# Fluid Attacks Documentation > Fluid Attacks is a cybersecurity company that offers continuous security > testing (SAST, DAST, SCA, CSPM, pentesting) across the entire SDLC. > IMPORTANT: The links below end in `.md` and return raw Markdown content. - Quick start - [Quick start](/quick-start.md): Learn how to sign up and set up your first project to start testing. - Get ready - [Sign up](/quick-start/get-ready/sign-up.md): Follow the steps to create your account on the Fluid Attacks platform and begin your free trial of automated security testing. - [Import repositories](/quick-start/get-ready/import-repositories.md): Learn to import Git repositories on the Fluid Attacks platform manually or using Open Authorization to start security testing. - [Invite team](/quick-start/get-ready/invite-team.md): Learn to invite team members to sign up on the Fluid Attacks platform so they can be assigned vulnerability remediation work. - See vulnerabilities - [Explore details](/quick-start/see-vulnerabilities/explore-details.md): View details of the results of scans and other security tests on Fluid Attacks' platform. - [Define assignees](/quick-start/see-vulnerabilities/define-assignees.md): Assign vulnerability remediation work to members of your team on the Fluid Attacks platform. - Fix code - [With AI](/quick-start/fix-code/with-ai.md): See the steps to get AI-generated fix suggestions and fix code automatically on the Fluid Attacks IDE plugin. - [Update dependencies](/quick-start/fix-code/update-dependencies.md): Know what dependency version you should upgrade to on the Fluid Attacks platform. - [Expert help](/quick-start/fix-code/expert-help.md): See the steps to request explanatory sessions with pentesters on the Fluid Attacks platform. The explanation may come through comments or video meetings. - Verify fixes - [Reattack](/quick-start/verify-fixes/reattack.md): Fluid Attacks retests your application both through scans and manually to verify your code fix. - [CI Gate installation](/quick-start/verify-fixes/ci-gate-installation.md): Installation of the Fluid Attacks CI Gate, an automated measure to secure your software development lifecycle. - [Break the build](/quick-start/verify-fixes/break-the-build.md): Fluid Attacks offers a tool to make your pipeline fail automatically if deploying a vulnerable build that does not comply with your policies. - FAQ - [Platform FAQ](/quick-start/faq/platform.md): Get answers to frequently asked questions about the Fluid Attacks platform. - [Scanners FAQ](/quick-start/faq/scanners.md): Get answers to frequently asked questions about Fluid Attacks' AppSec testing tools when used as standalone vulnerability scanners. - [Integrations FAQ](/quick-start/faq/integrations.md): Get answers to frequently asked questions about Fluid Attacks' API and plugin, especially privacy concerns regarding the features powered by Claude Sonnet. - [Billing FAQ](/quick-start/faq/billing.md): Find here the answers to the most frequently asked questions about the active authors in projects with Fluid Attacks and the billing of their work. - Basics - [Glossary](/quick-start/basics/glossary.md): This glossary provides definitions for common application security concepts and terms specific to Fluid Attacks products used in its documentation or elsewhere. - [CVSSF metric](/quick-start/basics/cvssf-metric.md): Find out the CVSSF metric of Fluid Attacks, why it was created, and how it can be helpful in your company's risk exposure management. - [What is SAST?](/quick-start/basics/what-is-sast.md): Identify source code vulnerabilities early with the Fluid Attacks SAST tool, which is recommended by the CASA framework and has a perfect OWASP Benchmark score. - [What is SCA?](/quick-start/basics/what-is-sca.md): The Fluid Attacks scanner does software composition analysis, SCA, a technique for detecting open-source packages with security vulnerabilities in applications. - [What is DAST?](/quick-start/basics/what-is-dast.md): The Fluid Attacks scanner performs dynamic application security testing, DAST, a technique for detecting security vulnerabilities in running applications. - [What is CSPM?](/quick-start/basics/what-is-cspm.md): Fluid Attacks' CSPM scanner detects misconfigurations and security issues in cloud environments, IaC scripts, and container images through automated cloud security posture management. - [SAST vs. Secret Scanning](/quick-start/basics/sast-vs-secret-scanning.md): Learn about the differences and similarities between SAST and Secret Scanning techniques and how Fluid Attacks implements them. - [Tutorial videos](/quick-start/basics/tutorial-videos.md): Watch tutorial videos to learn to use the Fluid Attacks platform and CI Agent for vulnerability management in favor of the security of your applications. - [Platform demo](/quick-start/basics/platform-demo.md): Request a demo to learn about the capabilities of the Fluid Attacks platform. - [Methodology](/quick-start/basics/methodology.md): Secure your software with the Fluid Attacks AI-powered testing, expert pentesting, and seamless integration throughout the