyg2gkGYXXe8YDePQpuyX>


# CI/CD

Integrate AquilaX within your CICD pipeline

<table data-card-size="large" data-view="cards"><thead><tr><th></th><th></th><th></th><th data-type="content-ref"></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td></td><td><img src="/files/xoCDYAhSk2D2FgeEjzjq" alt="" data-size="original"></td><td><a href="https://github.com/AquilaX-AI/template-pipeline"><strong><code>GitHub Action</code></strong></a></td><td></td><td></td></tr><tr><td></td><td><img src="/files/D2NZt9ZD9AChdpQ2qaRQ" alt="" data-size="original"></td><td><a href="https://gitlab.com/aquila-x/cicd-template"><strong><code>GitLab Job</code></strong></a></td><td></td><td></td></tr><tr><td></td><td></td><td></td><td><a href="/pages/ks0sjFOK8WAdLsQj1UPv">/pages/ks0sjFOK8WAdLsQj1UPv</a></td><td><a href="/files/bdljuGoGjgV2jQS2BbMf">/files/bdljuGoGjgV2jQS2BbMf</a></td></tr></tbody></table>


# GitHub Integration

How to scan your code with AquilaX with GitHub Action

## AquilaX Security Scan GitHub Action

AquilaX Security Scan is a comprehensive security analysis tool designed to scan your repositories for vulnerabilities, including issues related to sensitive data exposure, insecure configurations, and common coding weaknesses. The AquilaX Security Scan integrates seamlessly into your CI/CD pipeline to automatically check your repository every time you push or open a pull request.

### Why Use AquilaX Security Scan?

* **Automated Security Audits**: Automatically scan your repository for security vulnerabilities every time code is pushed to the main branch or during pull requests.
* **Comprehensive Scanners**: Includes scanners for sensitive data exposure (PII), insecure configurations (IaC), container vulnerabilities, code quality (SAST), and more.
* **SARIF Integration with GitHub Security**: Easily upload scan results in SARIF format to GitHub's security dashboard for detailed insights.
* **Improved Security Posture**: Identify and fix security vulnerabilities early in the development cycle to minimize risks.
* **Customizable**: Allows you to set organization ID, group ID, and various scan configurations to suit your project needs.

### Setup and Configuration

#### 1. Add the GitHub Actions YAML File

First, create a new workflow file in your repository. This file will configure the AquilaX Security Scan as part of your CI/CD pipeline.

**1. Create a .github/workflows/aquilax-security-scan.yml file.**

Add the following content:

```yaml
name: AquilaX Security Scan

on:
  push:
    branches:
      - '*'  # Run on all branches

permissions:
  contents: read
  security-events: write

jobs:
  aquilax_scan:
    runs-on: ubuntu-latest
    steps:
      - name: Checkout repository
        uses: actions/checkout@v3

      - name: Set up Python
        uses: actions/setup-python@v4
        with:
          python-version: '3.9'

      - name: Install AquilaX CLI
        run: pip install aquilax

      - name: AquilaX CI Scan
        env:
          AQUILAX_AUTH: ${{ secrets.AQUILAX_API_TOKEN }}
        run: |
          GIT_URL="https://github.com/${{ github.repository }}.git"
          aquilax ci-scan \
            "$GIT_URL" \
            --org-id "${{ vars.AQUILAX_ORG_ID }}" \
            --group-id "${{ vars.AQUILAX_GROUP_ID }}" \
            --branch ${GITHUB_REF#refs/heads/}

      - name: Upload SARIF to GitHub Security
        uses: github/codeql-action/upload-sarif@v3
        with:
          sarif_file: results.sarif
```

#### 2. Set GitHub Secrets

To securely authenticate with AquilaX and prevent exposing sensitive information, set up your secrets in GitHub:

Navigate to your GitHub repository.

Click on **Settings** > **Secrets and Variables** > **Actions**.

Click **New repository secret**.

Add the following secrets:

`AQUILAX_API_TOKEN: The API token for authenticating with AquilaX.`

You can find these values from your AquilaX dashboard (app.aquilax.ai) / Aquilax CLI

```bash
aquilax get orgs # output is your org id
aquilax get groups --org-id "org_id"
--scanners sast_scanner iac_scanner secret_scanner pii_scanner sca_scanner container_scanner cicd_scanner \ # scanners you want to enable
```

Also, you can set

```bash
--fail_on_vulns # Vulnerabilities found, but pipeline will continue due to 'fail_on_vulns' set to false else if vulnerabilities are found pipeline will break.
```

### Usage

Once you’ve set up the workflow and secrets:

Run on Push: Every time a new commit is pushed to the main branch, the AquilaX Security Scan will automatically start. Run on Pull Requests: The scan will also run on pull requests to main, ensuring that no vulnerabilities are introduced through new code changes.

#### Benefits of Using AquilaX Security Scan

Automated Security Checks

### Screenshots

![App Screenshot](https://i.pinimg.com/736x/02/45/64/02456463a2f50a33ea1e81deb8bea1b0.jpg)

### Support

For support, email <admin@aquilax.ai>

### More Links

* [Website](https://aquilax.ai)
* [Dashboard](https://app.aquilax.ai)
* [Github](https://github.com/AquilaX-AI)


# GitLab Integration

How to scan your code with AquilaX with GitLab Jobs

## AquilaX Security Scan Gitlab Action

AquilaX Security Scan is a comprehensive security analysis tool designed to scan your repositories for vulnerabilities, including issues related to sensitive data exposure, insecure configurations, and common coding weaknesses. The AquilaX Security Scan integrates seamlessly into your CI/CD pipeline to automatically check your repository every time you push or open a pull request.

### Why Use AquilaX Security Scan?

* **Automated Security Audits**: Automatically scan your repository for security vulnerabilities every time code is pushed to the main branch or during pull requests.
* **Comprehensive Scanners**: Includes scanners for sensitive data exposure (PII), insecure configurations (IaC), container vulnerabilities, code quality (SAST), and more.
* **SARIF Integration with GitLab Security**: Easily upload scan results in SARIF format to **GitLab's** security dashboard for detailed insights.
* **Customizable**: Allows you to set organization ID, group ID, and various scan configurations to suit your project needs.

### Setup and Configuration

#### 1. Add the Gitlab Actions YAML File

First, create a new workflow file in your repository. This file will configure the AquilaX Security Scan as part of your CI/CD pipeline.

**1. Create a .gitlab-ci.yml file.**

Add the following content:

<pre class="language-yaml"><code class="lang-yaml">stages:
  - aquilax
  
Security Scan:
  stage: aquilax
  image: python:3.12-slim
  allow_failure: true
  timeout: 5m
  script:
    - |
      echo "$CI_PROJECT_URL.git" - "$CI_COMMIT_REF_NAME"
      pip3 install --no-cache-dir --upgrade aquilax
      aquilax -v
      aquilax login "$AQUILAX_TOKEN" --server "<a data-footnote-ref href="#user-content-fn-1">https://aquilax.ai</a>" || exit 1
      aquilax ci-scan \
        "$CI_PROJECT_URL".git \
        --org-id "$AQUILAX_ORG_ID" \
        --group-id "$AQUILAX_GROUP_ID" \
        --branch "$CI_COMMIT_REF_NAME"
  artifacts:
    when: always 
    paths:
      - results.sarif
  rules:
    - if: '$CI_PIPELINE_SOURCE != "schedule"'

</code></pre>

#### 2. Set **GitLab** Secrets

To securely authenticate with AquilaX and prevent exposing sensitive information, set up your secrets in **GitLab**:

On the left sidebar, click on Settings to expand the menu. Under Settings, click on CI/CD.

in the CI/CD settings page, scroll down to the Variables section. Click on the Expand button next to Variables if it's not already expanded.

Click on the Add variable button.

Key: **Enter** `AQUILAX_TOKEN` as the variable key. Value: Enter your actual AquilaX API token. This is the token you use to authenticate with the AquilaX API. Type: Leave it as Variable. Environment scope: Set it to \* (the default) to make it available in all environments.

Click on the Add variable button at the bottom of the variable form to save your new CI/CD variable.

#### 3. Set Organization ID and Group ID

In the YAML file, update the placeholders with your organization ID and group ID:

```yaml
  AQUILAX_ORG_ID: "ORG_ID"
  AQUILAX_GROUP_ID: "GROUP_ID"
```

### Usage

Once you’ve set up the workflow and secrets:

Run on Push: Every time a new commit is pushed to the main branch, the AquilaX Security Scan will automatically start.

#### Benefits of Using AquilaX Security Scan

Automated Security Checks

### Support

For support, email <admin@aquilax.ai>.

### More Links

* [Website](https://aquilax.ai)
* [Dashboard](https://app.aquilax.ai)
* [Github](https://github.com/AquilaX-AI)

[^1]: Add your own server instance


# Azure DevOps Integration

Integrate AquilaX security scanning into your Azure DevOps CI/CD pipelines to automatically detect vulnerabilities, security issues, and compliance violations in your codebase.

Table of Contents

1. Prerequisites
2. Setup Instructions
3. Pipeline Configuration
4. Viewing Scan Results
5. Troubleshooting
6. Advanced Configuration

***

### Prerequisites

* Azure DevOps organization and project with pipeline permissions
* AquilaX account with API access
* Required AquilaX credentials:
  * API Token
  * Organization ID
  * Group ID

***

### Setup Instructions

#### Step 1: Obtain AquilaX Credentials

1. Log in to your AquilaX dashboard
2. Navigate to **Settings** → **API Tokens**
3. Copy your API Token, Organization ID, and Group ID

#### Step 2: Configure Azure DevOps Variables

1. In Azure DevOps, go to **Pipelines** → Select your pipeline → **Edit** → **Variables**
2. Add the following secret variable:
   * **Name**: `AQUILAX_API_TOKEN`
   * **Value**: Your API token
   * ✅ Enable **Keep this value secret**

#### Step 3: Create Pipeline File

Create `azure-pipelines.yml` in your repository root with the configuration below.

***

### Pipeline Configuration

#### Basic Pipeline Template

```yaml
trigger:
  - main

pr:
  - "*"

variables:
- name: AQUILAX_ORG_ID 
  value: "YOUR_ORGANIZATION_ID"
 
- name: AQUILAX_GROUP_ID 
  value: "YOUR_GROUP_ID"

- name: AQUILAX_GIT_URL
  value: "$(Build.Repository.Uri)"

- name: AQUILAX_BRANCH
  value: "$(Build.SourceBranchName)"

stages:
- stage: SecurityScan
  displayName: "AquilaX Security Scan"

  jobs:
  - job: AquilaXScan
    displayName: "Run AquilaX CI Scan"
    timeoutInMinutes: 10
    continueOnError: true

    pool:
      vmImage: "ubuntu-latest"

    steps:
    - checkout: self

    - task: UsePythonVersion@0
      inputs:
        versionSpec: "3.12"
      displayName: "Use Python 3.12"

    - script: |
        pip install --no-cache-dir --upgrade aquilax
        aquilax -v
      displayName: "Install AquilaX CLI"

    - script: |
        echo "Repo: $(Build.Repository.Uri)"
        echo "Branch: $(Build.SourceBranchName)"

        pip install --no-cache-dir --upgrade aquilax

        aquilax login "$(AQUILAX_API_TOKEN)" || exit 1

        aquilax ci-scan \
          "$(Build.Repository.Uri)" \
          --org-id "$(AQUILAX_ORG_ID)" \
          --group-id "$(AQUILAX_GROUP_ID)" \
          --branch "$(Build.SourceBranchName)"

      displayName: "Run AquilaX Security Scan"
      continueOnError: true
```

#### Configuration Parameters

| Variable            | Type     | Description                                          |
| ------------------- | -------- | ---------------------------------------------------- |
| `AQUILAX_API_TOKEN` | Secret   | API authentication token (stored as secret variable) |
| `AQUILAX_ORG_ID`    | Variable | Organization identifier                              |
| `AQUILAX_GROUP_ID`  | Variable | Group/project identifier                             |
| `AQUILAX_GIT_URL`   | Auto     | Repository URL (auto-populated)                      |
| `AQUILAX_BRANCH`    | Auto     | Branch name (auto-populated)                         |

<figure><img src="/files/fkyIqdbKUmcOcwX07d7P" alt=""><figcaption></figcaption></figure>

#### Key Settings

**Triggers**

* `trigger: - main` - Runs on commits to main branch
* `pr: - "*"` - Runs on all pull requests

**Pipeline Behavior**

* `timeoutInMinutes: 10` - Scan timeout (adjust based on repository size)
* `continueOnError: true` - Pipeline continues even if issues are found (set to `false` to enforce security gates)
* `vmImage: "ubuntu-latest"` - Build agent (alternatives: `windows-latest`, `macos-latest`)

***

### Viewing Scan Results

#### Access Results

1. Navigate to **Pipelines** → **Runs** → Select your run
2. Click **Artifacts** section
3. Download **AquilaX-Scan-Results** → `results.sarif`

<figure><img src="/files/djEwARrly5XHJaZVQQvt" alt=""><figcaption></figcaption></figure>

#### SARIF Report Contents

The SARIF report includes:

* Vulnerability details with severity levels
* Affected code locations
* Remediation recommendations
* Compliance findings

<figure><img src="/files/71vnLokB1JlVY2MvlMlT" alt=""><figcaption></figcaption></figure>

***

### Visual Guide

#### 1. **Pipeline Variables Setup**

Configure the API token as a secret variable in Azure DevOps.

#### 2. **Pipeline Run Overview**

View the pipeline execution status with all stages completed successfully.

#### 3. **Scan Execution Log**

Console output showing repository information, AquilaX CLI installation, and scan execution.

#### 4. **Scan Results Summary**

Security findings breakdown showing vulnerability counts by severity level.

#### 5. **Dashboard Results Link**

Complete scan results available on the AquilaX dashboard.

