Security Compliance Reporting

Nobody has ever enjoyed rebuilding six months of scan history the week an auditor asks for it. Topscan keeps the record as you go — what was scanned, what was found, what was fixed and how long it took — so the evidence is a by-product of the work instead of a project of its own.

14 days of the full Advanced plan · no card required · first results in 5–10 minutes

  • Free read-only seats for auditors
  • Every scan kept while you subscribe
  • Status and time to fix on every finding

what an auditor asks for — and what it costs to give them access

Topscan Scans: the scheduled runs above completed scans with their dates and issue counts

Security Challenges
Every Team Faces

What happens in practice

  • Scans happened, but nothing recorded when or against what

  • Evidence is reassembled from screenshots and someone's memory

  • A customer security review lands mid-sprint and takes a week to answer

  • Nobody can show that a finding from March was actually fixed

  • The spreadsheet tracking remediation was last accurate two releases ago

How Topscan handles it

  • Every scan is stored with its date, its target and what it found

  • Findings keep their severity, affected asset and remediation status over time

  • Remediation is timestamped, so «fixed in April» is a record rather than a claim

  • Overdue and reopened issues stay visible instead of quietly ageing out

  • Auditors get their own free read-only seats — no export ritual, no screenshots

How Compliance Reporting Works

  1. Step 1

    Scan on a schedule, or before releases

    The record starts with the scanning you were going to do anyway: recurring checks on your confirmed targets, plus runs triggered from your pipeline before a release. Nothing extra to remember, because reporting isn't a separate activity here.

    • Recurring scans
    • Pre-release runs
    • No separate reporting workflow
    Topscan Scans: weekly scheduled runs above the list of completed scans
  2. Step 2

    Everything is kept with its date attached

    Each scan is stored with its date and target, the vulnerabilities found, their severity, the affected assets and URLs, and the remediation status at that moment. That's the difference between «we scan regularly» and being able to show it.

    History is kept for as long as your subscription is active — there is no rolling window that quietly drops the period an auditor wants to see.

    • Scan date & target
    • Findings & severity
    • Kept while you subscribe
    One scan opened: issues counted by severity, and each finding with its date and status
  3. Step 3

    Watch the clock on remediation

    A finding carries its remediation deadline, and the time it actually took is recorded when it closes. Overdue items and issues that reopened are surfaced separately, which is exactly the pattern an auditor asks about: not «do you find things», but «what happens after you find them».

    • Remediation deadlines
    • Time to fix
    • Overdue & reopened tracked
    Topscan Activity: reopened issues and overdue deadlines, each entry dated
  4. Step 4

    Hand it over without a fire drill

    Invite the reviewer to a free read-only seat and they read the record themselves, or export it — the scan and remediation history goes out as PDF for a report and CSV for anyone who wants the raw rows.

    Either way nobody is assembling a folder of screenshots the week before the audit.

    • Free auditor seats
    • PDF report
    • CSV export
    • Scan & remediation history
    Topscan attack surface with the Export Targets action in the top right corner
Features

Features & Capabilities in one place

  • A record that writes itself

    Scan history, findings, severities and remediation status accumulate from ordinary use. There is no reporting step to skip when the week gets busy.

  • History that outlasts the audit cycle

    Everything is kept for as long as your subscription is active, so a reviewer asking for the last twelve months gets the last twelve months.

  • Time-to-fix, not just find-rate

    Remediation deadlines and the time each finding actually took are kept — the part of the story that says the process works.

  • Read-only seats for auditors on paid plans

    The person reviewing you can read the record directly. Paid plans allow unlimited users on your side, so nobody is sharing a login to produce evidence.

Who Topscan Is Built For

  • CTO going through SOC 2 or ISO 27001 preparation

    Produce the scanning and remediation evidence the process asks for, without adding a reporting workflow on top of engineering work.

  • Teams answering customer security reviews

    A due-diligence questionnaire arrives mid-sprint. Answer it from a record that already exists rather than assembling one.

  • Head of DevOps

    See unresolved and overdue items across targets without maintaining a spreadsheet that goes stale after two releases.

  • Anyone reporting upward

    Show what was found and fixed over time, with dates, instead of a scanner export nobody can read.

Findings and their history go where the work happens

Scans trigger from your pipeline, findings reach your chat, and the remediation record follows them.

