CI/CD Security Scanning

Run an external vulnerability check from your pipeline, so every deploy gets tested from the outside and the finding reaches you in the same week as the change that caused it — not three weeks after the branch was merged.

14 days of the full Advanced plan · no card required · first results in 5–10 minutes

  • One line in the pipeline
  • No agent
  • Unlimited runs
  • 5–15 min for a web check

what adding the check actually costs you

Topscan new scan: the Event section that generates the link a pipeline calls

Security Challenges
Every Team Faces

What happens in practice

  • A release ships on Friday and the security check waits for a free afternoon

  • A preview environment per pull request goes up, and nobody takes it down

  • Infrastructure changes open something that was closed last month

  • A finding is real, but it reaches the developer weeks after the code moved on

  • Security checks depend on someone remembering to run them

How Topscan handles it

  • The check starts from your pipeline, so it runs on every deploy

  • Runs are unlimited, so putting it on every deploy costs nothing extra

  • Hosts created by the pipeline are discovered from public records

  • Findings name the affected host and URL, with severity and remediation guidance

  • Open findings stay visible until they are resolved, with SLA tracking

How CI/CD Security Scanning Works

  1. Step 1

    Add one call to your pipeline

    One line in the workflow you already have. It starts the scan for a target you have already confirmed — no agent to install and nothing running on your servers.

    GitHub Actions

    - name: Trigger Topscan scan
      run: curl -fsS -X POST "$TOPSCAN_WEBHOOK"
      env:
        TOPSCAN_WEBHOOK: ${{ secrets.TOPSCAN_WEBHOOK }}

    GitLab CI

    topscan-scan:
      stage: deploy
      script:
        - curl -fsS -X POST "$TOPSCAN_WEBHOOK"

    Your webhook looks like https://hooks.topscan.me/scans/notify/<your-scan-id> — the URL is the credential, so store the whole thing as a masked secret. The -f flag makes the step fail if the trigger itself didn't go through; findings never fail the build.

    • One line
    • No agent
    • Confirmed targets
    Topscan Scans: a run started from the pipeline in the list of completed scans
  2. Step 2

    Test the deployed environment from the outside

    The scan runs against the environment you just deployed, the same way an outsider would reach it: the web application, its public APIs, and the infrastructure serving them. No agent runs on your servers and no access to your source is required for this step.

    A web check takes five to fifteen minutes; a full infrastructure audit runs thirty to ninety, so most teams put the fast one on deploys and the deep one on a schedule.

    • Web app & APIs
    • 5–15 min fast check
    • 30–90 min deep audit
    • No agent
    Topscan new scan: the scan presets with their expected duration
  3. Step 3

    Read the result where the findings live

    Findings come back with severity, the affected URLs and assets, what was found and how to fix it. The pipeline starts the scan; the results are read in Topscan and in the channel your team already watches.

    • Severity
    • Affected URLs
    • Remediation guidance
    • Slack & email
    One scan opened after a deploy: issues counted by severity, each with its own detail
  4. Step 4

    Keep a dated trail of what each release exposed

    Every run is recorded with its date and target, and new findings enter the same issue list with a deadline on each. The activity log is what answers «what did we expose last month» without anyone reconstructing it.

    • Activity log
    • Dated runs
    • SLA tracking
    Topscan Activity: dated entries for each run and the findings it produced
Features

Features & Capabilities in one step

  • Pipeline-triggered scanning

    The check starts from your existing workflow, not from someone remembering. It runs on deploys, on infrastructure changes, and after security fixes to confirm they landed.

  • Unlimited runs

    Scans are never billed, so putting the check on every deploy costs exactly the same as running it once a month.

  • Findings developers can act on

    Every result names the host, the URL and what answered, with severity and remediation guidance — so the person who wrote the code can confirm it in a browser.

  • Remediation that does not get lost

    Open findings stay visible until resolved, with SLA tracking, so a real issue doesn't quietly age out of everyone's memory between releases.

Who Topscan Is Built For

  • Head of DevOps

    Make the security check something everyone already runs, instead of a review that depends on someone having time.

  • Senior DevOps / Platform Engineer

    See what each deploy exposed on the outside, including the hosts the pipeline created on its own.

  • CTO

    Get recurring external checks on the delivery workflow without hiring an AppSec function to run them.

  • Teams preparing for an audit

    Produce continuous evidence of scanning tied to releases. Your auditor should confirm applicability.

Run scans inside the pipeline you already have

The call drops into your existing workflow, and results go where your team already reads them.