<figure><img src="/files/LJh4eYgDZbP6GKRqK1JP" alt=""><figcaption></figcaption></figure>

***

### Troubleshooting

#### Common Issues

| Issue                              | Solution                                                                         |
| ---------------------------------- | -------------------------------------------------------------------------------- |
| **API token not found**            | Verify variable `AQUILAX_API_TOKEN` is created as a secret in pipeline variables |
| **Python installation fails**      | Update `versionSpec` to `"3.x"` for latest Python 3.x version                    |
| **AquilaX CLI installation fails** | Check network connectivity and PyPI access permissions                           |
| **Scan timeout**                   | Increase `timeoutInMinutes` value based on repository size                       |
| **SARIF file not generated**       | Verify scan completed successfully; add debug step to list files                 |

#### Debug Commands

```yaml
# Add before PublishBuildArtifacts step to debug
- script: |
    echo "Checking for SARIF file..."
    ls -la *.sarif || echo "No SARIF files found"
  displayName: "Debug: List SARIF files"
```

***

### Advanced Configuration

#### Multi-Branch Scanning

```yaml
trigger:
  branches:
    include:
    - main
    - develop
    - release/*
```

#### Scheduled Scans

```yaml
schedules:
- cron: "0 2 * * *"
  displayName: Daily security scan
  branches:
    include:
    - main
  always: true
```

#### Branch Protection

Enable build validation in branch policies:

1. Go to **Repos** → **Branches** → Select branch → **Branch policies**
2. Add **Build validation** → Select AquilaX pipeline
3. Set as **Required** to prevent merging with security issues

#### Multi-Stage Pipeline

```yaml
stages:
- stage: SecurityScan
  jobs:
  - job: AquilaXScan
    # ... scan configuration ...

- stage: Build
  dependsOn: SecurityScan
  condition: succeeded()
  jobs:
  - job: BuildApp
    steps:
    - script: echo "Building application..."

- stage: Deploy
  dependsOn: Build
  condition: succeeded()
  jobs:
  - deployment: DeployProd
    environment: 'production'
    strategy:
      runOnce:
        deploy:
          steps:
          - script: echo "Deploying..."
```

***

### Support

* **Documentation**: <https://docs.aquilax.ai>
* **Support**: <admin@aquilax.ai>

***

*Last Updated: February 2026*


# Vulnerability Tickets

How to raise vulnerabilities into internal VM platform

For each finding identified within AquilaX, you have the option to create an issue in GitHub Issues, GitLab, or JIRA (Atlassian) to manage it directly within your own environment. The setup page provides clear guidance to help you configure everything.

For documentation purposes, we will demonstrate how to set up all three integration modes. However, you are free to use one, two, or all three based on your specific needs.

## Organization Settings

Firstly let's make sure you give your organization access to to various tools; navigate under your organization and scroll down to the `Integrations` section, as bellow:

<figure><img src="/files/Ydi98sS5vHIxJxSsWrp4" alt=""><figcaption><p>Integrations</p></figcaption></figure>

If you’re just getting started, chances are you haven’t set up any of these yet. Don’t worry—let’s walk through the setup step by step for each integration.

### GitHub

Click on the GitHub option, and you will be redirected to the AquilaX GitHub authorization page

<figure><img src="/files/p5SQEiBrQUfwB2cnKQvw" alt=""><figcaption><p>Select your org</p></figcaption></figure>

Here, you can select the level of access you wish to grant. In addition to read access for scanning, make sure to enable permissions for AquilaX to create issues as well.

<figure><img src="/files/aexq6o7SbhDSl2uLfHdz" alt=""><figcaption><p>Allow AquilaX to create and write to issues</p></figcaption></figure>

### GitLab

Setting up GitLab is straightforward. Simply generate an API token in GitLab and grant AquilaX the necessary permissions. This includes read access to your code and the ability to create GitLab issues.

<figure><img src="/files/YRmVn3tskcjTdM405itj" alt=""><figcaption><p>GitLab integration</p></figcaption></figure>

### JIRA

JIRA is exclusively used for raising tickets. The setup process is straightforward: simply use your access token from Atlassian as shown below.

<figure><img src="/files/JKlfVaiZ9mwPBhFSX5Su" alt=""><figcaption><p>JIRA Integration</p></figcaption></figure>

That's it, all done in the organization level, these configuration is accessible to anyone within your organization.

## Group Settings

Once you’ve provided all the necessary authorizations and permissions, you can refine the setup further at the group level. This is especially useful if you need different configurations for different groups, giving you the flexibility to tailor settings as needed. Navigate to the Groups page, select the group you want to edit, and update the Security Policy section to ensure the appropriate configuration is in place.

<pre class="language-json" data-title="security policy"><code class="lang-json">{
  ...
  "jira_project_key": "<a data-footnote-ref href="#user-content-fn-1">SCRUM</a>",
  "raise_tickets": <a data-footnote-ref href="#user-content-fn-2">true</a>,
  "ticket_body": "<a data-footnote-ref href="#user-content-fn-3">Was found this {{vuln}} on this file {{file}}</a>",
  "ticket_integration": "<a data-footnote-ref href="#user-content-fn-4">GitHub, GitLab, Jira</a>",
  "ticket_title": "<a data-footnote-ref href="#user-content-fn-5">AquilaX - {{vuln}}</a>"
  ...
}
</code></pre>

A list of values and data you can include in the tickets can be used from the table that is following

<table><thead><tr><th width="210">variable</th><th></th></tr></thead><tbody><tr><td>code</td><td>Line of code identified to be vulnerable</td></tr><tr><td>confidence</td><td>confidence of the vulnerability</td></tr><tr><td>cves</td><td>CVEs associated to the vulnerability</td></tr><tr><td>cvss_score</td><td>CVSS Score</td></tr><tr><td>cvss_vector</td><td>CVSS Vector</td></tr><tr><td>cwe</td><td>CWE Array</td></tr><tr><td>git_sha</td><td>Git Commit SHA</td></tr><tr><td>git_uri</td><td>Git URI</td></tr><tr><td>id</td><td>Finding ID</td></tr><tr><td>line_start</td><td>Start of the Line</td></tr><tr><td>line_end</td><td>End of the Line</td></tr><tr><td>message</td><td>Detailed message of the vulnerability</td></tr><tr><td>path</td><td>File path</td></tr><tr><td>recommendation</td><td>Recommendation for mitigation</td></tr><tr><td>rule_id</td><td>Rule ID used to identify the vulnerability</td></tr><tr><td>scanner</td><td>Scanner name used</td></tr><tr><td>severity</td><td>Severity / Criticality</td></tr><tr><td>status</td><td>True Positive / False Positive / Unverified</td></tr><tr><td>scan_id</td><td>Scan ID</td></tr></tbody></table>

Now save the changes and navigate to any project and for each finding you can raise a ticket to the platform you need:

{% content-ref url="/pages/5f8FZuePsj2oGa4jZtZK" %}
[GitHub Issues](/user-manual/devtools/vulnerability-tickets/github-issues)
{% endcontent-ref %}

{% content-ref url="/pages/jCbsrq0L69eZfIKyuReK" %}
[GitLab Issues](/user-manual/devtools/vulnerability-tickets/gitlab-issues)
{% endcontent-ref %}

{% content-ref url="/pages/LPtn5rXm6CgwR0WtT5C4" %}
[JIRA Tickets](/user-manual/devtools/vulnerability-tickets/jira-tickets)
{% endcontent-ref %}

[^1]: must be the project name inside your jira instance

[^2]: this must be present and true to be able to raise tickets for projects under this group

[^3]: This a parametrized content of the body that will be populated into the ticket for any integration. \\

[^4]: Case sensitive value to indicate one or more integration active for raising tickets

[^5]: This a parametrized content of the title that will be populated into the ticket for any integration. \\


# GitHub Issues

How to raise a GitHub issue for a finding from AquilaX

Pre-requisite, setup Organization and Group level before you try the following, details: <https://docs.aquilax.ai/user-manual/devtools/vulnerability-tickets>. Navigate to a scanning results and click on raising ticket

<figure><img src="/files/s6glCwqtiPgLR47uvBCD" alt=""><figcaption><p>Raise Ticket</p></figcaption></figure>

<figure><img src="/files/PuejwC9tcMm7JPpmlzR3" alt=""><figcaption><p>Select a framework</p></figcaption></figure>

<figure><img src="/files/1U4DXfDVaQkJSxILgVUN" alt=""><figcaption><p>Issue is raised to GitHub</p></figcaption></figure>


# GitLab Issues

How to raise a GitLab issue for a finding from AquilaX

Pre-requisite, setup Organization and Group level before you try the following, details: <https://docs.aquilax.ai/user-manual/devtools/vulnerability-tickets>. Navigate to a scanning results and click on raising ticket

<figure><img src="/files/s6glCwqtiPgLR47uvBCD" alt=""><figcaption><p>Raise Ticket</p></figcaption></figure>

<figure><img src="/files/1uyM2zOIPpPeLV4xkRil" alt=""><figcaption><p>Select a framework</p></figcaption></figure>

<figure><img src="/files/jY8MlvopWnIQzAa9i1zL" alt=""><figcaption><p>Check out the ticket in GitLab</p></figcaption></figure>


# JIRA Tickets

How to raise a JIRA ticket for a finding from AquilaX

Pre-requisite, setup Organization and Group level before you try the following, details: <https://docs.aquilax.ai/user-manual/devtools/vulnerability-tickets>. Navigate to a scanning results and click on raising ticket

<figure><img src="/files/s6glCwqtiPgLR47uvBCD" alt=""><figcaption><p>Raise Ticket</p></figcaption></figure>

<figure><img src="/files/PuejwC9tcMm7JPpmlzR3" alt=""><figcaption><p>Select a framework (JIRA)</p></figcaption></figure>

<figure><img src="/files/D1T7s5TnPoXwZJKhj0RH" alt=""><figcaption><p>Check out the JIRA Ticket</p></figcaption></figure>


# IDE

Integrated Development Environment plugin for AquilaX


# VS Code

AquilaX AppSec VS Code Extension - Installation and Usage Guide

## Overview

The **AquilaX AppSec VS Code Extension** brings **application security directly into your development environment**, allowing developers to identify and fix vulnerabilities early in the **Software Development Life Cycle (SDLC)**.

With this extension, security findings are highlighted directly in your source code - helping you write safer code, faster.

{% embed url="<https://vimeo.com/1129183499?share=copy>" %}

***

## 🚀 Key Features

* **Real-Time Vulnerability Detection** - Security issues are highlighted inline as you code.
* **Integration with AquilaX Scans** - Automatically syncs findings from AquilaX platform scans and maps them to exact file locations.
* **Detailed Insights** - View severity, description, and recommended fixes directly within VS Code.
* **Simple Setup** - Install and connect with your AquilaX account in just a few minutes.

***

## ⚙️ Prerequisites

Before installing, make sure you have:

* **VS Code** version `1.70.0` or later
* An **active AquilaX account**
* Access to at least one configured **organization** within AquilaX

***

## 🧩 Installation Guide

### Option 1 - Install via VS Code Marketplace

1. Open **Visual Studio Code**.
2. Go to the **Extensions** view (`Ctrl+Shift+X` or `Cmd+Shift+X` on macOS).
3. Search for **AquilaX AppSec**.
4. Click **Install** on the extension published by **AquilaX Ltd**.
5. Reload VS Code when prompted.

![Screenshot: Extension Search](/files/JWLCIV8owLfIq31V5kqX)

***

### Option 2 - Direct Marketplace Link

Visit:\
👉 [AquilaX AppSec Extension](https://marketplace.visualstudio.com/items?itemName=Aquilax.aquilax-appsec)

Then click **Install** to add it to VS Code.

![Screenshot: Marketplace Install](/files/CWzyBu7dIoGlij94vYG7)

***

## 🪄 Getting Started

### Step 1 - Login

1. After installation, open the **AquilaX AppSec** icon from the VS Code sidebar.
2. Click **Sign In** to authenticate using your AquilaX credentials.
3. Follow the browser-based authentication flow.

![Screenshot: Login Screen](/files/BsAzjMQ1S3tJmBen9MNo)

***

### Step 2 - Select Organization

* If your account is linked to multiple organizations, you’ll be prompted to select one.
* Click **Select Organization** and choose the relevant organization.

![Screenshot: Organization Selection](/files/IrfJUPsitsrWPLUIQRzL)

***

### Step 3 - Open Your Project

1. Open your local project or repository in VS Code.
2. The extension automatically syncs your recent AquilaX scans.
3. Detected vulnerabilities appear as **highlighted annotations** in your code.

![Screenshot: Vulnerability Highlight](/files/RCFFFLZJC6BcrofDGwca)

***

### Step 4 - View Details

Hover over a highlighted line to view detailed vulnerability information, including:

* Vulnerability name
* Severity level
* Description
* Recommended remediation steps

![Screenshot: Vulnerability Tooltip](/files/oQ5JYJpL08wnuTUPT6Hr)

***

### Step 5 - Manage Sessions

* To **switch organizations**, click **Change Organization**.
* To **logout**, select **Logout** from the sidebar menu.

![Screenshot: Session Options](/files/dhJON2NhZtkRZG0inw6M)

***

## 🧠 Troubleshooting

### Findings Not Displayed

* Ensure your project has been scanned by AquilaX.
* Verify you’re logged in and connected to the correct organization.
* Check your internet connection.

### Authentication Issues

* Re-login via the **Login** button in the extension sidebar.
* Verify your AquilaX credentials and account status.

### Organization Not Found

* Make sure your AquilaX account has organization access.
* Contact your admin if the organization list is empty.

***

## ❓ FAQs

**Q: Do I need to trigger scans manually?**\
A: No, the extension automatically fetches the latest scan results from AquilaX.

**Q: Can I use it offline?**\
A: No, the extension requires internet access to sync scan data.

**Q: Does it support all file types?**\
A: Yes, it supports all languages and frameworks covered by AquilaX AppSec.

***

## 💬 Support

For issues, feedback, or feature requests, please contact us:

📧 **Email:** <admin@aquilax.ai>\
💡 **Feedback Portal:** <https://aquilax.featurebase.app>

***

## ❤️ Acknowledgments

Built with ❤️ by **AquilaX Ltd** - your trusted partner in **Application Security Automation**.

Powered by [AquilaX AppSec](https://aquilax.ai).


# IntelliJ

AquilaX AppSec IntelliJ IDEA Plugin Documentation

The **AquilaX AppSec** plugin for IntelliJ IDEA brings powerful security analysis directly into your development workflow. It integrates seamlessly with the AquilaX platform to provide real-time vulnerability detection, detailed findings, and automated scanning capabilities right within your IDE.

**Version:** 1.0.2 **Vendor:** AquilaX

***

### Key Features

* **🛡️ Real-time Security Analysis**: Detect vulnerabilities as you code.
* **🔍 In-Editor Highlighting**: Visual indicators for security findings directly in your source files.
* **📊 Comprehensive Dashboard**: Manage organizations, groups, and scans from a dedicated tool window.
* **🤖 Automated Scanning**: Trigger and monitor security scans without leaving IntelliJ.
* **📝 Detailed Reports**: View severity, rule IDs, descriptions, and remediation recommendations.
* **🔗 Deep Integration**: Direct links to the AquilaX web dashboard for in-depth analysis.