SDLC. - [PoV](/quick-start/basics/pov.md): Learn about the scope, requirements, and workflow of the Proof of Value (a replacement for the PoC) of Fluid Attacks' Advanced plan. - [Plans and free trial](/quick-start/basics/plans-free-trial.md): Learn about the capabilities, plans and free trial of the Fluid Attacks' solution. - [Billing](/quick-start/basics/billing.md): Learn about Fluid Attacks' billing model for the solution, including details on author identification. - [Main website](/quick-start/basics/main-website.md): Visit the Fluid Attacks website to discover AppSec solutions, learn about security advisories, read blog posts, and more. - [Onboarding sessions](/quick-start/onboarding-sessions.md): Request free onboarding sessions with our education specialists to better understand our platform and improve your vulnerability management. - Find and fix - [Find and fix](/find-fix.md): Learn how vulnerabilities are detected, prioritized, and fixed. - Use the platform - [Use the platform](/find-fix/use-platform.md) - Access and navigation - [Sign-up and login](/find-fix/use-platform/access-navigation/sign-up-and-login.md): Sign-up and login requirements for the Fluid Attacks platform. - [Interface and sections](/find-fix/use-platform/access-navigation/interface-and-sections.md): See the functions of the Fluid Attacks platform’s sections as well as of its header items. - Manage org and groups - [Groups section](/find-fix/use-platform/manage-org-and-groups/groups-section.md): Navigate the Groups section on the Fluid Attacks platform to create groups, learn the status of a group and more. - [Group configuration](/find-fix/use-platform/manage-org-and-groups/group-configuration.md): The Information section provides details about a company and its corresponding group. - [Create and delete groups](/find-fix/use-platform/manage-org-and-groups/create-and-delete-groups.md): Steps to create a group on the Fluid Attacks platform or delete it. - [Create another organization](/find-fix/use-platform/manage-org-and-groups/create-another-organization.md): Learn how to create and manage multiple organizations within the Fluid Attacks platform to organize the projects of your enterprises. - [Portfolios](/find-fix/use-platform/manage-org-and-groups/portfolios.md): The Portfolios section on the Fluid Attacks platform enables users to compare analytics information across different groups within the same organization. - [Register payment information](/find-fix/use-platform/manage-org-and-groups/register-payment-method.md): Learn to register payment information of your subscription on the Fluid Attacks platform. - Manage members and roles - [Members](/find-fix/use-platform/manage-members-and-roles/members.md): Efficiently manage organization and group members on the Fluid Attacks platform, including invitations, role assignments, and removals. - [Understand roles](/find-fix/use-platform/manage-members-and-roles/understand-roles.md): Explanation of user roles and permissions on the Fluid Attacks platform for clients. - [Group-level authors](/find-fix/use-platform/manage-members-and-roles/group-level-authors.md): Learn how to view, filter, and manage authors (contributing developers) on the Fluid Attacks platform to enhance collaboration quality and security. - [Organization-level authors](/find-fix/use-platform/manage-members-and-roles/organization-level-authors.md): Efficiently manage the organization mailmap in the Authors section to keep all contributor information orderly on the Fluid Attacks platform. - Manage assets to test - [Repositories](/find-fix/use-platform/manage-assets-to-test/repositories.md): Efficiently manage Git repositories, IP Roots, and URL Roots for comprehensive security testing with Fluid Attacks. Add, edit, and exclude repos to tailor your scope. - [Import repositories with OAuth](/find-fix/use-platform/manage-assets-to-test/import-repositories-with-oauth.md): Learn to import Git repositories on the Fluid Attacks platform using Open Authorization to start security testing. - [Repositories out of scope](/find-fix/use-platform/manage-assets-to-test/repositories-out-of-scope.md): View repositories retrieved via OAuth that are not yet associated with any group on the Fluid Attacks platform and outside the scope of security testing. - [ToE and SBOM](/find-fix/use-platform/manage-assets-to-test/target-of-evaluation-and-sbom.md): The Fluid Attacks platform has detailed information about the attack surface of your software, showing the status of assets and allowing you to generate SBOMs. - [Manage your credentials](/find-fix/use-platform/manage-assets-to-test/credentials.md): Manage organization credentials and OAuth connections that give Fluid Attacks access to repositories to start security testing. - [Environments](/find-fix/use-platform/manage-assets-to-test/environments.md): Manage production and pre-production environments for comprehensive security testing with Fluid Attacks. Add, edit, and exclude them to tailor your scope. - [Resolve events](/find-fix/use-platform/manage-assets-to-test/resolve-events.md): The Events section in the Fluid