  • GitHub
  • GitLab
  • Slack
  • Jira
  • Email
  • AWS
  • CI/CD webhook

Fair pricing for your evidence

On paid plans read-only seats for auditors are free, users are unlimited and scans are unlimited — so scanning often enough to satisfy a reviewer doesn't change the bill.

  • Basic

    $129/ month

    For small teams without cloud infrastructure — one DevOps or CTO who owns security among other things.


    • 3 infrastructure hosts — an IP, a hostname or a subdomain
    • 1 web application tested while it’s running
    • 10 repositories scanned by SAST
  • Advanced

    14 days free trialBest value

    $269/ month

    For companies of 20–60 with AWS infrastructure and active CI/CD.


    • 8 infrastructure hosts, 2 web applications, 20 repositories
    • AWS integration — cloud assets discovered automatically
    • Slack routing and Jira tickets for findings
  • Pro

    $449/ month

    For companies of 30–100 with mature DevOps, first enterprise customers and audit requirements.


    • 15 infrastructure hosts, 4 web applications, 40 repositories
    • Custom SLA by severity and per target, Severity Override with an audit trail
    • Two-way CI/CD webhook and Attack Surface change tracking with alerts

You pay for what you monitor — not for seats, scans or findings

Discovery costs nothing: it maps your whole footprint and a licence is used only when you put a host under monitoring. Scans are never billed, so a weekly schedule costs the same as a monthly one, and the whole team reads findings on any paid plan — developers, whoever tracks remediation, and read-only seats for auditors.

In every paid plan

  • External infrastructure scanning
  • Static code analysis, all supported languages
  • Remediation history with dates
  • Role-based access control
  • Attack Surface and Security Score
  • Dependency scanning (SCA)
  • CI/CD webhook to trigger a scan
  • Unlimited scans and users
  • Web application scanning
  • Statuses, SLA and snooze on every finding
  • Email alerts
  • Free read-only seats for auditors
Need more than your plan includes? Extra licences are $4 per infrastructure host, $45 per web application and $9 per repository — the same rate on every paid plan, with no volume pricing to negotiate. The 14-day trial gives you the full Advanced plan and needs no card.

Walk through it before you sign up

Five clicks through the real product. No form, no demo call.

Topscan: the scan history

Step 1 · Open the scan history

Every run, with its date and its target.

Step 1 of 5 — click the highlighted spot

FAQ

Topscan builds on the best in class scanning engines

Still have questions?

Contact us
Add a domain while you sign up and discovery answers within five to ten minutes — that is your first map of what faces the internet, before anything is scanned. Scanning comes after you confirm what to monitor: a fast check finishes in five to fifteen minutes, a full infrastructure audit in thirty to ninety, and a deep web application scan can run up to a few hours. Those are typical times, not guarantees — the real duration depends on the target: how many hosts answer, how large the application is and how quickly it responds.
No, and no tool does. Both frameworks cover far more than vulnerability management. What Topscan provides is one piece of the evidence — regular external scanning and a dated record of what was found and fixed. Your auditor should confirm applicability to your scope.
For as long as your subscription is active. There is no rolling window, so a reviewer asking for the last three, six or twelve months gets the whole period.
No, and the two sit side by side. Those platforms manage the programme: policies, controls, evidence collection across the whole framework. Topscan produces the scanning and remediation part of that evidence. We use Drata ourselves for our own SOC 2 audit.
For every scan: the date, the target, the vulnerabilities found, their severity, the affected assets and URLs, the remediation status and deadline, and the changes to that status over time.
Invite them to a free read-only seat and they read the record themselves. If they would rather have a document, the history exports as PDF or CSV.
Often, yes — and this isn't one. A pentest is a deep look on one day; this is a shallow look every day plus the record of it. Most audit scopes reference both.
Customer data is stored in the Hetzner cloud in Ashburn, Virginia, US. None of the developers have access to the production environment — only the Head of DevOps does, and every action he takes is logged. No customer data leaves our infrastructure or is passed to third-party systems, including third-party AI services: everything happens inside a closed environment. We are currently going through a SOC 2 audit and track our processes in Drata. If you delete your account, all data is permanently removed from our servers within 180 days.

Start the record today, not the week before the audit

Add one domain. Everything after that is kept with a date on it.

14 days of the full Advanced plan · no card required