***

### Installation

#### Option 1: JetBrains Marketplace

1. Open IntelliJ IDEA.
2. Navigate to **Settings** (or **Preferences** on macOS) → **Plugins**.
3. Select the **Marketplace** tab.
4. Search for **"AquilaX AppSec"**.
5. Click **Install**.
6. Restart the IDE if prompted.

<figure><img src="/files/aTJAhZJWO3CJjlkwQmMo" alt=""><figcaption></figcaption></figure>

#### Option 2: Manual Installation

1. Download the plugin ZIP file from the AquilaX Releases Page.
2. Open **Settings** → **Plugins**.
3. Click the **Gear Icon** ⚙️ and select **Install Plugin from Disk...**.
4. Select the downloaded ZIP file.
5. Restart the IDE.

***

### Getting Started

#### 1. Accessing the Tool Window

After installation, you will see a new tool window named **"AquilaX AppSec"** on the right sidebar of your IDE. Click it to open the dashboard.

#### 2. Authentication

You can authenticate using one of two methods:

**Method A: Sign In with Browser (Recommended)**

1. Click the **"Sign In with Browser"** button in the tool window.
2. Your default web browser will open to the AquilaX login page.
3. Complete the authentication process.
4. You will be redirected back to IntelliJ IDEA automatically.

**Method B: Personal Access Token (PAT)**

1. Generate a Personal Access Token from your [Aquilax Profile](https://aquilax.ai/app/dashboard/pages/settings/account).
2. In the plugin tool window, enter your token in the **"Enter Personal Access Token (PAT)"** field.
3. Click **"Connect with PAT"**.

***

### Using the Plugin

#### Dashboard Configuration

Once logged in, you need to select your context:

1. **Organization**: Select your target organization from the dropdown.
2. **Group**: Select the specific project group you are working on.

<figure><img src="/files/zouWC7T0MHk7o0XViLKQ" alt="" width="429"><figcaption></figcaption></figure>

#### Running a Scan

To initiate a new security scan:

1. Ensure an Organization and Group are selected.
2. Click the **"Scan Now"** button.
3. The status label will update to show "Scan in progress...".
4. You can monitor the status or click **"Cancel Scan"** if needed.

<figure><img src="/files/JgrffKk8fQStslidIXap" alt=""><figcaption></figcaption></figure>

#### Viewing Findings

If a scan has already been completed, or once a new scan finishes:

1. Click **"See Findings"** (or "Fetch Findings").
2. The plugin will retrieve all vulnerabilities and display a summary in the console.
3. The **Status Bar** at the bottom of the IDE will update to show the total number of findings.

<figure><img src="/files/MkKVzRXIeO2Vq4cLMxYH" alt=""><figcaption></figcaption></figure>

***

### In-Editor Experience

#### Code Highlighting

The plugin automatically highlights vulnerable code segments in your open files:

* **🔴 Red Highlight**: Confirmed **True Positive** vulnerabilities.
* **🟠 Orange Highlight**: **Unverified** findings that may require review.

<figure><img src="/files/r800OZrPzyy5JDkmpVXx" alt=""><figcaption></figcaption></figure>

#### Tooltips & Details

Hover over any highlighted code to see a detailed tooltip containing:

* **Severity Icon**: (🔴 High, 🟠 Medium, 🟢 Low)
* **Rule ID**: The specific security rule violated.
* **Description**: Explanation of the vulnerability.
* **Vulnerability Snippet**: The specific code flagged.
* **Recommendation**: How to fix the issue.
* **View Details Link**: A direct link to the finding in the AquilaX Web Dashboard.

#### Project View Integration

Files containing security findings are marked with error indicators in the **Project** view, making it easy to identify which files need attention at a glance.

***

### Troubleshooting

**"Failed to load organizations"**

* Check your internet connection.
* Your session may have expired. Click **Logout** and sign in again.

**"No scan found"**

* Ensure you have selected the correct Organization and Group.
* Click **"Scan Now"** to start a fresh analysis.

**Highlights not appearing**

* Ensure the file is part of the scanned project.
* Try closing and reopening the file to refresh the findings.

***

### Support

For additional assistance, please contact our support team:

* 📧 **Email**: <support@aquilax.ai>
* 🌐 **Website**: <https://aquilax.ai/>


# Frameworks

Scanning Functionalities supported by AquilaX

{% hint style="warning" %}
Page under construction
{% endhint %}

* [x] Terraform
* [x] Terraform Plan
* [x] Helm
* [x] Kustomize
* [x] AWS SAM
* [x] Ansible Configuration
* [x] Argo Workflows Configuration
* [x] Azure ARM Templates
* [x] Azure Pipelines Configuration
* [x] Azure Bicep Configuration
* [x] BitBucket Configuration
* [x] AWS CDK
* [x] Cloudformation Configuration
* [x] Dockerfile Configuration
* [x] GitHub Configuration
* [x] GitLab Configuration
* [x] Kubernetes Configuration
* [x] OpenAPI Configuration
* [x] Serveless Frameworks


# Roles

AquilaX platform is using access roles and grouping by organization in order to authorize and control every API request

Each user may have access to any organization governed by the below access control list :

<table><thead><tr><th width="284">Operation</th><th width="178" data-type="checkbox">Security Manager</th><th width="178" data-type="checkbox">Security Engineer</th><th data-type="checkbox">Developer</th></tr></thead><tbody><tr><td>Delete Org</td><td>false</td><td>false</td><td>false</td></tr><tr><td>Update Org</td><td>false</td><td>false</td><td>false</td></tr><tr><td>Add Members (exclude owner)</td><td>true</td><td>false</td><td>false</td></tr><tr><td>Update Billing</td><td>false</td><td>false</td><td>false</td></tr><tr><td>Start Scan</td><td>true</td><td>true</td><td>true</td></tr><tr><td>Delete Scan</td><td>true</td><td>true</td><td>false</td></tr><tr><td>Create Group</td><td>true</td><td>true</td><td>true</td></tr><tr><td>Update Group</td><td>true</td><td>true</td><td>true</td></tr><tr><td>Delete Group</td><td>true</td><td>true</td><td>true</td></tr><tr><td>Update Policy (org level)</td><td>true</td><td>false</td><td>false</td></tr><tr><td>Update Policy (group level)</td><td>true</td><td>true</td><td>false</td></tr><tr><td>Update Policy (project level)</td><td>true</td><td>true</td><td>true</td></tr></tbody></table>

{% hint style="info" %}
Owner have access to all the operation for any resource within the organization that he is owner
{% endhint %}

{% hint style="warning" %}
Viewer have read only access to all the resources. Usualy this role is assigned to auditor and someone that have to review the output only
{% endhint %}


# Security Policy

Security policy is a configuration in JSON format, that is attached to a group, in order to \`instruct\` how AquilaX scanner and engine needs to behave.

You can imagine this as a set of configuration mapped into a file. Each organization can have one or multiple groups, and each group have one configuration (Security policy) defined.

\
An example of a security policy is:

<pre class="language-json" data-title=".aquilax-policy.json" data-overflow="wrap" data-line-numbers><code class="lang-json">{
    "<a data-footnote-ref href="#user-content-fn-1">avatar</a>": "https://avatars.githubusercontent.com/u/155273638?s=200&#x26;v=4",
    "<a data-footnote-ref href="#user-content-fn-1">description</a>": "<a data-footnote-ref href="#user-content-fn-2">Example Policy for testing purposes</a>",
    "author": "AquilaX Core engineering Team",
    "testing": false,
    "<a data-footnote-ref href="#user-content-fn-3">notify_on_failure</a>": true,
    "jira_project_key": "SCRUM",
    "raise_tickets": true,
    "ticket_body": "Was found this {{vuln}} on this file {{file}}",
    "ticket_integration": "GitHub, GitLab, Jira",
    "ticket_title": "AquilaX - {{vuln}}",
    "<a data-footnote-ref href="#user-content-fn-4">tags</a>": [
        "all-scanners",
        "special-project"
    ],
    "<a data-footnote-ref href="#user-content-fn-5">frequency</a>": "<a data-footnote-ref href="#user-content-fn-6">weekly</a>",
    "<a data-footnote-ref href="#user-content-fn-7">ignore</a>":[
        "test/*",
        "node_modules/*",
        "tests/*"
    ],
    "scanners": [
        {
            "enforced": true,
            "compliance": true
        },
        {
            "<a data-footnote-ref href="#user-content-fn-8">enforced</a>": true,
            "secret": true
        },
        {
            "enforced": true,
            "pii": true
        },
        {
            "enforced": false,
            "sast": true
        },
        {
            "enforced": false,
            "sca": true,
              "licenses": {
                "mixed_licenses": true,
                "prohibited": [
                  "GPL*",
                  "BSD"
                ]
              },
        },
        {
            "enforced": false,
            "container": true
        },
        {
            "enforced": true,
            "iac": true
        },
        {
            "enforced": true,
            "api": true
        },
        {
            "enforced": true,
            "malware": true
        }
    ],
    "<a data-footnote-ref href="#user-content-fn-9">repos</a>": [
        "https://github.com/aquilax-ai"
    ]
}
</code></pre>

More information how to use ticketing <https://docs.aquilax.ai/user-manual/devtools/vulnerability-tickets>

[^1]: Used for reporting (optional)

[^2]: Optional

[^3]: Notify if something goes wrong

[^4]: simple tag system for reporting and categorization

[^5]: how often you want the repos in this group to be scanned (default==once)

[^6]: \["daily", "weekly", "monthly"]

[^7]: This a list of files and folders to be ignored by the scanners

[^8]: If present and true, then the downside groups or project have to accept this action, and cannot overwrite the decision.

[^9]: A list of groups or repos to be scanned


# Custom Security Policy

This release introduces scan-level custom security policies, allowing users to override group-level security configurations on a per-scan basis.

### 🎯 Key Features

#### 1. **Custom Security Policy Per Scan**

* Define custom security policies when starting a new scan
* Override group-level policies for specific scanning requirements
* Policy automatically preserved during rescans

#### 2. **Intelligent Policy Management**

* Workers prioritize custom policies over group defaults
* **All policies** (custom and group) are normalized based on organization plan
* Automatic policy inheritance for project rescans

#### 3. **Dual Editing Modes**

* **Form Mode**: User-friendly interface for common configurations
* **JSON Mode**: Advanced editing with syntax validation

***

### 📦 Changes Summary

#### **Backend Changes**

**1. Scan Creation Endpoint (`POST /api/v2/scan`)**

**File:** `app/handlers/scan.go`

* Added `custom_security_policy` parameter to `RequestPayloadScan` struct
* Accepts dynamic JSON object (`map[string]interface{}`)
* Conditionally stored in database only when provided

**Request Schema:**

```
{
  "git_uri": "string",
  "endpoint_url": "string",
  "branch": "string",               // optional
  "initiated": "string",             // optional
  "custom_security_policy": {        // optional
    "scanners": ["compliance", "sast", "securitron"],
    "severity_threshold": "high"
  }
}
```

**2. Pending Scans API (`GET /api/v2/admin/scans/pending`)**

**File:** `app/handlers/scan_handler.go`

* Enhanced `CheckPendingScans` function with conditional logic
* If scan has `custom_security_policy` → use it as `security_policy`
* If scan lacks custom policy → use group policy
* **Both policies** are normalized based on organization plan

**Behavior:**

| Scenario             | Security Policy Source    | Plan-Based Normalization |
| -------------------- | ------------------------- | ------------------------ |
| Custom policy exists | `custom_security_policy`  | ✅ **Applied**            |
| No custom policy     | Group's `security_policy` | ✅ **Applied**            |

Important

**Plan-Based Scanner Enforcement**: All security policies (custom and group) are now normalized based on the organization's subscription plan. This ensures that even custom policies respect plan tier restrictions:

* **FREE**: Only `compliance`, `secret`, `pii` scanners
* **PREMIUM**: Adds `sast`, `sca`, `container`, `iac`, `api`
* **ULTIMATE**: All scanners including `malware`, `vibe`, `securitron`

**3. Project Scans Endpoint (`GET /api/v2/project/:project_id`)**

**File:** `app/datastores/projects.go`

* Added `custom_security_policy` to response projection
* Returns custom policy in scan listings when available

**Response Schema:**

```
[
  {
    "_id": "...",
    "created_at": 1234567890,
    "branch": "main",
    "status": "COMPLETED",
    "metadata": { "git": { "sha": "..." } },
    "custom_security_policy": {
      "scanners": ["compliance", "sast", "securitron"]
    }
  }
]
```

***

#### **Frontend Changes**

**1. New Component: Scan Security Policy Modal**

**File:** `scan-security-policy-modal.tsx`

* Dedicated modal for customizing scan-level security policies
* Toggle between Form and JSON editing modes
* Real-time validation and syntax checking
* Apply/Reset functionality

**Features:**

* 📝 Form editor for common configurations
* 🔧 Advanced JSON editor with syntax highlighting
* ✅ Validation feedback
* 🔄 Reset to group defaults

**2. Enhanced: New Scan Modal**

**File:** `new-scan-modal.tsx`

**Additions:**

* "Custom Security Policy" button (bottom left)
* Auto-fetch group security policy on modal open
* Visual badge: "Custom Policy Applied" when customized
* Passes `custom_security_policy` to API payload

**User Flow:**

1. User clicks "Start Scan"
2. Optionally clicks "Custom Security Policy"
3. Customizes policy → Apply
4. Starts scan with custom configuration

**3. Enhanced: Projects Component**

**File:** `projects-component.tsx`

**Modified Function:** `handleRescan()`

**Enhancements:**

* Fetches project's last scan via `ApiClient.getProject()`
* Extracts `custom_security_policy` from last scan (if present)
* Automatically passes it to rescan API

**Rescan Behavior:**

```
Last Scan Had Custom Policy → Rescan uses same custom policy
Last Scan Used Group Policy → Rescan uses current group policy
```

***

### 🔄 User Workflows

#### **Workflow 1: Create Scan with Custom Policy**

1. Navigate to group → Click **"Start Scan"**
2. Fill in required fields (Git URI, endpoint, branch)
3. Click **"Custom Security Policy"** button
4. Customize scanners, thresholds, or other settings
5. Click **"Apply"** → Badge shows "Custom Policy Applied"
6. Start scan