Attacks platform keeps a record of solved and unsolved events within a group, which are situations impeding security testing. - Manage vulnerabilities - [Vulnerabilities section guide](/find-fix/use-platform/manage-vulnerabilities/vulnerabilities-section-guide.md): See information about reported vulnerabilities, like description, severity, vulnerable code, treatments, and fix recommendations on the Fluid Attacks platform. - [Examine evidence](/find-fix/use-platform/manage-vulnerabilities/examine-evidence.md): In the Evidence section of the platform, Fluid Attacks provides supporting proof of the existence and exploitation of the corresponding type of vulnerability. - [Supply chain analysis](/find-fix/use-platform/manage-vulnerabilities/supply-chain-analysis.md): The Fluid Attacks platform allows you to track the security of software dependencies in your app, learn the reachability analysis results and download SBOMs. - [Reachability analysis](/find-fix/use-platform/manage-vulnerabilities/dependency-reachability-analysis.md): Fluid Attacks identifies your supply chain and helps you find reachable vulnerabilities in your code. - [Vulnerability signature update](/find-fix/use-platform/manage-vulnerabilities/vulnerability-signature-update.md): Learn about the Fluid Attacks vulnerability signature management for software composition analysis SCA scans. - [CVSS score adjustment](/find-fix/use-platform/manage-vulnerabilities/cvss-score-adjustment.md): Learn why the severity scores of vulnerabilities found by SCA are lower in the Fluid Attacks than in external sources like the NIST NVD. - [Correlate threat models](/find-fix/use-platform/manage-vulnerabilities/correlate-threat-models.md): Discover the correlation between your threat model and vulnerabilities reported by Fluid Attacks. Then, prioritize remediation based on your business risks. - [Assign treatments](/find-fix/use-platform/manage-vulnerabilities/assign-treatments.md): The Treatments section in the Fluid Attacks platform allows you to define business decisions concerning vulnerabilities, including assigning fix work to users. - [Assigned to you](/find-fix/use-platform/manage-vulnerabilities/assigned-to-you.md): The To do section on the Fluid Attacks platform enables users to visualize vulnerabilities assigned to them, change treatments and request reattacks. - [Verify fixes with reattacks](/find-fix/use-platform/manage-vulnerabilities/verify-fixes-with-reattacks.md): Request reattacks on the Fluid Attacks platform to test the success of fixes addressing vulnerabilities. Understand reattack outcomes and troubleshoot errors. - [False positive requests](/find-fix/use-platform/manage-vulnerabilities/false-positive-requests.md): Fluid Attacks lets you assign a Treatment called False positive request to reported vulnerabilities on the platform that you think are FPs or pose no threat. - Help options - [Help options](/find-fix/use-platform/help-options.md) - [AI Agent](/find-fix/use-platform/help-options/ask-ai-agent.md): Learn to use the Fluid Attacks AI Agent to query the platform using natural language. - [Live chat](/find-fix/use-platform/help-options/ask-via-chat.md): Get instant support via Live chat or leave a detailed message for prompt assistance on the Fluid Attacks platform. - [Email](/find-fix/use-platform/help-options/send-email.md): Need assistance? Contact Fluid Attacks support via email. Find this and other help options on the platform. - [Post comments](/find-fix/use-platform/help-options/post-comments.md): Reach out to Fluid Attacks through the platform for discussions, questions or requests related to your group, specific vulnerabilities or events. - [Talk to a Pentester](/find-fix/use-platform/help-options/talk-to-a-pentester.md): Use the Talk to a Pentester feature on the Fluid Attacks platform if you need guidance to understand complex reported vulnerabilities that you need to remediate. - [Tutorial videos or demo](/find-fix/use-platform/help-options/tutorial-videos-or-demo.md): Learn how to use the Fluid Attacks platform effectively with free, certifiable tutorials and live demos covering key product features and functionalities. - Get analytics and reports - [Vulnerability reporting](/find-fix/use-platform/get-analytics-and-reports/vulnerability-reporting.md): Request to download vulnerability reports on the Fluid Attacks platform. - [Standard compliance](/find-fix/use-platform/get-analytics-and-reports/standard-compliance.md): The Compliance section on the platform shows the compliance of your software with the standards validated by Fluid Attacks at the organization and group level. - [ZTNA logs](/find-fix/use-platform/get-analytics-and-reports/ztna-logs.md): Steps to view and download the HTTP, network and session logs on the Fluid Attacks platform when you have zero trust network access (ZTNA) implemented. - [Recent downloads](/find-fix/use-platform/get-analytics-and-reports/recent-downloads.md): Learn to view the download progress and access recently requested reports on the Fluid Attacks platform. - [Common analytics](/find-fix/use-platform/get-analytics-and-reports/common-analytics.md): The