Notifications & Alerting

Most weeks there is nothing to tell you, and that's the point. Topscan stays quiet until something actually changed on your perimeter — a new finding, a severity that moved, an issue that came back, a deadline that passed — and then it says so in the channel you already read.

14 days of the full Advanced plan · no card required · first results in 5–10 minutes

  • New finding
  • Severity changed
  • Reopened
  • SLA overdue

the events that raise an alert today

Topscan: the activity log with what changed and when

Security Challenges
Every Team Faces

What happens in practice

  • A finding lands in a dashboard, and the dashboard gets opened next quarter

  • The problem surfaces through a customer email instead of a scan

  • An issue was closed, came back with the next release, and nobody noticed

  • A remediation deadline passes quietly

  • Every tool wants a channel, so the team mutes all of them

How Topscan handles it

  • New findings reach your channel while they're still cheap to fix

  • Alerts carry the affected asset, the type, the severity and a direct link

  • A reopened issue is flagged as reopened, not as new

  • Overdue remediation deadlines are surfaced on their own

  • Alerts fire on change, so a standing list of open items doesn't generate daily noise

How Alerting Works

  1. Step 1

    Choose the events worth an interruption

    Four things raise an alert today: a newly detected vulnerability with the scan that found it, a severity that changed, an issue that reopened, and a remediation deadline that passed. You pick which of them travel, and where.

    • New finding
    • Severity change
    • Reopened
    • SLA overdue
    Topscan: certificates with their dates and status
  2. Step 2

    Send it where the team actually looks

    Email reaches everyone; Slack reaches the channel the team already has open. Email alerts are on every plan, Slack starts on Advanced.

    • Email on every plan
    • Slack from Advanced
    Topscan: connected integrations
  3. Step 3

    Get the finding, not a notification about a finding

    Every alert carries what's needed to act: the affected asset or URL, the type of issue, the severity, the current remediation status and a direct link. No raw scanner output, and no report that has to be opened to find out whether it matters.

    • Affected asset & URL
    • Issue type
    • Severity
    • Direct link
    Topscan: a finding with severity, status and a link
  4. Step 4

    Deadlines that don't slip quietly

    A passed deadline is its own event, so an issue can't age out of everyone's attention just because it stopped being new. Overdue items are surfaced separately from the stream of new findings.

    • SLA overdue
    • Reopened flagged
    • Change, not existence
    Topscan: the activity log with what changed and when
Features

Features & Capabilities in one place

  • Alerts on what changed, not on what exists

    The trigger is a change: a new finding, a severity that moved, an issue that came back. A standing list of open items doesn't generate a message every day.

  • Overdue remediation surfaced separately

    A deadline that passed is its own event, so an issue can't disappear into a long list just because it stopped being new.

  • A reopened issue is marked as returning

    Recurrence is information. An issue that comes back is flagged as the same issue rather than arriving as something new.

  • Alerts that carry the work

    Asset, type, severity, status and a direct link — enough to act without opening another tool.

Who Topscan Is Built For

  • Head of DevOps

    Hear about a new exposure the week it appears, in the channel your team already watches.

  • Senior DevOps / Platform Engineer

    Know when a deadline passed or an old issue came back, without checking.

  • CTO

    Know that nothing is waiting in a dashboard for someone to open it.

  • Teams preparing for an audit

    Overdue remediation and reopened issues are surfaced as they happen, so the record you hand an auditor doesn't need reconstructing. Your auditor should confirm applicability.

Alerts arrive where your team already looks

Email on every plan, Slack from Advanced. The same destinations as the rest of Topscan.

  • GitHub
  • GitLab
  • Slack
  • Jira
  • Email
  • AWS
  • CI/CD webhook

Fair pricing for your team

Email alerts are part of every plan. Slack routing starts on Advanced at $269 a month, together with Jira and AWS.

  • Basic

    $129/ month

    For small teams without cloud infrastructure — one DevOps or CTO who owns security among other things.


    • 3 infrastructure hosts — an IP, a hostname or a subdomain
    • 1 web application tested while it’s running
    • 10 repositories scanned by SAST
  • Advanced

    14 days free trialBest value

    $269/ month

    For companies of 20–60 with AWS infrastructure and active CI/CD.


    • 8 infrastructure hosts, 2 web applications, 20 repositories
    • AWS integration — cloud assets discovered automatically
    • Slack routing and Jira tickets for findings
  • Pro

    $449/ month

    For companies of 30–100 with mature DevOps, first enterprise customers and audit requirements.


    • 15 infrastructure hosts, 4 web applications, 40 repositories
    • Custom SLA by severity and per target, Severity Override with an audit trail
    • Two-way CI/CD webhook and Attack Surface change tracking with alerts

You pay for what you monitor — not for seats, scans or findings

Discovery costs nothing: it maps your whole footprint and a licence is used only when you put a host under monitoring. Scans are never billed, so a weekly schedule costs the same as a monthly one, and the whole team reads findings on any paid plan — developers, whoever tracks remediation, and read-only seats for auditors.

In every paid plan

  • External infrastructure scanning
  • Static code analysis, all supported languages
  • Remediation history with dates
  • Role-based access control
  • Attack Surface and Security Score
  • Dependency scanning (SCA)
  • CI/CD webhook to trigger a scan
  • Unlimited scans and users
  • Web application scanning
  • Statuses, SLA and snooze on every finding
  • Email alerts
  • Free read-only seats for auditors
Need more than your plan includes? Extra licences are $4 per infrastructure host, $45 per web application and $9 per repository — the same rate on every paid plan, with no volume pricing to negotiate. The 14-day trial gives you the full Advanced plan and needs no card.

Walk through it before you sign up

Five clicks through the real product. No form, no demo call.

Topscan: certificates with their dates and status

Step 1 · Pick the events

New finding, severity change, reopened, overdue.

Step 1 of 5 — click the highlighted spot

FAQ

Topscan builds on the best in class scanning engines

Still have questions?

Contact us
Add a domain while you sign up and discovery answers within five to ten minutes — that is your first map of what faces the internet, before anything is scanned. Scanning comes after you confirm what to monitor: a fast check finishes in five to fifteen minutes, a full infrastructure audit in thirty to ninety, and a deep web application scan can run up to a few hours. Those are typical times, not guarantees — the real duration depends on the target: how many hosts answer, how large the application is and how quickly it responds.
That's the failure mode we design against. Alerts fire on change, not on the existence of open items — a list of things you already know about doesn't generate a daily message.
A newly detected vulnerability, a severity that changed, an issue that reopened, and a remediation deadline that passed.
Email on every plan, and Slack from Advanced. A finding can also become a Jira task, with the summary and description filled in — see the Integrations page.
Customer data is stored in the Hetzner cloud in Ashburn, Virginia, US. None of the developers have access to the production environment — only the Head of DevOps does, and every action he takes is logged. No customer data leaves our infrastructure or is passed to third-party systems, including third-party AI services: everything happens inside a closed environment. We are currently going through a SOC 2 audit and track our processes in Drata. If you delete your account, all data is permanently removed from our servers within 180 days.

Hear about it the week it appears

Add one domain and one channel. The first scan takes about five minutes.

14 days of the full Advanced plan · no card required