**Result:** Scan runs with custom policy, bypassing group defaults.

***

#### **Workflow 2: Rescan with Preserved Policy**

1. Navigate to project with previous custom-policy scan
2. Click **"Rescan"**
3. System automatically fetches and applies last scan's custom policy

**Result:** Rescan maintains original custom configuration.

***

#### **Workflow 3: Edit Custom Policy (JSON Mode)**

1. Click "Custom Security Policy" → Toggle to **"JSON"** tab
2. Edit raw JSON configuration
3. Validate syntax in real-time
4. Apply changes

**Result:** Advanced users can define complex custom policies.

***

### 🔌 API Integration

#### **Request Format**

```
POST /api/v2/scan
Content-Type: application/json

{
  "git_uri": "https://github.com/org/repo",
  "endpoint_url": "https://api.example.com",
  "branch": "main",
  "custom_security_policy": {
    "scanners": ["compliance", "sast", "securitron"],
    "severity_threshold": "critical",
    "exclude_patterns": ["test/*", "*.md"]
  }
}
```

#### **Response**

```
{
  "scan_id": "507f1f77bcf86cd799439011"
}
```

***

### 🛡️ Technical Details

#### **Database Schema**

Custom policies are stored in the `scans` collection:

```
{
  _id: ObjectId("..."),
  git_uri: "https://github.com/org/repo",
  branch: "main",
  status: "NEW",
  custom_security_policy: {  // Optional field
    scanners: [...],
    severity_threshold: "high"
  },
  // ... other fields
}
```

#### **Worker Integration**

Workers receive enriched scan documents from `/api/v2/admin/scans/pending`:

```
{
  "id": "...",
  "security_policy": {  // Either custom or group policy
    "scanners": ["compliance", "sast", "securitron"],
    ...
  },
  "access_token": "...",
  ...
}
```

***

### ✅ Benefits

| Benefit          | Description                                                       |
| ---------------- | ----------------------------------------------------------------- |
| **Flexibility**  | Different policies for different projects/scenarios               |
| **Consistency**  | Rescans preserve original configurations                          |
| **Control**      | Fine-grained security policy management                           |
| **Efficiency**   | No need to modify group policies temporarily                      |
| **Transparency** | Custom policies visible in scan metadata                          |
| **Security**     | Plan-based enforcement ensures compliance with subscription tiers |

***

### 🔧 Migration Notes

* **Backward Compatible**: Existing scans without custom policies continue using group policies
* **No Breaking Changes**: All existing API contracts maintained
* **Optional Feature**: Custom policies are opt-in; default behavior unchanged

***

### 📝 Files Modified

#### Backend

* `app/handlers/scan.go` - Scan creation with custom policy support
* `app/handlers/scan_handler.go` - Pending scans with policy prioritization
* `app/datastores/projects.go` - Project scans with custom policy in response

#### Frontend

* `scan-security-policy-modal.tsx` - **New** custom policy editor modal
* `new-scan-modal.tsx` - Custom policy integration for new scans
* `projects-component.tsx` - Rescan with preserved custom policies

***

### 🚀 Future Enhancements

* Policy templates library
* Policy versioning and history
* Audit logging for policy changes
* Policy validation rules engine

***

**Release Date:** 2026-02-09\
**Status:** ✅ Production Ready


# Comparison

AquilaX vs other AppSec Product in the market

We conduct a fair assessment of other products in the market to give our current and new customers an unbiased view of various services in AppSec and DevSecOps space.

{% content-ref url="/pages/cKoUa4p8dRbHKWHhPFoo" %}
[Black Duck vs AquilaX](/user-manual/comparison/black-duck-vs-aquilax)
{% endcontent-ref %}

{% content-ref url="/pages/slZP3m0E1qsa3SOQGEJH" %}
[ArmorCode vs AquilaX](/user-manual/comparison/armorcode-vs-aquilax)
{% endcontent-ref %}

{% hint style="info" %}
All information on the subpages is based on our fair analysis but may not be exhaustive or cross-verified. Please seek independent advice or conduct your own research if necessary.
{% endhint %}


# ArmorCode vs AquilaX

Differences and similarities between ArmorCode and AquilaX

[ArmorCode](https://www.armorcode.com/) and AquilaX both operate in the Application Security space, but they differ significantly in their services and products. ArmorCode's primary objective is to provide a comprehensive integration platform for third-party scanners, consolidating their outputs into a single solution. It is fair to say that ArmorCode does not use scanners directly, but relies on third-party tools. In contrast, AquilaX offers a seamless blend of proprietary and third-party scanners within a unified solution, eliminating the need for integration and management of third-party components.

Additionally, AquilaX develops portions of its scanners and employs AI to optimize triaging, minimizing noise and significantly reducing integration costs. On the other hand, ArmorCode focuses on offering robust vulnerability management solutions.

Contact AquilaX Engineering team to run a full comparison [https://aquilax.a](https://aquilax.ai/)i in your code base

{% hint style="info" %}
This analysis and report were prepared by an AquilaX employee based on publicly available information. It does not include extensive research and is intended as a preliminary comparison; we recommend conducting your own detailed assessment for more accurate insights.
{% endhint %}


# Black Duck vs AquilaX

Differences and similarities between BlackDuck and AquilaX

Black Duck and AquilaX are both companies specializing in application security, but they differ in their approaches and offerings.

**Black Duck** provides a comprehensive suite of application security solutions, including:

* **Software Composition Analysis (SCA):** Helps teams manage security, quality, and license compliance risks from open source and third-party code in applications and containers.

  [Black Duck](https://www.blackduck.com/software-composition-analysis-tools/black-duck-sca.html)
* **Static Application Security Testing (SAST):** Detects software defects and vulnerabilities in proprietary code.
* **Dynamic Application Security Testing (DAST):** Identifies vulnerabilities in running applications.
* **Interactive Application Security Testing (IAST):** Combines elements of SAST and DAST to detect vulnerabilities during runtime.
* **Fuzz Testing:** Uncovers defects and zero-day vulnerabilities in services and protocols.

Black Duck's solutions are designed to integrate into various stages of the software development lifecycle, providing visibility and control over the software supply chain.

**AquilaX**, on the other hand, focuses on leveraging artificial intelligence to enhance application security testing. Their offerings include:

* **AI-Powered Security Scanning:** Utilizes custom, lightweight AI models to virtually eliminate false positives, mimicking the logic and reasoning of an application security expert.

  [Aquilax](https://aquilax.ai/)
* **Comprehensive Security Solutions:** Provides a suite of security tools, including Static Application Security Testing (SAST), Software Composition Analysis (SCA), Container Scanning, Infrastructure Scanning, and API Security.

  [GitHub](https://github.com/AquilaX-AI)
* **Simplified Integration:** Offers easy integration without the need for extensive setup, allowing for quick identification of vulnerabilities and risks across code, third-party libraries, software, and infrastructure.

  [Aquilax](https://aquilax.ai/)

AquilaX's approach emphasizes reducing the learning curve for developers and streamlining the utilization of security scanners through AI-driven solutions.

In summary, while both Black Duck and AquilaX aim to secure software applications, Black Duck offers a broad range of traditional security testing tools integrated throughout the development process, whereas AquilaX focuses on AI-driven solutions to enhance accuracy and efficiency in security scanning.

<table><thead><tr><th>Product/Service</th><th data-type="checkbox">AquilaX</th><th data-type="checkbox">Black Duck</th></tr></thead><tbody><tr><td>SAST</td><td>true</td><td>true</td></tr><tr><td>SCA</td><td>true</td><td>true</td></tr><tr><td>DAST</td><td>true</td><td>true</td></tr><tr><td>IAST</td><td>false</td><td>true</td></tr><tr><td>MAST</td><td>false</td><td>true</td></tr><tr><td>ASPM</td><td>true</td><td>true</td></tr><tr><td>License Risks</td><td>true</td><td>true</td></tr><tr><td>Fix/Remediation Advice</td><td>true</td><td>true</td></tr><tr><td>False Positive Removal</td><td>true</td><td>false</td></tr><tr><td>CICD Integration</td><td>true</td><td>true</td></tr><tr><td>Freemium Offering</td><td>true</td><td>false</td></tr><tr><td>3rd Party Scanners</td><td>true</td><td>false</td></tr><tr><td>Software Supply Chain</td><td>true</td><td>true</td></tr></tbody></table>

{% hint style="info" %}
This analysis and report were prepared by an AquilaX employee based on publicly available information. It does not include extensive research and is intended as a preliminary comparison; we recommend conducting your own detailed assessment for more accurate insights.
{% endhint %}


# AquilaX vs other Vendors

AquilaX vs Traditional Security Vendors: The Future of DevSecOps

<figure><img src="/files/2vqx7v4Zo5GOKf1xqu0g" alt=""><figcaption><p>AquilaX vs Traditional Security Vendors: The Future of DevSecOps</p></figcaption></figure>

## AquilaX vs Other Security Vendors

| Feature                        | AquilaX AI                                            | Traditional Vendors (Snyk, Checkmarx, Veracode) |
| ------------------------------ | ----------------------------------------------------- | ----------------------------------------------- |
| **AI-Powered Security**        | ✅ Yes (Advanced AI for triaging)                      | ❌ Limited or rule-based detection               |
| **False Positive Filtering**   | ✅ AI-driven, near zero false positives                | ❌ High false positives requiring manual review  |
| **Scanning Speed**             | ✅ Under 60 seconds per scan                           | ❌ Slower, sometimes minutes to hours            |
| **Parallel Scanning**          | ✅ 9+ Scanners running simultaneously                  | ❌ Sequential scanning, increasing delays        |
| **Code Context Awareness**     | ✅ Deep understanding with contextual AI               | ❌ Basic static rule checks                      |
| **Multi-Layered Security**     | ✅ Covers SAST, SCA, IaC, API, Malware, Secrets        | ❌ Often limited to SAST & SCA                   |
| **Seamless CI/CD Integration** | ✅ Works with GitHub, GitLab, BitBucket                | ⚠️ Requires complex setup                       |
| **Deployment Options**         | ✅ SaaS, Single-Tenant, On-Prem                        | ⚠️ Mostly SaaS, limited on-prem options         |
| **Cost Efficiency**            | ✅ Fraction of an FTE                                  | ❌ Expensive per-seat pricing                    |
| **Automated Remediation**      | ✅ AI-suggested fixes with developer-friendly insights | ❌ Manual fixes required                         |
| **Transparency**               | ✅ Open-source & proprietary scanner support           | ❌ Proprietary & closed-source only              |

🚀 **AquilaX AI: Faster, Smarter, and More Cost-Effective DevSecOps!**


# AquilaX vs Checkmarx

AquilaX vs Checkmarx — Head-to-Head Findings & Product Quality

**Scope:** 8 independent codebases (referenced here as `project_case_1` … `project_case_8`). Each was scanned by both platforms; results below come directly from the scan exports.

{% hint style="warning" %}
This assessment was conducted in good faith as an internal, like-for-like benchmark across eight independent codebases. Every figure in it is drawn directly from the two platforms' own native scan exports — no findings were added, removed, or re-weighted. The tested codebases are anonymized throughout precisely to keep the focus on measurable output rather than on any specific customer or product.

The differences reported are factual and reproducible, not editorial. Coverage differences reflect the detection engines each platform actually ran during the tests (for example, infrastructure-as-code, secrets, container, PII, and compliance scanning were not present in the Checkmarx output). Triage status ("Unverified," "True Positive," "False Positive") is reported exactly as each platform labeled it in its own results. Where a finding was classified as a true or false positive, that classification is the tool's own — or, where AquilaX applied its verification layer, it is identified as such.

We recognize that scan results depend on configuration, scope, and product tier, and that a differently configured run could produce different numbers. For that reason we welcome Checkmarx, or any independent party, to reproduce the assessment against the same codebases under agreed conditions. If a re-run surfaces a configuration difference that materially changes any figure, we will update the assessment accordingly.

This document is a point-in-time engineering comparison, not a certification, endorsement, or statement about either company's overall capabilities. It reflects the specific scans performed on the specific code tested, on the dates tested.
{% endhint %}

***

### TL;DR

* **AquilaX runs 9 detection engines** (SAST, SCA, IAC, Secrets, Container, PII, Compliance, Securitron, AI/Vibe-Code). **Checkmarx runs 2** (SAST, SCA). Entire risk classes — infrastructure-as-code, hardcoded secrets, container, PII, compliance — are simply **invisible to Checkmarx** in these tests.
* **AquilaX ships triaged results. Checkmarx does not.** Across all 8 projects, **100% of Checkmarx findings came back as "Unverified"** (0 conformed, 0 urgent). Every one of Checkmarx's **4,838 raw findings** lands on a human to sort. AquilaX pre-classifies each finding as True Positive / False Positive.
* **AquilaX confirmed 5,475 true-positive findings** at **61% aggregate precision** after its own verification — versus a Checkmarx queue that is 0% triaged.
* **70.8% of AquilaX's scanner-attributed true positives (3,880 of 5,480) fall outside Checkmarx's scope entirely** — issues Checkmarx structurally could not find. In the reverse direction, a 10-item sample of Checkmarx findings on `project_case_1` were **all false positives (10/10)** — noise Checkmarx reported as valid.

***

### 1. Detection Coverage — Engines in Play

Checkmarx reports on two scanner types. AquilaX reports on up to nine, so it surfaces categories Checkmarx never looks at.

| Engine                    | AquilaX | Checkmarx |
| ------------------------- | :-----: | :-------: |
| SAST (static code)        |    ✅    |     ✅     |
| SCA (dependencies)        |    ✅    |     ✅     |
| IAC (infra-as-code)       |    ✅    |     ❌     |
| Secrets                   |    ✅    |     ❌     |
| Container                 |    ✅    |     ❌     |
| PII                       |    ✅    |     ❌     |
| Compliance                |    ✅    |     ❌     |
| Securitron (AI reasoning) |    ✅    |     ❌     |
| AI / Vibe-Code            |    ✅    |     ❌     |

**Why it matters:** in these 8 projects, IAC alone accounted for large volumes of confirmed true positives (e.g. **1,894 IAC true positives** in `project_case_3`, **872** in `project_case_4`). None of that class is in Checkmarx's field of view here.

***

### 2. Triage Quality — The Core Difference

This is the single most important metric in the dataset.

| Status                          |     AquilaX     | Checkmarx |
| ------------------------------- | :-------------: | :-------: |
| Findings pre-classified (TP/FP) | ✅ every finding |   ❌ none  |
| Findings left "Unverified"      |     minimal     |  **100%** |

Checkmarx status breakdown, **every project**: `Unverified = 100%`, `Conformed = 0`, `Urgent = 0`.