Fluid Attacks platform provides shared analytics across the organization, groups and portfolios for actionable insights into your security posture. - [Organization analytics](/find-fix/use-platform/get-analytics-and-reports/organization-analytics.md): Consult analytics on the Fluid Attacks platform to gain insights into the status of vulnerabilities and remediation practices of your organization. - [Group analytics](/find-fix/use-platform/get-analytics-and-reports/group-analytics.md): Consult analytics on the Fluid Attacks platform to gain insights into the status of vulnerabilities and remediation practices of your group. - [Portfolio analytics](/find-fix/use-platform/get-analytics-and-reports/portfolio-analytics.md): Gain insights into the security posture of your portfolios on the Fluid Attacks platform through detailed analytics. - [Chart options](/find-fix/use-platform/get-analytics-and-reports/chart-options.md): Analytics on the Fluid Attacks platform include interactive charts with the options to apply filters, get chart information and download, among other. - Manage policies - [CI Gate configuration](/find-fix/use-platform/manage-policies/ci-gate-configuration.md): Generate, update or reset the Fluid Attacks Group token used to fail your pipeline if deploying a build in noncompliance with your policies. - [CI Gate executions](/find-fix/use-platform/manage-policies/ci-gate-executions.md): View the execution details of the Fluid Attacks CI Gate, the security measure that acts as a security gate in CI/CD environments and breaks the build. - [Security gates](/find-fix/use-platform/manage-policies/security-gates.md): The Policies section allows organizations to establish various security gates for vulnerability acceptance and member access control. - [Vulnerability acceptance](/find-fix/use-platform/manage-policies/vulnerability-acceptance.md): The Fluid Attacks platform offers setting policies to accept vulnerabilities permanently or temporarily within its risk management features. - [Prioritization attributes](/find-fix/use-platform/manage-policies/vulnerability-prioritization-attributes.md): Learn to set organization policies on the Fluid Attacks platform to prioritize vulnerabilities for fixing. - Manage user settings - [Explore the user menu](/find-fix/use-platform/manage-user-settings/explore-menu.md): Access the options to manage notifications, get an API token, delete your account, etc., in the user menu on the Fluid Attacks platform. - [Notifications](/find-fix/use-platform/manage-user-settings/enable-disable-notifications.md): Understand the notification system of the Fluid Attacks platform and learn to enable and disable emails. - [Subscribe to News](/find-fix/use-platform/manage-user-settings/subscribe-to-news.md): Subscribe to news about the Fluid Attacks platform and other products via the website or platform to get updates about the latest features and enhancements. - Use the CLI - Overview - [Fluid Attacks' scanners](/find-fix/use-cli/overview/fluid-attacks-scanners.md): Learn about the Fluid Attacks scanners designed to perform SAST, DAST, SCA, CSPM, and MAST security analysis. - [OWASP Benchmark results](/find-fix/use-cli/overview/scanner-results-owasp-benchmark.md): Know about the Fluid Attacks scanner true positive rate of 100 on the OWASP Benchmark. A guide is included to reproduce the results in vulnerability detection. - Authentication - [Authentication](/find-fix/use-cli/authentication.md): Authenticate Fluid Attacks CLI scans: sign in through your browser for runs on your own machine, or authenticate pipelines as a group with OpenID Connect or a Group token. - [Browser login](/find-fix/use-cli/authentication/browser-login.md): Sign in to the Fluid Attacks CLI through your browser, so scans on your own machine are attributed to you without storing a long-lived token. - [OIDC federation](/find-fix/use-cli/authentication/oidc-federation.md): Set up token-less OpenID Connect (OIDC) federation so your CI/CD pipelines authenticate to Fluid Attacks without a stored secret. - Use the scanners - [Use the scanners](/find-fix/use-cli/use-scanners.md): Configure and run Fluid Attacks' scanners for vulnerability scanning in your code, apps, and infrastructure. - Docker - [Docker](/find-fix/use-cli/use-scanners/docker.md): Run Fluid Attacks' security scanners using Docker containers, locally or in any CI/CD provider that supports Docker. - [Docker in CI/CD](/find-fix/use-cli/use-scanners/docker/ci-cd.md): Use Fluid Attacks' Docker-based scanners in your CI/CD pipeline with GitHub Actions, GitLab CI, Travis CI, Bitbucket Pipelines, and other providers. - [CI/CD integration](/find-fix/use-cli/use-scanners/ci-cd-integration.md): Integrate Fluid Attacks' security scanners into your CI/CD pipeline using Docker containers, GitHub Actions, or standalone binaries. - GitHub Actions - [GitHub Actions](/find-fix/use-cli/use-scanners/github-actions.md): Use Fluid Attacks' dedicated GitHub Actions for SAST, SCA, Secret Scan, DAST, and CI Gate to integrate automated security testing into your CI/CD