  • GitHub
  • GitLab
  • Slack
  • Jira
  • Email
  • AWS
  • CI/CD webhook

Fair pricing for your pipeline

Runs are unlimited, so the check can go on every deploy at no extra cost. The per-branch hosts your pipeline creates are found by discovery for free and only consume a licence if you put them under monitoring.

  • Basic

    $129/ month

    For small teams without cloud infrastructure — one DevOps or CTO who owns security among other things.


    • 3 infrastructure hosts — an IP, a hostname or a subdomain
    • 1 web application tested while it’s running
    • 10 repositories scanned by SAST
  • Advanced

    14 days free trialBest value

    $269/ month

    For companies of 20–60 with AWS infrastructure and active CI/CD.


    • 8 infrastructure hosts, 2 web applications, 20 repositories
    • AWS integration — cloud assets discovered automatically
    • Slack routing and Jira tickets for findings
  • Pro

    $449/ month

    For companies of 30–100 with mature DevOps, first enterprise customers and audit requirements.


    • 15 infrastructure hosts, 4 web applications, 40 repositories
    • Custom SLA by severity and per target, Severity Override with an audit trail
    • Two-way CI/CD webhook and Attack Surface change tracking with alerts

You pay for what you monitor — not for seats, scans or findings

Discovery costs nothing: it maps your whole footprint and a licence is used only when you put a host under monitoring. Scans are never billed, so a weekly schedule costs the same as a monthly one, and the whole team reads findings on any paid plan — developers, whoever tracks remediation, and read-only seats for auditors.

In every paid plan

  • External infrastructure scanning
  • Static code analysis, all supported languages
  • Remediation history with dates
  • Role-based access control
  • Attack Surface and Security Score
  • Dependency scanning (SCA)
  • CI/CD webhook to trigger a scan
  • Unlimited scans and users
  • Web application scanning
  • Statuses, SLA and snooze on every finding
  • Email alerts
  • Free read-only seats for auditors
Need more than your plan includes? Extra licences are $4 per infrastructure host, $45 per web application and $9 per repository — the same rate on every paid plan, with no volume pricing to negotiate. The 14-day trial gives you the full Advanced plan and needs no card.

Walk through it before you sign up

Five clicks through the real product. No form, no demo call.

Topscan: generating the event link a pipeline calls

Step 1 · Add the call

One line in the workflow you already have.

Step 1 of 5 — click the highlighted spot

FAQ

Topscan builds on the best in class scanning engines

Still have questions?

Contact us
Add a domain while you sign up and discovery answers within five to ten minutes — that is your first map of what faces the internet, before anything is scanned. Scanning comes after you confirm what to monitor: a fast check finishes in five to fifteen minutes, a full infrastructure audit in thirty to ninety, and a deep web application scan can run up to a few hours. Those are typical times, not guarantees — the real duration depends on the target: how many hosts answer, how large the application is and how quickly it responds.
Not today. The pipeline starts the scan and carries on; results are read in Topscan and in your chat. A status callback into the pipeline — the thing that would let you gate a release on severity — is on the roadmap for Pro and isn't built yet, so we won't claim it here.
A fast web check runs five to fifteen minutes, which is what most teams put on deploys. A full infrastructure audit runs thirty to ninety minutes and usually sits on a schedule instead.
This page is about the check that runs against the deployed application from the outside — it needs no access to your repository. Source code scanning is a separate part of Topscan, included in the same subscription: see the Static Code Analysis page.
Authenticated scanning is in testing and ships shortly. It runs only where you have supplied the credentials yourself — the scanner never attempts to get past authentication it wasn't explicitly asked to use.
Discovery is passive: public registries, DNS and one ordinary HTTP request per host. Active checks run only against targets you have explicitly confirmed, request rate is limited, and the engine observes rather than exploits — nothing destructive is sent and no data is modified. If you would rather not point it at production, point it at staging.
Runs are unlimited, so the check can go on every deploy at no extra cost, and users are unlimited with free read-only seats. What is licensed is the hosts you monitor: one IP, hostname or subdomain is $4 a month, with 3 included on Basic and 8 on Advanced. Per-branch hosts are discovered for free and only cost something if you choose to monitor them.
Customer data is stored in the Hetzner cloud in Ashburn, Virginia, US. None of the developers have access to the production environment — only the Head of DevOps does, and every action he takes is logged. No customer data leaves our infrastructure or is passed to third-party systems, including third-party AI services: everything happens inside a closed environment. We are currently going through a SOC 2 audit and track our processes in Drata. If you delete your account, all data is permanently removed from our servers within 180 days.

Put the check where the change happens

Add one call to your pipeline and one domain to Topscan. It costs nothing to look.

14 days of the full Advanced plan · no card required