**Translation:** Checkmarx hands over a raw, unranked list. A security engineer must manually confirm or dismiss all **4,838** findings. AquilaX does that classification up front, so the team starts from a list that already separates real issues from noise.

***

### 3. Per-Project Numbers

#### AquilaX — confirmed findings & precision

"Precision" = True Positives ÷ (True Positives + False Positives), using AquilaX's own verification labels.

| Project          | True Positives | False Positives | Precision |
| ---------------- | -------------: | --------------: | --------: |
| project\_case\_1 |            386 |             897 |     30.1% |
| project\_case\_2 |            173 |             272 |     38.9% |
| project\_case\_3 |          2,507 |             245 | **91.1%** |
| project\_case\_4 |          1,314 |             841 |     61.0% |
| project\_case\_5 |            973 |           1,179 |     45.2% |
| project\_case\_6 |              5 |               0 |  **100%** |
| project\_case\_7 |              5 |               0 |  **100%** |
| project\_case\_8 |            112 |              71 |     61.2% |
| **Total**        |      **5,475** |       **3,505** | **61.0%** |

#### Checkmarx — raw findings, none triaged

| Project          | Raw findings | Verified |       Unverified |
| ---------------- | -----------: | -------: | ---------------: |
| project\_case\_1 |          124 |        0 |       124 (100%) |
| project\_case\_2 |          217 |        0 |       217 (100%) |
| project\_case\_3 |          240 |        0 |       240 (100%) |
| project\_case\_4 |        1,713 |        0 |     1,713 (100%) |
| project\_case\_5 |          448 |        0 |       448 (100%) |
| project\_case\_6 |          486 |        0 |       486 (100%) |
| project\_case\_7 |          320 |        0 |       320 (100%) |
| project\_case\_8 |        1,290 |        0 |     1,290 (100%) |
| **Total**        |    **4,838** |    **0** | **4,838 (100%)** |

**Read the two tables together:** AquilaX delivers 5,475 *confirmed* issues with each finding already labeled. Checkmarx delivers 4,838 issues with *zero* labeled — the triage cost is entirely downstream on the customer.

***

### 4. Severity Distribution (AquilaX confirmed true positives)

Where a finding was confirmed, this is how it broke down by severity. Shows AquilaX isn't just producing volume — it's flagging genuine High/Critical exposure.

<table><thead><tr><th width="148.90234375">Project</th><th align="right">Critical</th><th align="right">High</th><th align="right">Medium</th><th align="right">Low</th><th align="right">Info</th></tr></thead><tbody><tr><td>project_case_1</td><td align="right">0</td><td align="right">76</td><td align="right">204</td><td align="right">88</td><td align="right">19</td></tr><tr><td>project_case_2</td><td align="right">0</td><td align="right">49</td><td align="right">85</td><td align="right">34</td><td align="right">7</td></tr><tr><td>project_case_3</td><td align="right">15</td><td align="right">203</td><td align="right">1,793</td><td align="right">469</td><td align="right">27</td></tr><tr><td>project_case_4</td><td align="right">5</td><td align="right">119</td><td align="right">929</td><td align="right">251</td><td align="right">12</td></tr><tr><td>project_case_5</td><td align="right">2</td><td align="right">128</td><td align="right">611</td><td align="right">216</td><td align="right">16</td></tr><tr><td>project_case_8</td><td align="right">0</td><td align="right">26</td><td align="right">45</td><td align="right">33</td><td align="right">8</td></tr></tbody></table>

***

### 5. Concrete Cases — Both Directions

#### 5a. Cases where AquilaX found the vulnerability and Checkmarx did NOT

Checkmarx ran only two engines (SAST + SCA). Every AquilaX-confirmed true positive from any other engine is a finding Checkmarx **structurally could not detect**. That is not a handful of edge cases — it is the majority of confirmed risk:

* **3,880 confirmed true positives** sit in engine classes Checkmarx never runs.
* That is **70.8% of all AquilaX scanner-attributed true positives** (3,880 of 5,480).
* It is **0.80× the size of Checkmarx's entire output** across all 8 projects (3,880 vs 4,838 raw findings) — an invisible risk surface nearly as large as everything Checkmarx reported in total.

**Aggregate — confirmed true positives Checkmarx missed, by engine:**

| Engine (not run by Checkmarx) | Confirmed TPs missed by Checkmarx | Share of missed |
| ----------------------------- | --------------------------------: | --------------: |
| IAC (infrastructure-as-code)  |                             3,550 |           91.5% |
| Securitron (AI reasoning)     |                               205 |            5.3% |
| Secrets                       |                                85 |            2.2% |
| Compliance                    |                                29 |            0.7% |
| AI / Vibe-Code                |                                 8 |            0.2% |
| Container                     |                                 2 |            0.1% |
| PII                           |                                 1 |            0.0% |
| **Total**                     |                         **3,880** |        **100%** |

**Per-project — confirmed findings Checkmarx couldn't see:**

| Project          | Missed TPs | Breakdown                                                                   |
| ---------------- | ---------: | --------------------------------------------------------------------------- |
| project\_case\_1 |        198 | IAC 156, Securitron 40, Compliance 1, Vibe-Code 1                           |
| project\_case\_2 |         65 | IAC 39, Securitron 21, Compliance 4, Vibe-Code 1                            |
| project\_case\_3 |      2,000 | IAC 1,894, Securitron 58, Secrets 43, Compliance 3, PII 1, Vibe-Code 1      |
| project\_case\_4 |        929 | IAC 872, Secrets 23, Securitron 20, Compliance 12, Container 1, Vibe-Code 1 |
| project\_case\_5 |        566 | IAC 503, Securitron 43, Secrets 17, Container 1, Compliance 1, Vibe-Code 1  |
| project\_case\_6 |          5 | Securitron 2, Compliance 2, Vibe-Code 1                                     |
| project\_case\_7 |          5 | Securitron 2, Compliance 2, Vibe-Code 1                                     |
| project\_case\_8 |        112 | IAC 86, Securitron 19, Compliance 4, Secrets 2, Vibe-Code 1                 |

**Sharpest single case — project\_case\_3:** AquilaX confirmed **2,000 true positives** in classes Checkmarx doesn't scan (1,894 IAC + 58 Securitron + 43 secrets + 3 compliance + 1 PII + 1 AI). Checkmarx's total output on the same codebase was **240 findings** — meaning AquilaX surfaced **8.3× more confirmed risk from categories Checkmarx cannot see** than Checkmarx reported in total.

#### 5b. Cases where AquilaX flagged it as a FALSE POSITIVE but Checkmarx reported it as VALID

On `project_case_1`, a 10-finding sample was pulled from Checkmarx's 124 reported vulnerabilities and reviewed. **All 10 (100% of the sample) were false positives** — findings Checkmarx reported as valid that are not real vulnerabilities. Checkmarx left every one "Unverified," pushing the disproof work onto the customer.

**Sample false-positive rate: 10 / 10 (100%).** By vulnerability class:

| Checkmarx "vulnerability" class | Count in sample | Why it's a false positive                                                          |
| ------------------------------- | --------------: | ---------------------------------------------------------------------------------- |
| Broken Hashing (MD5)            |               2 | MD5 used for non-security purposes (element IDs, cache keys), not password storage |
| Missing HSTS Header             |               1 | Raised on error responses, which don't require HSTS                                |
| HttpOnly Cookie Flag Not Set    |               1 | Flagged a cookie READ path, not a SET path                                         |
| Weak PRNG                       |               1 | Randomness used for UI uniqueness, not cryptographic security                      |
| Unchecked Loop Condition        |               1 | Loop bound is internal completion, not a user-controlled count                     |
| DOM Open Redirect               |               1 | Redirect target is a system-generated link, not user input                         |
| Unsafe Reflection               |               1 | Call goes through a whitelist-validated framework mechanism                        |
| CSRF                            |               1 | Raised on test-framework/debug code, not a production path                         |
| Prototype Pollution             |               1 | Legacy polyfill parsing its own parameters, not external data                      |
| **Total**                       |          **10** | **0 real vulnerabilities**                                                         |

**The number that matters:** in this sample, **100% of Checkmarx's "valid" findings were noise**, and every one was shipped unverified. Extrapolated across its 4,838 raw findings, the untriaged false-positive burden is the customer's to absorb. AquilaX's verification layer is what removes this class before it reaches the report.

***

### 6. Bottom Line

| Dimension                               | AquilaX                                                 | Checkmarx                          |
| --------------------------------------- | ------------------------------------------------------- | ---------------------------------- |
| Detection engines                       | 9                                                       | 2                                  |
| Risk classes covered                    | SAST, SCA, IAC, Secrets, Container, PII, Compliance, AI | SAST, SCA only                     |
| Findings pre-triaged                    | Yes — every finding labeled TP/FP                       | No — 100% unverified               |
| Confirmed true positives (8 projects)   | 5,475                                                   | not distinguished                  |
| Aggregate precision (post-verification) | 61.0%                                                   | n/a (untriaged)                    |
| Human triage burden handed to customer  | Low                                                     | 4,838 raw findings, 0 sorted       |
| Context-aware validation                | Yes (see §5b)                                           | No — false positives shipped as-is |

**The value in one line:** AquilaX covers more of the attack surface, verifies its own findings before you see them, and demonstrably catches real issues Checkmarx misses while filtering out noise Checkmarx ships raw. Checkmarx's output in these 8 tests is narrower in coverage and 100% unverified — the actual work of separating signal from noise is left entirely to your team.

***

*All figures taken directly from the scan-export workbook (8 project sheets). True-positive / false-positive labels are as recorded in each platform's own output. Product names of the tested codebases have been anonymized to `project_case_1`–`project_case_8`.*

*Note on totals: the status-based confirmed-TP total is 5,475 (from each project's TP/FP/Unverified breakdown); the scanner-attributed TP total is 5,480 (from each project's per-engine breakdown). The 5-count difference is a rounding/attribution artifact in the source workbook, not a computed error. Coverage percentages in §5a use the scanner-attributed basis (3,880 of 5,480 = 70.8%) because the miss is defined per engine.*


# Press and Logo

AquilaX logo and brand assets

Different logo variations for AquilaX, designed and copyrighted by AquilaX LTD, are available for use. Must be used to attribute and link back to the AquilaX website when using these logos in relation to our services or content: <https://aquilax.ai>\\

### Color Palette

<table data-card-size="large" data-view="cards"><thead><tr><th></th><th></th><th></th></tr></thead><tbody><tr><td><p><code>Dark Midnight Blue (Main)</code></p><p><code>HEX #003460</code></p><p><code>RGB 0, 52, 96</code></p><p><code>CMYK 100, 84, 36, 27</code></p></td><td></td><td></td></tr><tr><td><p><code>Ocean Boat Blue (Secondary)</code></p><p><code>HEX #0076c2</code></p><p><code>RGB 0, 118, 194</code></p><p><code>CMYK 86, 49, 0, 0</code></p></td><td></td><td></td></tr></tbody></table>

***

### Logo

<figure><img src="/files/XjbJLwn4K8mfSqmkJ9Hb" alt="" width="96"><figcaption><p>Logo Mini (ICON)</p></figcaption></figure>

<figure><img src="/files/saz2RvZHVT1XpybCfQuf" alt="" width="188"><figcaption><p>Full Logo Vertical</p></figcaption></figure>

<figure><img src="/files/GXhffZwm2UNOGV66ZAfb" alt="" width="375"><figcaption><p>Full Logo horizontal</p></figcaption></figure>

<figure><img src="/files/4OPl0qJZNL1ZtXkaLqMN" alt="" width="375"><figcaption><p>AquilaX AI</p></figcaption></figure>

<figure><img src="/files/l4U5VN4N2mLU38WPSdgB" alt="" width="179"><figcaption><p>Symbol Only</p></figcaption></figure>

<figure><img src="/files/5epEw0LCbR5OTinb0sJG" alt="" width="375"><figcaption><p>Text Only</p></figcaption></figure>


# Install AquilaX

How to prepare and install AquilaX On-Prem / Cloud or your VM

The **AquilaX** solution consists of 4 key components, each responsible for specific tasks. These components work together to deliver comprehensive security scanning and intelligence.

1. **AquilaX Server**: Manages the API and User Interface (UI) of the service, acting as the central control point for all operations.
2. **AquilaX Worker**: Responsible for executing the actual security scans, performing the analysis and reporting vulnerabilities back to the AquilaX Server.
3. **AquilaX AI** : Specialized AI-powered models designed to assist with decision-making and emulate human logic in engineering tasks. These models enhance the solution’s ability to reason, automate processes, and build intelligent responses.
4. **On-Prem AI Models**: These are not developed by AquilaX itself, but are open source models that are light and small to be used in CPU and GPU with limited resources, however are tuned by AquilaX to perform better within the AppSec use cases.

Below is a diagram illustrating the relationship between these components. Following the diagram, you’ll find instructions on how to set up the solution in a dedicated environment.

<img src="/files/MtvLmQADutytWIH5NDg4" alt="" class="gitbook-drawing">

## Prerequisite

1. To prepare for the installation of various AquilaX components, you can structure the deployment using a dedicated Virtual Machines. However depending of the demand of usage, the solution can be scaled to more machines to offload the compute needs
2. Install on all of them `Docker` and `Docker Compose`: [Install Docker and docker compose](/user-manual/install-aquilax/install-docker-and-docker-compose)
3. To have the application up and running you will need 3 secret keys from AquilaX Team
   1. **Deployment Key** to access the container images
   2. **Running Key** for the Application to run in your environment
   3. **License Key** to able to have the full functionalities (ultimate or premium version)

The required dedicated VMs must have at least the below capacities to be able to work correctly

<table><thead><tr><th width="140.359375">VM</th><th>CPU/GPU (min)</th><th width="123.40234375">RAM (min)</th><th>Storage</th><th>Network</th></tr></thead><tbody><tr><td>AquilaX Server</td><td>32 vCPU</td><td>48 GB</td><td>240 GB SSD</td><td>SSH / HTTPs</td></tr></tbody></table>

## Setup AquilaX Server

Sign in to the Server VM and run the command below. It sets up the environment with the initial folders, files, and so on. You can review the code that gets downloaded and executed here: <https://gitlab.com/aquila-x/install-on-prem>

The command will prompt you for a **RUNNING KEY**, **SMTP settings**, and other configuration. AquilaX will provide the Running Key. SMTP is required for sign-in (magic link)

```bash
curl -fsSL https://gitlab.com/aquila-x/install-on-prem/-/raw/main/setup.sh | bash
```

### Start the service

When you have the setup done done, request a **deployment key** from AquilaX and execute the below commands

```bash
docker login registry.gitlab.com
docker compose pull
docker compose up -d
```

### Go

Now you can signing into the service just by navigating at `https://<your own ip>`

<figure><img src="/files/ubjpiOqUAUvHz4G9iLvJ" alt=""><figcaption><p>Landing Page AquilaX On-Prem</p></figcaption></figure>

### License Application

Once you are inside the application, create a personal access token, you will need this for the worker. In addition go into the settings of your new organization and apply a license key, the license key will be provided to you by the the AquilaX team.