pipeline. - [SAST action](/find-fix/use-cli/use-scanners/github-actions/sast.md): Run the Fluid Attacks SAST GitHub Action to detect source-code vulnerabilities on every push and pull request. - [SCA action](/find-fix/use-cli/use-scanners/github-actions/sca.md): Run the Fluid Attacks SCA GitHub Action to find known CVEs in your third-party dependencies on every push and pull request. - [Secret Scan action](/find-fix/use-cli/use-scanners/github-actions/ss.md): Run the Fluid Attacks SS GitHub Action to detect hardcoded secrets and credentials in your repository. - [DAST action](/find-fix/use-cli/use-scanners/github-actions/dast.md): Run the Fluid Attacks DAST GitHub Action to find vulnerabilities in your live web application on every push and pull request. - [CI Gate action](/find-fix/use-cli/use-scanners/github-actions/ci-gate.md): Run the Fluid Attacks CI Gate GitHub Action to enforce a security gate in your CI/CD pipeline based on vulnerabilities reported on the Fluid Attacks platform. - Distributed binaries - [Distributed binaries](/find-fix/use-cli/use-scanners/distributed-binaries.md): Install and run Fluid Attacks' distributed binaries for security scanning without Docker. - [ss](/find-fix/use-cli/use-scanners/distributed-binaries/ss.md): Install and run the ss binary to detect hardcoded secrets and credentials in your source code without Docker or authentication. - [cs](/find-fix/use-cli/use-scanners/distributed-binaries/cs.md): Install and run the CS binary to analyze container images without Docker or authentication. - [Understanding outputs](/find-fix/use-cli/use-scanners/understanding-outputs.md): Guide to understanding security testing reports generated by the Fluid Attacks scanner when used as a standalone tool to find vulnerabilities. - [Findings exclusion](/find-fix/use-cli/use-scanners/findings-exclusion.md): Learn about the NOFLUID functionality of the Fluid Attacks scanner as well as other methods which allow developers to exclude specific findings from reports. - Fix code with gen AI - [Automatic remediation](/find-fix/fix-code-with-gen-ai/automatic-remediation.md): Learn to use the generative AI integrated with the Fluid Attacks VS Code extension to automatically remediate some of your software security vulnerabilities. - [Custom remediation guides](/find-fix/fix-code-with-gen-ai/custom-remediation-guides.md): Learn to use the generative artificial intelligence integrated with the Fluid Attacks VS Code extension to receive specific vulnerability remediation guidance. - Fix SCA vulnerabilities - [Fix SCA vulnerabilities](/find-fix/fix-sca-vulnerabilities.md) - [In JavaScript](/find-fix/fix-sca-vulnerabilities/javascript.md): Learn the recommended strategies to remediate SCA vulnerabilities found in transitive npm and pnpm dependencies, from updating packages to using dependency overrides. - [In Python](/find-fix/fix-sca-vulnerabilities/python.md): Learn the recommended strategies to remediate SCA vulnerabilities found in transitive Python dependencies, from updating packages to using uv dependency overrides. - [In Kotlin](/find-fix/fix-sca-vulnerabilities/kotlin.md): Learn the recommended strategies to remediate SCA vulnerabilities found in transitive Kotlin Gradle dependencies, from raising a version constraint to forcing a resolution strategy. - [In Rust](/find-fix/fix-sca-vulnerabilities/rust.md): Learn the recommended strategies to remediate SCA vulnerabilities found in transitive Rust dependencies, from updating crates to patching a fork. - Prioritize files - [Introduction to Sorts](/find-fix/prioritize-files/introduction-to-sorts.md): Learn about Sorts, the Fluid Attacks AI tool for prioritizing files in your software according to their likelihood of having vulnerabilities. - [Sorts user guide](/find-fix/prioritize-files/sorts-user-guide.md): Assess file vulnerability probability with Fluid Attacks Sorts. Test your code repository or integrate Sorts into your CI/CD pipeline for automated checks. - Access to your assets - [Connection mechanisms](/find-fix/access-to-assets/connection-mechanisms.md): Fluid Attacks offers three secure connectivity options: Cloud, Egress, and Connector (ZTNA), ensuring safe access to your resources. Learn their benefits. - [Cloud connection](/find-fix/access-to-assets/cloud-connection.md): Fluid Attacks works over secure and efficient cloud connection with HTTPS and SSH encryption. Requires Internet. Supports OAuth, SSH and HTTPS authentication. - [Egress connection](/find-fix/access-to-assets/egress-connection.md): Securely connect Fluid Attacks to your resources using Egress. Configure your firewall and whitelist Fluid Attacks static IPs to allow security testing. - [Connector connection](/find-fix/access-to-assets/connector-connection.md): Securely connect Fluid Attacks to your private network for vulnerability assessments using Connector. Learn how to set up and configure ZTNA. - [Types of authentication](/find-fix/access-to-assets/types-of-authentication.md): Learn about the authentication methods Fluid Attacks may use to securely access your repositories. Get links to the