CI/CD Security Scanning
Run an external vulnerability check from your pipeline, so every deploy gets tested from the outside and the finding reaches you in the same week as the change that caused it — not three weeks after the branch was merged.
14 days of the full Advanced plan · no card required · first results in 5–10 minutes
- One line in the pipeline
- No agent
- Unlimited runs
- 5–15 min for a web check
what adding the check actually costs you

Security Challenges
Every Team Faces
What happens in practice
A release ships on Friday and the security check waits for a free afternoon
A preview environment per pull request goes up, and nobody takes it down
Infrastructure changes open something that was closed last month
A finding is real, but it reaches the developer weeks after the code moved on
Security checks depend on someone remembering to run them
How Topscan handles it
The check starts from your pipeline, so it runs on every deploy
Runs are unlimited, so putting it on every deploy costs nothing extra
Hosts created by the pipeline are discovered from public records
Findings name the affected host and URL, with severity and remediation guidance
Open findings stay visible until they are resolved, with SLA tracking
How CI/CD Security Scanning Works
Step 1
Add one call to your pipeline
One line in the workflow you already have. It starts the scan for a target you have already confirmed — no agent to install and nothing running on your servers.
GitHub Actions
- name: Trigger Topscan scan run: curl -fsS -X POST "$TOPSCAN_WEBHOOK" env: TOPSCAN_WEBHOOK: ${{ secrets.TOPSCAN_WEBHOOK }}GitLab CI
topscan-scan: stage: deploy script: - curl -fsS -X POST "$TOPSCAN_WEBHOOK"Your webhook looks like https://hooks.topscan.me/scans/notify/<your-scan-id> — the URL is the credential, so store the whole thing as a masked secret. The -f flag makes the step fail if the trigger itself didn't go through; findings never fail the build.
- One line
- No agent
- Confirmed targets

Step 2
Test the deployed environment from the outside
The scan runs against the environment you just deployed, the same way an outsider would reach it: the web application, its public APIs, and the infrastructure serving them. No agent runs on your servers and no access to your source is required for this step.
A web check takes five to fifteen minutes; a full infrastructure audit runs thirty to ninety, so most teams put the fast one on deploys and the deep one on a schedule.
- Web app & APIs
- 5–15 min fast check
- 30–90 min deep audit
- No agent

Step 3
Read the result where the findings live
Findings come back with severity, the affected URLs and assets, what was found and how to fix it. The pipeline starts the scan; the results are read in Topscan and in the channel your team already watches.
- Severity
- Affected URLs
- Remediation guidance
- Slack & email

Step 4
Keep a dated trail of what each release exposed
Every run is recorded with its date and target, and new findings enter the same issue list with a deadline on each. The activity log is what answers «what did we expose last month» without anyone reconstructing it.
- Activity log
- Dated runs
- SLA tracking

Features & Capabilities in one step
Pipeline-triggered scanning
The check starts from your existing workflow, not from someone remembering. It runs on deploys, on infrastructure changes, and after security fixes to confirm they landed.
Unlimited runs
Scans are never billed, so putting the check on every deploy costs exactly the same as running it once a month.
Findings developers can act on
Every result names the host, the URL and what answered, with severity and remediation guidance — so the person who wrote the code can confirm it in a browser.
Remediation that does not get lost
Open findings stay visible until resolved, with SLA tracking, so a real issue doesn't quietly age out of everyone's memory between releases.
Who Topscan Is Built For
Head of DevOps
Make the security check something everyone already runs, instead of a review that depends on someone having time.
Senior DevOps / Platform Engineer
See what each deploy exposed on the outside, including the hosts the pipeline created on its own.
CTO
Get recurring external checks on the delivery workflow without hiring an AppSec function to run them.
Teams preparing for an audit
Produce continuous evidence of scanning tied to releases. Your auditor should confirm applicability.
Run scans inside the pipeline you already have
The call drops into your existing workflow, and results go where your team already reads them.
GitHub
GitLab
Slack
Jira
AWS
- CI/CD webhook
Fair pricing for your pipeline
Runs are unlimited, so the check can go on every deploy at no extra cost. The per-branch hosts your pipeline creates are found by discovery for free and only consume a licence if you put them under monitoring.
Basic
$129/ month
For small teams without cloud infrastructure — one DevOps or CTO who owns security among other things.
- 3 infrastructure hosts — an IP, a hostname or a subdomain
- 1 web application tested while it’s running
- 10 repositories scanned by SAST
Advanced
14 days free trialBest value$269/ month
For companies of 20–60 with AWS infrastructure and active CI/CD.
- 8 infrastructure hosts, 2 web applications, 20 repositories
- AWS integration — cloud assets discovered automatically
- Slack routing and Jira tickets for findings
Pro
$449/ month
For companies of 30–100 with mature DevOps, first enterprise customers and audit requirements.
- 15 infrastructure hosts, 4 web applications, 40 repositories
- Custom SLA by severity and per target, Severity Override with an audit trail
- Two-way CI/CD webhook and Attack Surface change tracking with alerts
You pay for what you monitor — not for seats, scans or findings
Discovery costs nothing: it maps your whole footprint and a licence is used only when you put a host under monitoring. Scans are never billed, so a weekly schedule costs the same as a monthly one, and the whole team reads findings on any paid plan — developers, whoever tracks remediation, and read-only seats for auditors.
In every paid plan
- External infrastructure scanning
- Static code analysis, all supported languages
- Remediation history with dates
- Role-based access control
- Attack Surface and Security Score
- Dependency scanning (SCA)
- CI/CD webhook to trigger a scan
- Unlimited scans and users
- Web application scanning
- Statuses, SLA and snooze on every finding
- Email alerts
- Free read-only seats for auditors
Walk through it before you sign up
Five clicks through the real product. No form, no demo call.

Step 1 · Add the call
One line in the workflow you already have.
Step 1 of 5 — click the highlighted spot
FAQ
Topscan builds on the best in class scanning engines
Still have questions?
Contact usPut the check where the change happens
Add one call to your pipeline and one domain to Topscan. It costs nothing to look.
14 days of the full Advanced plan · no card required