<figure><img src="/files/bPUGmFTIFpWfigBR5LBj" alt="" width="375"><figcaption></figcaption></figure>

{% hint style="warning" %}
AI Models within pure CPU environment maybe slow!
{% endhint %}

{% hint style="info" %}
Contact a member of AquilaX if you need help for the installation or configuration. Is strongly suggested to do the installation of the environment together with AquilaX Engineering team. Please contact us at. <https://aquilax.ai/contact>
{% endhint %}


# Install Docker and docker compose

#### Install Docker and docker compose

You can use this script and follow your own way to install docker and docker compose in your environment

```bash
# Add Docker's official GPG key:
sudo apt-get update
sudo apt-get install ca-certificates curl
sudo install -m 0755 -d /etc/apt/keyrings
sudo curl -fsSL https://download.docker.com/linux/ubuntu/gpg -o /etc/apt/keyrings/docker.asc
sudo chmod a+r /etc/apt/keyrings/docker.asc

# Add the repository to Apt sources:
echo \
  "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.asc] https://download.docker.com/linux/ubuntu \
  $(. /etc/os-release && echo "$VERSION_CODENAME") stable" | \
  sudo tee /etc/apt/sources.list.d/docker.list > /dev/null
sudo apt-get update
sudo apt-get install -y docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin
sudo usermod -aG docker $USER
```

#### Test

Before you test, logout and login again and run the this command

```bash
docker run hello-world
```


# Public Scan

Scan your open source code for free

{% hint style="warning" %}
By using this functionality, you confirm that you have the necessary permissions to scan the repository. Findings must only be used for legitimate purposes and not for any malicious intent.
{% endhint %}

You can easily scan any open-source code on GitHub or GitLab for vulnerabilities—completely free of charge, with no authentication or credit card required. The process is simple and straightforward:

1\. Visit [AquilaX App](https://app.aquilax.ai/).

2\. Paste the URL of any public Git repository.

3\. Click Scan to start the analysis.

Alternatively, you can use the built-in web shell (a pseudo-shell) by running the following command:

```bash
aquila scan https://github.com/AquilaX-AI/vulnapp-python
```

## Demo

<figure><img src="/files/TBPd6Oc3a96fCTMRoccQ" alt=""><figcaption></figcaption></figure>

## Limitations

This functionality is designed to quickly showcase value rather than serve as a comprehensive solution. As such, there are a few limitations:

1\. Each user can initiate up to 10 scans per day.

2\. Scans are automatically deleted from our system after 24 hours.

## APIs

{% content-ref url="<https://github.com/AquilaX-AI/docs/blob/main/user-manual/broken-reference/README.md>" %}
<https://github.com/AquilaX-AI/docs/blob/main/user-manual/broken-reference/README.md>
{% endcontent-ref %}


# Scanning Setup Guide

Setting Up AquilaX Scanning and Groups: A Guide

Organizations often have multiple repositories distributed across platforms like GitHub and GitLab. While some repositories have CI/CD pipelines enabled, others do not. To ensure comprehensive scanning across all repositories—both on event-based triggers and periodically—it’s essential to establish a well-structured setup. This practice is commonly referred to as Application Security Hygiene and is often a mandatory requirement for maintaining software security compliance.\\

Here’s how to set up your AquilaX environment for optimal scanning and group management:

## Step-by-Step Guide

### 1. Organize Your Groups

Log in to the AquilaX portal. Create or modify your groups to maintain a simple structure. For most cases, having **a single group**—let’s call it “*Default Group*”—is sufficient. This centralizes management and simplifies your setup.

### 2. Clean Up Existing Projects

If there are pre-existing projects in the group, **delete them to start fresh**. A clean setup ensures consistency and avoids misconfigurations.

### 3. Configure the Security Policy

Set up a **Security Policy JSON for your group**. This policy defines the scanning rules and parameters to ensure uniform application across all repositories.

<pre class="language-json"><code class="lang-json">{
  "<a data-footnote-ref href="#user-content-fn-1">frequency</a>": "weekly",
  "<a data-footnote-ref href="#user-content-fn-2">avatar</a>": "https://avatars.githubusercontent.com/u/155273638?s=200&#x26;v=4",
  "description": "Example Policy for production purposes",
  "author": "&#x3C;Your team name here>",
  "<a data-footnote-ref href="#user-content-fn-3">ignore</a>": [
    "test/*",
    "tests/*",
    "node_modules/*",
    "semgrep-rules/**",
    "yara_rules/**",
    "configs/**"
  ],
  "<a data-footnote-ref href="#user-content-fn-4">jira_project_key</a>": "SCRUM",
  "notify_on_failure": true,
  "<a data-footnote-ref href="#user-content-fn-5">raise_tickets</a>": true,
  "<a data-footnote-ref href="#user-content-fn-6">ticket_body</a>": "Was found this {{vuln}} on this file {{file}}",
  "<a data-footnote-ref href="#user-content-fn-7">ticket_integration</a>": "GitHub, GitLab, Jira",
  "<a data-footnote-ref href="#user-content-fn-8">ticket_title</a>": "AquilaX - {{vuln}}",
  "<a data-footnote-ref href="#user-content-fn-9">repos</a>": [
        "https://github.com/aquilax-ai"
  ],
  "<a data-footnote-ref href="#user-content-fn-10">scanners</a>": [
    {
      "compliance": true,
      "enforced": true
    },
    {
      "enforced": true,
      "secret": true
    },
    {
      "enforced": true,
      "pii": true
    },
    {
      "enforced": true,
      "sast": true
    },
    {
      "enforced": true,
      "sca": true,
      "licenses": {
                "mixed_licenses": true,
                "prohibited": [
                  "GPL*",
                  "BSD"
                ]
      },
    },
    {
      "container": true,
      "enforced": true
    },
    {
      "enforced": true,
      "iac": true
    },
    {
      "api": true,
      "enforced": true
    },
    {
      "enforced": true,
      "malware": true
    }
  ],
  "<a data-footnote-ref href="#user-content-fn-11">tags</a>": [
    "all-scanners",
    "prod"
  ],
  "testing": false,
  "<a data-footnote-ref href="#user-content-fn-12">threshold</a>": {
    "HIGH": 50,
    "LOW": 99999,
    "MEDIUM": 1000,
    "total": 300
  }
}
</code></pre>

### 4. Enable CI/CD Integration

• For each repository in GitHub or GitLab:

• Integrate AquilaX scanning into the **CI/CD pipeline to automatically scan** code with every software change. <https://docs.aquilax.ai/user-manual/devtools/ci-cd>

• This ensures that vulnerabilities are identified and addressed in real-time during development.

### 5. Schedule Monthly Full Scans

Regardless of CI/CD-triggered scans, initiate a **full scan of all repositories weekly**. This practice captures any vulnerabilities that might be missed in incremental scans.

### 6. Review Findings with AquilaX

Engage AquilaX’s team to review findings classified as “Unverified”, This step **reduces noise by identifying false positives**. It also helps train your custom AI model, improving accuracy over time. (Note: This feature is available with the Ultimate License.)

### 7. Monitor Reports

Access the **report page** to review detailed findings or wait for the automated **weekly report over email** for a summary of security insights.

### 8. Create a Testing Group (Optional)

If needed, set up a **separate group for testing or development purposes**. This serves as a sandbox environment for experimentation without impacting production scans.

[^1]: Ensure all projects are scanned at least every week

[^2]: Link to a public accessible Avatar (optional)

[^3]: Folders to be ignored during scanning

[^4]: JIRA name (Optional)

[^5]: Ability to raise tickets for security issues

[^6]: Ticket Body (optional)

[^7]: Ticketing systems enabled (Optional)

[^8]: Ticket Title (Optional)

[^9]: List of repos subject to this group, can be a single repo or group repos from github and/or gitlab

[^10]: List of scanners enabled

[^11]: Tags associated with the scan (Optional)

[^12]: Threshold used before the CICD block the pipeline for vulnerabilites


# AI Chat Prompts

How to interact with AquilaX ChatBot

A list of potential commands/chat prompt to interact with AquilaX (Securitron). Of course, you don't need to folow the below, as it's just some example, but is good as a starting point

| Prompt                                                 | Expected output                                                                | AI Model                 |
| ------------------------------------------------------ | ------------------------------------------------------------------------------ | ------------------------ |
| Hey                                                    | Greating message from AquilaX                                                  | Security Engineer (QNA)  |
| Give me a summary report                               | Create an executive report of all vulnerabilities of your organization         | Security Engineer (TAGS) |
| Start a scan                                           | A link to initiate a new scan                                                  | Security Engineer (TAGS) |
| Who am I?                                              | Will tell you who you are                                                      | Security Engineer (TAGS) |
| show all members of the organization                   | Will print out all users having access to your selected / current organization | Security Engineer (TAGS) |
| Give me the security tasks for the entire organization | Will print the list of actions you should pay attention                        | Security Engineer (TAGS) |
| Groups                                                 | will list all the groups belonging to the current organization                 | Security Engineer (TAGS) |
| What is XSS?                                           | Will explain what is XSS                                                       | Security Engineer (QNA)  |

\\


# Connect AquilaX with Git


# GitLab Connection

Connecting AquilaX to Your Private GitLab Repositories

To enable AquilaX to scan private GitLab repositories, you must grant the platform access to your GitLab account or self-hosted instance.

### Steps

1. **Log in** to your AquilaX account: <https://aquilax.ai>
2. **Go to your Organizations** page: <https://aquilax.ai/app/dashboard/pages/organizations/>
3. **Find the organization** you want to connect and click the **three-dot menu** next to it, then select **Manage**
4. On the **Configuration** page, scroll to the **Integrations** section
5. Under **GitLab**, click **+ Connect**
6. In the dialog that appears:
   * Enter your **GitLab instance URL** (either a public `gitlab.com` account or a private/self-hosted GitLab instance)
   * Enter your **GitLab Access Token** with the necessary permissions for repository access (the access granted must be at least `read_api` and `read_repository`, alternative you can select only `api`)\
     \\

     <figure><img src="/files/m2u8XtYvCMT3XDYM7Vr3" alt="" width="375"><figcaption></figcaption></figure>
7. Click **Next** and select the **GitLab groups** you want to grant access to

<figure><img src="/files/H3jOuqVHMr3rSC8UOMla" alt="" width="375"><figcaption></figcaption></figure>

Once connected, **refresh the page** to confirm the integration status and verify that AquilaX has access. You can now scan any repository from the connected groups\
\\

**Notes**

* If you have already connected your GitLab account, you can click View Details in the Integrations section to:

  • Update the connection details to refresh connection and list of repos

  • Delete the integration and start over
* Only Organization Owners can perform these operations


# GitHub Connection

Connecting AquilaX to Your Private GitHub Repositories

To enable AquilaX to scan your GitHub repositories, you must grant the platform access to your GitHub account or organization. This integration uses GitHub's official OAuth app flow, giving you granular control over which repositories are shared.

#### Steps

1. **Log in** to your AquilaX account: <https://aquilax.ai>
2. **Go to your Organizations** page: <https://aquilax.ai/app/dashboard/pages/organizations/>
3. **Find the organization** you want to connect and click the **three-dot menu** next to it, then select **Manage**
4. On the **Configuration** page, scroll to the **Repositories & git Integrations** section
5. Under **GitHub**, click **+ Connect**<br>

   <figure><img src="/files/Rd2o1H4zm72SAiB1ZQhA" alt="" width="563"><figcaption></figcaption></figure>
6. You will be redirected to GitHub to install and authorize the **AquilaX AI Security** app. Select the account to install on, then choose which repositories to grant access to:

   * **All repositories** - applies to all current and future repositories owned by the account, including public repositories (read-only)
   * **Only select repositories** - choose specific repositories; also includes public repositories (read-only)<br>

   <figure><img src="/files/eCXAVtUZfaAXErsTK2VJ" alt="" width="375"><figcaption></figcaption></figure>

{% hint style="info" %}
**Permissions requested:** AquilaX requests **Read** access to code and metadata only. No write access is ever requested.
{% endhint %}

7. Click **Install & Authorize**. You will be redirected back to AquilaX at `https://aquilax.ai/app/github/webhook`
8. A confirmation screen will appear indicating the **GitHub Integration** was successful<br>

   <figure><img src="/files/h9uBnXDJ0BvEWlA639FW" alt="" width="316"><figcaption></figcaption></figure>
9. **Refresh the page** to confirm the integration status. The GitHub row will now show **✓ Connected** along with the number of repositories integrated and the date

<p align="center"><img src="/files/hJzCP1hjsxv5J2Kv9pR0" alt=""><br><br></p>

You can now scan any repository from your connected GitHub account or organization.

***

**Notes**

* If you have already connected your GitHub account, you can click **View Details** in the Integrations section to:
  * Update the connection to refresh the integration and repository list
  * Delete the integration and start over
* Only **Organization Owners** can connect or manage git integrations
* If you selected **Only select repositories** during setup and want to add more later, go to your GitHub account under **Settings → Integrations → GitHub Apps** and update the AquilaX app permissions


# API Docs

API Documentation

Welcome to the API documentation for our new platform! Here, you'll find comprehensive guides and documentation to help you start working with our APIs as quickly as possible. Explore the detailed [API reference](https://developers.aquilax.ai/api-reference/start) to understand how to integrate and leverage our services efficiently.

{% hint style="success" %}
API Doc Portal: <https://developers.aquilax.ai/api-reference/start>
{% endhint %}


# Tech Articles


# Proprietary AI Models

ML and AI Models of AquilaX

## AquilaX: Advancing AI for Engineers and Developers

At AquilaX, we are committed to developing and continually training a series of AI models designed to better serve the engineering and developer communities using our service. Our multidisciplinary team of AI researchers, data scientists, and software engineers work collaboratively to ensure our models are both efficient and effective.