steps for using OAuth, SSH, and HTTPS. - [AWS CodeCommit](/find-fix/access-to-assets/aws-codecommit.md): Create an AWS IAM role to grant Fluid Attacks cross-account access to your CodeCommit repositories using the management console or CloudFormation. - Service-level agreement - [Service-level agreement](/find-fix/service-level-agreement.md): The Fluid Attacks service-level agreement, SLA, guarantees platform availability and risk exposure discovery of at least 90 percent, and fast response times. - [Availability SLA](/find-fix/service-level-agreement/availability-sla.md): Fluid Attacks offers a platform and API availability SLA of 99.95%. Learn when this applies and how it is measured. - [Response SLA](/find-fix/service-level-agreement/response-sla.md): Fluid Attacks offers quick responses to your requests with a 90 percent response time SLA. Learn when this SLA applies and how it is measured. - [Accuracy SLA](/find-fix/service-level-agreement/accuracy-sla.md): Fluid Attacks offers accurate vulnerability analysis with a 90 percent risk exposure detection SLA. Learn when this applies and how it is measured. - [False negatives](/find-fix/service-level-agreement/false-negatives.md): Definition of false negatives and protocol to handle those that may occur during the Fluid Attacks' Advanced plan. - [False positives](/find-fix/service-level-agreement/false-positives.md): Learn the definition of false positives in cybersecurity and when Fluid Attacks accepts or rejects false positive requests for reported vulnerabilities. - [SLA scope](/find-fix/service-level-agreement/scope.md): Learn about the scope of Fluid Attacks security testing along with what is considered false negatives. - Support information - [Support information](/find-fix/support-information.md) - Changelog - [Changelog](/find-fix/support-information/changelog.md) - [2026](/find-fix/support-information/changelog/2026.md): See new features and enhancements to the Fluid Attacks platform, tools and other products. The company works always to improve its security testing capability. - [2025](/find-fix/support-information/changelog/2025.md): See new features and enhancements to the Fluid Attacks platform, tools and other products. The company works always to improve its security testing capability. - [2024](/find-fix/support-information/changelog/2024.md): See new features and enhancements to the Fluid Attacks platform, tools and other products. The company works always to improve its security testing capability. - [2023](/find-fix/support-information/changelog/2023.md): See new features and enhancements to the Fluid Attacks platform, tools and other products. The company works always to improve its security testing capability. - [Roadmap](/find-fix/support-information/roadmap.md): Check upcoming enhancements to vulnerability analysis, supply chain management, reporting, and policy centralization for improved security and efficiency. - [AI functions](/find-fix/support-information/supported-ai-functions.md): Discover the AI functions supported by Fluid Attacks to prioritize files for security testing and fix application vulnerabilities effectively. - [Attack surfaces](/find-fix/support-information/supported-attack-surfaces.md): Learn about the attack surfaces supported by the Fluid Attacks dynamic analysis and PTaaS. Fluid Attacks detects vulnerabilities in your running applications. - [Binaries](/find-fix/support-information/supported-binaries.md): Discover the binary files supported by the Fluid Attacks SAST scanner to analyze and secure your applications effectively. - [Browsers](/find-fix/support-information/supported-browsers.md): Discover the browsers supported by the Fluid Attacks platform and main website. These include Chrome, Edge, Safari, Opera and Firefox. - [CI/CD](/find-fix/support-information/supported-ci-cd.md): Discover the CI/CD integrations supported by Fluid Attacks to automate security testing in your development pipeline. - [Clouds](/find-fix/support-information/supported-cloud.md): Learn about the cloud environments that can be integrated with Fluid Attacks to perform comprehensive security scanning across your cloud infrastructure. - [Containers](/find-fix/support-information/supported-containers.md): Explore the containers supported by the Fluid Attacks scanner to detect vulnerabilities and secure your containerized applications. - [CVEs for reachability](/find-fix/support-information/supported-cves-reachability.md): CVEs for which the Fluid Attacks reachability analysis is supported. It determines if dependency vulnerabilities are exploitable in your applications. - [Evidence formats](/find-fix/support-information/supported-evidence-formats.md): Discover the evidence formats provided by Fluid Attacks to deliver comprehensive and actionable security testing findings and proof of exploitation to clients. - [Frameworks](/find-fix/support-information/supported-frameworks.md): Frameworks supported by the Fluid Attacks SAST scanner for tests that help you enhance application security and streamline secure development. - [IDEs](/find-fix/support-information/supported-ides.md): Explore