Security scans
Scoped, evidence-backed investigations of your repositories. Armalo pins the exact snapshot, runs detectors, and links every finding to the evidence that supports it.
Point at a repository and ref; Armalo pins the exact snapshot it examined.
Findings are proposed with severity and rationale, separate from validated state.
Evidence references stay attached to the run that produced them.
Point Armalo at a repository, name the attacker paths that matter, and run a scan you can trace back to evidence.
Scan target
github · main · immutable snapshot
This scan can read the pinned target and produce evidence. It cannot modify code or open a pull request.
You can review the threat model before any deeper assessment starts.
Sign in to see this workspace's scan history.
Workspace history is private.
Scan history belongs to each workspace. You’re signed out, so there’s nothing to show here — sign in to see your workspace’s runs.
Start a new investigation →Found something we should know about? Email security@armalo.ai with what you found, where you found it, and how to reproduce it. We read every report and confirm we have received it.