### **Core Principles for Optimal User Experience**

To achieve the best user experience, we adhere to the following principles:

1. **Efficient and Compatible Models**
   * **Performance Optimization:** We focus on building AI models that are not only fast but also optimized for CPU compatibility wherever possible. This approach ensures that our solutions are accessible and efficient across various hardware configurations, reducing latency and enhancing real-time performance.
2. **Targeted Training Data**
   * **Specific Data Utilization:** Our models are trained on a combination of proprietary and open-source data, meticulously selected to meet our specific needs. By targeting our training data, we can fine-tune our models to address the unique challenges and requirements of the engineering and developer communities, leading to more accurate and relevant outputs.

## **Team and Collaboration**

Our team at AquilaX is a diverse group of professionals dedicated to pushing the boundaries of AI. This includes:

* **AI Researchers:** Innovating new algorithms and refining existing ones to enhance model performance.
* **Data Scientists:** Curating and processing large datasets to train our models, ensuring they are robust and well-generalized.
* **Software Engineers:** Integrating AI models into our platform, optimizing for performance, and ensuring seamless user experience.
* **Quality Assurance Specialists:** Rigorous testing of models to ensure reliability and accuracy.

Together, these efforts enable us to deliver high-quality, responsive AI solutions that significantly improve the workflows of engineers and developers. By staying committed to these principles, AquilaX aims to set the standard for AI-driven tools in the tech industry.

## AquilaX AI Models

<table data-view="cards"><thead><tr><th></th><th></th><th></th></tr></thead><tbody><tr><td><code>Securitron: Summary</code></td><td>json-to-text</td><td></td></tr><tr><td><code>Securitron: Query</code></td><td>text-to-JSON</td><td></td></tr><tr><td><code>Securitron: Command</code></td><td>text-to-JSON</td><td></td></tr><tr><td><code>Securitron: Ask</code></td><td>text-to-text</td><td></td></tr><tr><td><code>Securitron: Code</code></td><td>text-to-code</td><td></td></tr><tr><td><code>Securitron: Assistant</code></td><td>text-to-text</td><td></td></tr></tbody></table>

<img src="/files/8ncAsjq2jyOS1SvH6mCP" alt="" class="gitbook-drawing">

{% tabs %}
{% tab title="Summary" %}
This model is trained on a comprehensive dataset of cybersecurity reports focused on application security. It can analyze the findings from these reports and generate a summary that explains the identified vulnerabilities and the assurance level of the scan. The summary can be presented in simple English for general understanding or in more technical language for expert use.\
\
**Input**: JSON (structured findings and metadata)\
**Output**: Text (Report summary)
{% endtab %}

{% tab title="Query" %}
This model is one of the first developed by AquilaX, designed to provide users with a natural language interface for interacting with the AquilaX system. Users can ask straightforward questions, such as "How many vulnerabilities do I have?" and receive structured responses in JSON format. Additionally, the model can generate graphs and charts to visualize the data effectively.\
\
**Input**: Text (English questions - NL)\
**Output**: JSON (Answers in JSON format)
{% endtab %}

{% tab title="Command" %}
The Command Model is responsible for interpreting natural language text and executing the desired actions on the platform. For example, if a user says, "Please scan this repo for secrets," the model accurately understands the command and performs the action on behalf of the user.\
\
**Input**: Text (English questions - NL)\
**Output**: JSON (Operation execution output )
{% endtab %}

{% tab title="Ask" %}
\<coming soon>
{% endtab %}

{% tab title="Code" %}
\<coming soon>
{% endtab %}

{% tab title="Assistant" %}
\<coming soon>
{% endtab %}
{% endtabs %}


# AquilaX Securitron

AquilaX's flagship AI Model

<img src="/files/OaZQ5RNPfqDfel5XeKCZ" alt="AquilaX Securitron Training Loop" class="gitbook-drawing">

AquilaX powers across two core domains:

1. **All in one scanner**: Utilizing eight security scanners for code base assessment.
2. **AI Engine Securitron**: A highly trained model specialized in application security (AppSec).

Securitron has been trained on over 300 million open-source projects, learning from their source code and identified security vulnerabilities. It has also been meticulously trained on the triaging work performed by leading cybersecurity engineers. As a result, Securitron is the first AI engine on the market extensively trained on billions of data points, enabling it to reason like a human security expert.

This dataset includes:

1. Source Code snippets
2. Identified vulnerabilities
3. Triage results from top security engineers
4. Tags categorizing findings as:
   * False Positive
   * False Negative
   * True Positive
   * True Negative
   * Undefined

This dataset is pivotal in training our **Securitron** model. Securitron plays a crucial role in assessing new vulnerabilities, distinguishing between False and True Positives, offering an unparalleled contextual understanding.

Moreover, Securitron features a Chat component serving as both API and UI. This allows AquilaX users to interact, gain insights into vulnerabilities, understand why certain findings are True Positives, and learn effective mitigation strategies.

Continuous training of Securitron ensures it evolves with each new triage performed by our security engineers, facilitating ongoing improvements in our system.


# Securitron AI Service

Functionalities of AquilaX's AI Engine

<figure><img src="/files/ZU93878KFdGLebkJvxCO" alt=""><figcaption><p>Functionalities of AquilaX's AI Engine</p></figcaption></figure>

Securitron, our flagship AI engine, serves as the core interface of our service.

Key capabilities of Securitron include:

1. Raising pull requests (or merge requests) directly to the codebase to address identified security issues.
2. Accepting requests and commands from developers to perform scans or answer any software security questions.
3. Providing metrics and risk information to C-level managers, either in plain English or through detailed reports.


# Secure SDLC (DevSecOps)

Secure your application via SDLC

DevSecOps encompasses automated security controls integrated within a DevOps pipeline to enhance the security posture of software builds and deployments. In contrast, Secure Software Development Lifecycle (Secure SDLC) is a broader framework that extends beyond DevOps, encompassing practices such as Threat Modeling, Design Review, and security training initiatives.

<img src="/files/3rUQUgH0kgSHCQjraui4" alt="" class="gitbook-drawing">

AquilaX primarily focuses on code scanning practices, positioning itself within the realm of DevSecOps while not exclusively confined to it. Examples of AquilaX usage scenarios include:

1. Pre-release scanning
2. Pre and post-build analysis
3. Periodic security assessments
4. Training support\\

As our capabilities expand daily, it is crucial to emphasize that AquilaX serves primarily as a versatile tool, akin to a multitool or Swiss Army knife, catering to various application security needs.


# Bending the technology

Serving you customers

<figure><img src="/files/oyk4WePozp1kga8JS5bO" alt="Bending the technology" width="563"><figcaption><p>Bending the technology</p></figcaption></figure>

> If you don't bend technology to edge for your customers, you're merely a reseller.

This is, one of the quote of an engineers here at AquilaX, something that may seems logical at the first glance, but if I dive in and decompose the message we extract 2 key info

1. **Bend technology**, this is linked to change or even change beyond possible the tech space
2. **Edge for customer**, to provide them a competitive advantages

Not all technology companies out there have a clear view of this problem, and don't get me wrong, business is a business and many tech firms are doing pretty well by just being reseller of other techs via their offering, there is nothing wrong in it.

An plausible and strong case can be seen into the AI space, where microsoft is taking OpenAI technology and embedded into their product, and is indeed very useful to the end customer... but never the less, is still reselling action.

Now, why are we even arguing this point, well, simply because any business and product out there is doing a bit of re-selling in a way or another, but what we aim in AquilaX is to use existing technology and bending it towards our core value... and everything else we planning to share it freely in the community back, an recent example is this blog post here: <https://aquilax-security.medium.com/intro-to-ml-ai-part-1-78bfdc1ec461>

By bending the technology we aim shape any existing tech advantage we can see out there to serve 100% our customer base!

Please shout out if you think our value does alterate from our services... we are not perfect but we want to be!


# SecuriTron In Action

AI Security Assistan

{% embed url="<https://vimeo.com/998928112>" %}


# Future


# The Future of Code Review

AquilaX to surpass traditional Code Review

<figure><img src="/files/xNJiHY861eVZlO9m5Gik" alt=""><figcaption><p>AquilaX to surpass traditional Code Review</p></figcaption></figure>

\
**AquilaX AI is ushering in a new era of software security, revolutionizing the way code reviews are conducted.** Traditional methods like **Static Application Security Testing (SAST)** and **Open Source Scanning (OSS)**, while valuable, are limited in scope and struggle to keep up with the vast complexity of modern codebases. Companies today rely on a handful of tools and overburdened security engineers to manually review and triage vulnerabilities, leading to inefficiencies and missed threats.

AquilaX AI aims to solve this by combining **advanced machine learning, natural language processing**, and security tools to analyze all source code in milliseconds. It evolves with each scan, identifying vulnerabilities early and predicting future risks based on evolving threat patterns. By integrating into **DevSecOps** pipelines, AquilaX AI enhances security from the earliest stages of development, ensuring real-time, continuous protection.

**AquilaX AI will surpass human intelligence in code review**, creating a powerful, fast, and intelligent security platform that can scan, secure, and evolve at a speed and scale unimaginable with traditional methods. The future of secure development has arrived with AquilaX AI, where intelligent automation takes software security to the next level.

Full story: <https://aquilax-security.medium.com/unstoppable-code-review-41d3d0b0b5f5>


# Building Superhumans

Software Security Revolution

<figure><img src="/files/7s4C9eGObu4OKpG0ZqPy" alt=""><figcaption><p>Building Superhumans in AppSec</p></figcaption></figure>

The article "[Building Superhumans](https://aquilax-security.medium.com/building-superhumans-2faa51c97b4d)" discusses the inevitable rise of AI in transforming industries, particularly cybersecurity. It compares AI’s potential impact to past technological revolutions like the Industrial Revolution, e-commerce, and the shift from Blockbuster to Netflix. While people initially resist change, they eventually embrace it because it improves convenience and efficiency.

The article highlights how AI will soon perform complex tasks better than humans, particularly in software security. It imagines AI models with superhuman abilities — 24/7 work, continuous learning, and no pay raises — outperforming the ideal human expert. AquilaX is developing such models to revolutionize cybersecurity, inviting users to try their platform and urging experts to share feedback.

In essence, AI isn’t a distant future; it’s already shaping up to deliver superhuman results across industries.


# Blog


# Breaking the Code: AquilaX

An AquilaX Opinion

<figure><img src="/files/muNhY2j2m3mbUBhSiKON" alt=""><figcaption><p>Breaking the Code: AquilaX</p></figcaption></figure>

\
Developers today face overwhelming choices in application security (AppSec) tools, leading to confusion about which tools to trust. The rapid growth of tools and diverse opinions complicates decision-making, especially for newer developers\\

To navigate this, developers should focus on understanding their expected outcomes before choosing tools. Research and test a few options to find the best fit for specific needs.\\

AquilaX simplifies this process by offering an integrated platform for tool selection, scanning, reporting, and fixing security issues. It helps developers streamline AppSec workflows and reduce confusion.\
\
Read more: <https://aquilax-security.medium.com/breaking-the-code-aquilax-de8fc3b509e5>


# Rethinking Authentication in 2024

An AquilaX Opinion

<figure><img src="/files/2K2IQny4emxprQIPWUXb" alt=""><figcaption><p>14 Controls for User Authentication</p></figcaption></figure>

the authentication systems of modern applications play a pivotal role in safeguarding user data and ensuring secure access. Yet, it’s astonishing that in 2024, many websites, portals, and online services persist in implementing their own user authentication mechanisms, often reinventing the wheel instead of leveraging established solutions. While there are valid cases for bespoke authentication, such as government websites, the majority of platforms simply require basic user identification and authentication.

Before delving into the benefits of embracing modern authentication solutions, let’s outline the fundamental prerequisites that any engineering team should ensure for a robust authentication service:

1\. **Strong Passwords:** Enforce stringent password policies to thwart brute force attacks and ensure password complexity.

2\. **Unique Username/Email:** Prevent duplication and enhance security by mandating unique user identifiers.

3\. **Bot Prevention System:** Implement measures to differentiate between human users and automated bots to mitigate fraudulent activities.

4\. **Two-Factor Authentication (2FA):** Augment security by requiring users to authenticate via a secondary method, typically a one-time code sent to their registered device.

5\. **User Enumeration Prevention:** Conceal user existence to deter malicious actors from exploiting enumeration vulnerabilities.

6\. **Brute Force Attack Prevention:** Implement mechanisms to detect and mitigate brute force attacks aimed at guessing user credentials.

7\. **Reverse Brute Force Attack Prevention:** Protect against attacks where a single password is attempted across multiple accounts.

8\. **Password Recovery Service:** Offer secure methods for users to regain access to their accounts in the event of password loss.

9\. **Email Validation:** Verify the authenticity of user-provided email addresses to prevent misuse.

10\. **Password Reset Functionality:** Enable users to reset forgotten passwords securely.

11\. **Geo Location for Authentication:** Employ geo-location data to verify user identity based on their physical location.

12\. **Account Lock and Unlock:** Implement mechanisms to temporarily lock user accounts after multiple failed login attempts, with provisions for unlocking.

13\. **Periodical Source Code Review:** Regularly audit the authentication system's source code to identify and mitigate potential vulnerabilities.

14\. **Penetration Testing and Security Assessments:** Conduct thorough penetration tests and security assessments to identify and rectify any vulnerabilities proactively.

While these measures form the foundation of a secure authentication system, the question arises: should engineering resources be expended on reinventing authentication mechanisms, or should the focus be on core functionalities?

The answer is clear: leveraging established authentication providers allows engineering teams to concentrate on developing the unique features that set their platform apart. At [AquilaX](https://aquilax.io/), we advocate for this approach, entrusting authentication to industry-leading services such as Google, Facebook, GitHub, or LinkedIn. By leveraging these platforms for user authentication, we not only streamline the development process but also inherit robust security measures implemented by these providers.

This approach not only simplifies the development process but also enhances security by leveraging the expertise and resources of established authentication providers. Additionally, it fosters interoperability and user convenience, as users can access multiple services with a single set of credentials.

While this discussion primarily focuses on authentication, the principles extend to authorization and trust chain for third-party providers. Embracing modern authentication solutions such as OpenID Connect fosters a more secure, interoperable, and user-friendly digital ecosystem.

In conclusion, in the age of heightened cybersecurity concerns, it’s imperative for engineering teams to prioritize secure authentication without diverting resources from core functionalities. By embracing modern authentication solutions and leveraging established providers, organizations can enhance security, streamline development, and deliver a seamless user experience. Let’s make secure authentication the norm in modern application development.