the Fluid Attacks IDE extensions or plugins to enhance secure development, following DevSecOps best practices. - [Languages](/find-fix/support-information/supported-languages.md): Programming languages supported by the Fluid Attacks SAST tool. Fluid Attacks tests your source code to ensure application security during development. - [Languages for fixes](/find-fix/support-information/supported-languages-for-fixes.md): Programming languages supported by the automated vulnerability remediation capabilities of Fluid Attacks. - [Package managers](/find-fix/support-information/supported-package-managers.md): Package managers supported by the Fluid Attacks software composition analysis (SCA) scans. Fluid Attacks detects vulnerable dependencies in your application. - [Remediation](/find-fix/support-information/supported-remediation.md): Discover the options provided by Fluid Attacks which aim to help you efficiently fix security vulnerabilities. - [Runtimes](/find-fix/support-information/supported-runtimes.md): Which ecosystems get runtime CVE detection from Fluid Attacks' software composition analysis (SCA) scans, and the criterion behind why most package managers don't. - [SCM systems](/find-fix/support-information/supported-scm-systems.md): Source code management systems supported by Fluid Attacks. Fluid Attacks is committed to adaptability so that it can integrate with your existing workflows. - [Secrets](/find-fix/support-information/supported-secrets.md): Learn what secrets the Fluid Attacks scanner detects across various platforms to ensure the security of your sensitive data. - [Standards](/find-fix/support-information/supported-standards.md): Learn about the international security standards supported by Fluid Attacks to ensure compliance and enhance the security posture of your application. - [Ticketing systems](/find-fix/support-information/supported-ticketing-systems.md): Explore the ticketing systems Fluid Attacks integrates to. Use the Fluid Attacks integrations to streamline issue tracking and enhance your security workflow. - [Documentation sections](/find-fix/support-information/documentation-sections.md): Explore the documentation sections of Fluid Attacks. - Integrations - [Integrations](/integrations.md): Connect Fluid Attacks to your workflow and automate security testing. - Bug-tracking systems - [Bug-tracking systems](/integrations/bug-tracking-systems.md): Compare Fluid Attacks integrations with Jira Cloud, Azure DevOps, and GitLab for vulnerability issue creation and reattack requests. - [Azure DevOps](/integrations/bug-tracking-systems/azure-devops.md): Use the integration to create Azure DevOps issues from the Fluid Attacks platform. - [GitLab](/integrations/bug-tracking-systems/gitlab.md): Use the GitLab integration to automatically create issues from vulnerabilities reported on the Fluid Attacks platform. - Jira - [Install app for Jira](/integrations/bug-tracking-systems/jira/install.md): Install the Fluid Attacks app for Jira Cloud to manage reported vulnerabilities from Jira, create Jira issues from the platform, request reattacks and more. - [App setup](/integrations/bug-tracking-systems/jira/setup.md): Set up the Fluid Attacks Jira integration to manage reported vulnerabilities from Jira, create Jira issues from the platform, request reattacks and more. - [Issue creation](/integrations/bug-tracking-systems/jira/issue-creation.md): Learn about the integration feature to create Jira issues for vulnerabilities reported by Fluid Attacks. - [Automatic issue creation](/integrations/bug-tracking-systems/jira/automatic-issue-creation.md): Configure Jira Cloud to automatically create issues for vulnerabilities reported on the Fluid Attacks platform. - [Link vulnerabilities](/integrations/bug-tracking-systems/jira/link-vulnerabilities.md): Learn about the integration feature to link vulnerabilities reported by Fluid Attacks to Jira issues and unlink them. - [Vulnerability details in Jira](/integrations/bug-tracking-systems/jira/vulnerability-details.md): Use this Jira integration feature to access from an issue to the links to see evidence, locations and more details of vulnerabilities found by Fluid Attacks. - [Request reattacks](/integrations/bug-tracking-systems/jira/request-reattacks.md): Learn about the integration feature to request reattacks by Fluid Attacks from a Jira issue to verify that the fix to a software vulnerability was successful. - [App help options](/integrations/bug-tracking-systems/jira/help-options.md): Use this Jira integration feature to access from an issue to the links to request help sessions with Fluid Attacks' ethical pentesters and create tickets. - [Export issues to Excel](/integrations/bug-tracking-systems/jira/export-issues-to-excel.md): Learn why Microsoft Excel does not properly render line breaks when importing a CSV file exported from Jira, and how to work around this limitation. - IDE extensions - [IDE extensions](/integrations/ide-extensions.md): Compare Fluid Attacks' IDE extensions for Cursor, VS Code, and IntelliJ IDEA. See which features are supported