# Software Supply Chain Security

An AquilaX Opinion

<figure><img src="/files/SYbiCFbIOi1C1lfYR2Uz" alt=""><figcaption><p>SCA and Open Source Security Pipeline</p></figcaption></figure>

**Introduction**:

In software development, ensuring digital product security is crucial. Software Composition Analysis (SCA) is key in this process. AquilaX Security offers a robust SCA solution to identify and address vulnerabilities in your codebase.

**Understanding SCA:**

SCA involves scanning libraries in your application to detect known vulnerabilities, using databases like the National Vulnerability Database (NVD) for thorough risk assessment.

**Beyond Basic Security:**

AquilaX Security’s SCA not only identifies vulnerabilities but also evaluates license compatibility, addressing both security and legal compliance issues to avoid potential pitfalls.

**Utilizing Databases:**

AquilaX Security uses trusted databases such as NVD to stay updated on vulnerabilities, ensuring clients receive current and reliable security assessments.

**Supply Chain Security:**

SCA helps secure the software supply chain by identifying risks in dependencies, contributing to a robust and secure software delivery process.

**Legal and Compliance Considerations:**

AquilaX Security’s SCA also reviews license compatibility, helping organizations avoid legal issues and adhere to licensing agreements, fostering compliant software development.

**Conclusion:**

AquilaX Security’s SCA is essential for enhancing digital security, ensuring license compliance, and building a resilient software supply chain, making it a vital practice for secure software development.​\
\
Read more: <https://aquilax-security.medium.com/enhancing-software-supply-chain-security-with-software-composition-analysis-ea767424ae36>


# OneFirewall - Network Security

Enhancing Data Center Security: The Technical Impact of AquilaX's Partnership with OneFirewall

<figure><img src="/files/50odApHX0PJYpyfLU5nG" alt=""><figcaption><p>Network Protection with OneFirewall</p></figcaption></figure>

In response to increasingly sophisticated cyber threats, **AquilaX** has integrated **OneFirewall's real-time Indicator of Compromise (IoC) feeds** into its security architecture to strengthen its network perimeter and data center defenses. This collaboration brings together advanced technical capabilities to address the modern challenges of securing infrastructure against evolving attack vectors.

**Understanding OneFirewall’s IoC Capabilities**

[**OneFirewall**](https://onefirewall.com) provides comprehensive threat intelligence through a dynamic feed of IoCs, which are critical in identifying and responding to potential threats. These IoCs include:

1. **IP and Domain Indicators**: Regularly updated lists of malicious or compromised IP addresses and domains associated with known attack campaigns.
2. **File Hashes and Malware Signatures**: Unique identifiers for malicious files that allow for immediate detection during file or traffic analysis.
3. **Behavioral Data**: Indicators based on traffic patterns and anomalies associated with advanced persistent threats (APTs) and malware delivery mechanisms.
4. **Contextual Metadata**: Geolocation, ownership details, and historical usage patterns of flagged entities to enhance investigative capabilities.

These IoCs are collected and validated through a combination of machine learning algorithms, global honeypots, and community-driven threat submissions, ensuring high accuracy and minimal false positives.

**Technical Integration with AquilaX**

The integration of OneFirewall's IoC feeds into AquilaX’s infrastructure enables significant enhancements to its security operations:

1. **Real-Time Perimeter Defense**:
   * **Firewall and IDS/IPS Optimization**: IoC feeds are continuously synchronized with firewalls and intrusion detection/prevention systems (IDS/IPS) deployed within AquilaX’s environment. This ensures immediate blocking of malicious traffic attempting to penetrate the network.
   * **Dynamic Blocklists**: Automated updates to blocklists reduce manual intervention, keeping defenses aligned with the latest threat landscape.
2. **Threat Hunting and Forensics**:
   * **Proactive Threat Identification**: Security teams can use IoCs for active threat hunting within logs and traffic data to identify compromised systems or suspicious behavior.
   * **Incident Analysis**: IoC metadata provides contextual information that helps analysts determine the origin, intent, and scope of detected threats.
3. **Data Center Hardening**:
   * **Anomaly Detection**: By correlating OneFirewall’s data with internal telemetry (e.g., traffic patterns, authentication logs), anomalies indicative of lateral movement or exfiltration attempts can be detected early.
   * **Segmentation and Access Control**: IoC-based insights enhance micro-segmentation policies by restricting malicious entities at a granular level, protecting critical systems within the data center.
4. **AI-Driven Synergy**:
   * AquilaX’s AI-based vulnerability management system utilizes IoC data to enhance its threat prioritization algorithms. IoC feeds provide external validation for internal alerts, reducing false positives and improving response times.

**Strategic Advantages for Data Center Security**

The technical benefits of integrating OneFirewall’s IoC feeds include:

* **Enhanced Detection Accuracy**: High-fidelity IoCs reduce noise and ensure that only verified threats are flagged for action.
* **Faster Response Times**: Automation of IoC ingestion and enforcement significantly reduces the time from detection to mitigation.
* **Comprehensive Coverage**: Threat intelligence feeds cover a broad spectrum of attack vectors, from phishing campaigns to advanced malware distribution, providing holistic protection.
* **Scalable Protection**: Continuous updates and machine learning-driven insights enable the defenses to evolve in tandem with the threat landscape.

**Conclusion**

By combining **OneFirewall's real-time threat intelligence** with AquilaX’s AI-driven security platform, this partnership establishes a robust, layered defense system. The integration enables proactive identification, isolation, and remediation of threats targeting the network perimeter and data center environments.

This technical alliance underscores AquilaX’s commitment to leveraging state-of-the-art technologies to protect its infrastructure and ensure secure, uninterrupted operations in an era of ever-escalating cyber threats.


# The Art of Doing Source Code Review

Practical Guide

Source code review is a critical step in securing applications, but it’s often overlooked. In *The Art of Doing Source Code Review*, Aditya Rana breaks down the essentials, showing how to identify vulnerabilities early and improve code security.\\

Key Points:

• Why source code review matters in preventing security flaws

• Common vulnerabilities like SQL Injection, Path Traversal, and Remote Code Execution

• Code examples that highlight security risks

• A list of dangerous functions developers should be cautious about

• How tools like AquilaX can speed up the review process\\

This article is straightforward, with real examples and practical takeaways. If you work with code, it’s worth a read. Read more here: <https://green-terminals.medium.com/the-art-of-doing-source-code-review-c98ae0e35f84>


# Our Cloud Infrastracture

How AquilaX is deployed on multi-cloud

<figure><img src="/files/klMGruLvuImJOAfsx5e7" alt=""><figcaption><p>AquilaX Cloud Deployement Infra</p></figcaption></figure>


# AppSec


# 10 ‘must’ controls

10 ‘must’ controls for modern AppSec

## Introduction:

In the dynamic realm of digital advancements, the imperative for application security is more crucial than ever. With cyber threats evolving rapidly, the integration of robust security controls into the software development lifecycle (SDLC) becomes paramount. This article delves into a comprehensive set of security controls supported by AquilaX Security’s expert analysis. Their in-depth insights, available at \[AquilaX Security]\([https://aquilax.io](https://aquilax.io/)), enhance our understanding of securing applications throughout the development process.

### **1. Code Scanning:** <a href="#id-467c" id="id-467c"></a>

AquilaX Security’s analysis underscores the importance of code scanning tools like Fortify, Checkmarx, and SonarQube. Static Application Security Testing (SAST) provides early detection of vulnerabilities in source code, a critical step in building a secure foundation.

### 2. Dependency Scanning: <a href="#id-1886" id="id-1886"></a>

With insights from AquilaX, the significance of managing third-party dependencies is emphasized. Tools like OWASP Dependency-Check and Snyk help identify and patch vulnerabilities in open-source libraries, mitigating the risk of incorporating insecure components.

### 3. Container Scanning: <a href="#bf69" id="bf69"></a>

AquilaX Security’s expertise highlights the need to secure containerized applications. Container scanning tools such as Clair and Anchore, as recommended by AquilaX, play a crucial role in analyzing container images for vulnerabilities and misconfigurations.

### 4. Infrastructure Scanning: <a href="#c2dd" id="c2dd"></a>

Securing the underlying infrastructure is paramount, as pointed out by AquilaX’s analysis. Infrastructure as Code (IaC) scanning tools like TerraScan and Terrascan help identify security misconfigurations in cloud infrastructure deployments.

### 5. Secret Scanner: <a href="#ade7" id="ade7"></a>

AquilaX Security emphasizes the importance of securing sensitive information. Secret scanners like Trufflehog and GitGuardian, recommended by AquilaX, are essential tools for searching repositories and codebases for exposed secrets.

### 6. Automated Testing: <a href="#id-806a" id="id-806a"></a>

AquilaX Security’s insights stress the need to integrate security testing into automated processes. Dynamic Application Security Testing (DAST) tools like OWASP ZAP and Burp Suite are recommended by AquilaX for simulating real-world attacks and identifying vulnerabilities.

### 7. Security Training and Awareness: <a href="#id-9cb4" id="id-9cb4"></a>

AquilaX underscores the value of developer training programs to enhance security awareness. Educated developers, as highlighted by AquilaX’s analysis, are more likely to write secure code and follow best practices.

### 8. Secure Coding Standards: <a href="#id-9c85" id="id-9c85"></a>

AquilaX Security advocates for the establishment and enforcement of secure coding standards. Tools like SonarQube, as mentioned by AquilaX, automate code reviews and provide feedback on adherence to coding standards and security guidelines.

### 9. Continuous Integration/Continuous Deployment (CI/CD) Security: <a href="#id-32cf" id="id-32cf"></a>

AquilaX’s analysis encourages embedding security checks into the CI/CD pipeline. Tools like GitLab CI/CD and Jenkins, along with security plugins, enable automated security checks throughout the deployment pipeline.

### 10. Incident Response Planning: <a href="#e0ea" id="e0ea"></a>

AquilaX Security highlights the importance of an incident response plan. This plan should outline steps to be taken in case of a security breach, emphasizing communication, investigation, and mitigation strategies.

## Conclusion: <a href="#d20e" id="d20e"></a>

The comprehensive security controls discussed, backed by AquilaX Security’s expert analysis available at \[AquilaX]\([https://aquilax.](https://aquilax.io/)ai), provide a robust framework for enhancing application security throughout the software development lifecycle. By integrating these controls and insights into the development process, organizations can fortify their applications against evolving cyber threats, ensuring the protection of users and valuable data.\\


# OWASP Top 10

Understanding and Mitigating Common Vulnerabilities

## Introduction

The OWASP Top 10 is a well-established list of the most critical web application security risks. The purpose of this article is to break down these vulnerabilities, explain their implications, and provide practical steps to mitigate them.

## A1: Injection

**Description:** Injection flaws, such as SQL injection, occur when an attacker can send untrusted data to an interpreter as part of a command or query. This can lead to data leakage, corruption, and even full server compromise.

**Mitigation:** Use prepared statements and parameterized queries.

```python
# Example of SQL Injection Prevention in Python using parameterized queries
import sqlite3

def get_user(user_id):
    conn = sqlite3.connect('example.db')
    cursor = conn.cursor()
    cursor.execute("SELECT * FROM users WHERE id = ?", (user_id,))
    return cursor.fetchone()
```

## A2: Broken Authentication

**Description:** This category includes risks such as predictable login credentials, session fixations, and missing logout provisions.

**Mitigation:** Implement multi-factor authentication (MFA) and secure session management.

```javascript
// Example of secure session handling in Express.js
app.post('/login', (req, res) => {
    req.session.userId = user.id;
    req.session.save();
});
```

## A3: Sensitive Data Exposure

**Description:** Sensitive data, including passwords, credit cards, and personal information, can be exposed through inadequate protection.

**Mitigation:** Use strong encryption protocols and techniques for data at rest and in transit.

```java
// Example of using AES for encryption in Java
import javax.crypto.Cipher;
import javax.crypto.KeyGenerator;
import javax.crypto.SecretKey;

Cipher cipher = Cipher.getInstance("AES");
KeyGenerator keyGen = KeyGenerator.getInstance("AES");
keyGen.init(128);
SecretKey key = keyGen.generateKey();
```

## A4: XML External Entities (XXE)

**Description:** XXE vulnerabilities exploit a poorly configured XML parser to process an external entity, leading to data exposure.

**Mitigation:** Disable external entity processing in XML parsers.

```xml
// Disable external entities in Java DOM parser
DocumentBuilderFactory factory = DocumentBuilderFactory.newInstance();
factory.setFeature("http://xml.org/sax/features/external-general-entities", false);
factory.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
```

## A5: Broken Access Control

**Description:** This involves flaws that permit users to act outside their intended access permissions.

**Mitigation:** Implement proper role-based access control (RBAC) checks on resources.

```php
// Example of RBAC check in PHP
if ($_SESSION['user_role'] === 'admin') {
    // Allow access to sensitive data
} else {
    // Deny access
}
```

## A6: Security Misconfiguration

**Description:** Misconfigurations can happen at any level, including the operating system, application server, database, or custom code. They can leave the application vulnerable to attacks.

**Mitigation:** Regularly review and update configuration settings. Automate security checks in your CI/CD pipeline.

## A7: Cross-Site Scripting (XSS)

**Description:** XSS allows attackers to inject client-side scripts into web pages viewed by other users.

**Mitigation:** Encode outputs and use Content Security Policies (CSP).

```javascript
// Example of output encoding in JavaScript
document.getElementById('output').innerText = userInput;
```

## A8: Insecure Deserialization

**Description:** Insecure deserialization can lead to remote code execution attacks and alter application behavior.

**Mitigation:** Avoid accepting serialized objects from untrusted sources.

## A9: Using Components with Known Vulnerabilities

**Description:** Applications using third-party libraries and components that contain known vulnerabilities can be exploited easily by attackers.

**Mitigation:** Regularly update and patch libraries. Use Software Composition Analysis (SCA) tools to manage dependencies.

## A10: Insufficient Logging & Monitoring

**Description:** Insufficient logging and monitoring can hinder the detection of attacks and allow them to persist undetected.

**Mitigation:** Implement logging best practices and ensure logs are monitored for unusual activity.

## Conclusion

Understanding the OWASP Top Ten is crucial for developers and security teams. By recognizing these risks and implementing best practices for mitigation, organizations can significantly reduce their vulnerability to cyber threats.




---

[Next Page](/llms-full.txt/1)