across platforms to manage your vulnerabilities. - Cursor - [Installation](/integrations/ide-extensions/cursor/install.md): Learn how to download, install, and configure the Fluid Attacks IDE extension for Cursor, whose features enable enhanced vulnerability management. - [Vulnerability management](/integrations/ide-extensions/cursor/vulnerability-management.md): Use the Fluid Attacks Cursor extension to view vulnerable code, apply treatments, request reattacks, and fix code directly in your IDE. - IntelliJ IDEA - [Installation](/integrations/ide-extensions/intellij-idea/install.md): Identify the location of code vulnerabilities directly on IntelliJ IDEA using the Fluid Attacks plugin. - [Vulnerability management](/integrations/ide-extensions/intellij-idea/vulnerability-management.md): Use the Fluid Attacks IntelliJ IDEA plugin to view vulnerable code and fix code directly in your IDE. - [Troubleshooting](/integrations/ide-extensions/intellij-idea/troubleshooting.md): Troubleshoot common issues and errors with the Fluid Attacks IntelliJ plugin. This guide provides step-by-step solutions for SSL certificate and connectivity problems. - VS Code - [VS Code](/integrations/ide-extensions/vscode.md): Learn how to download, install, and configure the Fluid Attacks IDE extension for Visual Studio Code, whose features enable enhanced vulnerability management. - [Installation](/integrations/ide-extensions/vscode/install.md): Learn how to download, install, and configure the Fluid Attacks IDE extension for Visual Studio Code, whose features enable enhanced vulnerability management. - [Functions](/integrations/ide-extensions/vscode/functions.md): Use the Fluid Attacks VS Code extension to view vulnerable code, apply treatments, request reattacks, and fix code directly in your IDE. - [Troubleshooting](/integrations/ide-extensions/vscode/troubleshooting.md): Troubleshoot common issues and errors with the Fluid Attacks VS Code extension. This guide provides step-by-step solutions to get you back on track. - MCP server - [Introduction to the MCP server](/integrations/mcp-server.md): Get an introduction to our Model Context Protocol, its capabilities, purpose, and usage examples. - [Installation](/integrations/mcp-server/installation.md): Integrate the Fluid Attacks MCP server to use natural language queries in AI tools (examples in Claude, Cursor, VS Code, and Windsurf). Also, integrate our scanners into your SDLC using AI agents. - [Capabilities and use cases](/integrations/mcp-server/capabilities-and-use-cases.md): Complete reference for Fluid Attacks MCP tools — analytics, vulnerability management, asset discovery, security scanning, DevSecOps, and knowledge base capabilities. - Peer Reviewer Assistant - [Peer Reviewer Assistant](/integrations/peer-reviewer-assistant.md): Automatically scan pull requests and merge requests and get comments on the security of contributions to help peer reviewers assess them faster. - [GitLab Peer Reviewer Assistant](/integrations/peer-reviewer-assistant/integrate-with-gitlab.md): Set up the Fluid Attacks Peer Reviewer Assistant for GitLab to get automated vulnerability scanning and comments on merge requests. - [Azure DevOps Peer Reviewer Assistant](/integrations/peer-reviewer-assistant/integrate-with-azure-devops.md): Set up the Fluid Attacks Peer Reviewer Assistant for Azure DevOps to get automated vulnerability scanning and comments on pull requests. - [GitHub Peer Reviewer Assistant](/integrations/peer-reviewer-assistant/integrate-with-github.md): Set up the Fluid Attacks Peer Reviewer Assistant for GitHub to get automated vulnerability scanning and comments on pull requests. - [Functionality](/integrations/peer-reviewer-assistant/functionality.md): Learn how the Peer Reviewer Assistant analyzes code changes in pull requests and merge requests, reports security vulnerabilities as inline comments, and validates remediations. - [Troubleshooting](/integrations/peer-reviewer-assistant/troubleshooting.md): Fix common Peer Reviewer Assistant issues on GitLab including integrations not working after setup and token expiration after six months. - [File exclusion](/integrations/peer-reviewer-assistant/file-exclusion.md): Exclude files and directories from Peer Reviewer Assistant scans using pattern matching similar to gitignore. - Use a configuration file - [Use a configuration file](/integrations/use-configuration-file.md): Learn to use configuration files for vulnerability scans with the Fluid Attacks scanners. Fluid Attacks offers SAST, SCA, DAST, CSPM and MAST security analysis. - [MAST scanner](/integrations/use-configuration-file/apk-scanner.md): Learn to configure the scans of the Fluid Attacks MAST scanner. - [Container scanner](/integrations/use-configuration-file/containers-scanner.md): Learn to configure the scans of the Fluid Attacks CS scanner. - [CSPM scanner](/integrations/use-configuration-file/cspm-scanner.md): Learn to configure the scans of the Fluid Attacks CSPM scanner. - [DAST scanner](/integrations/use-configuration-file/dast-scanner.md): Learn to configure the scans of the Fluid Attacks DAST scanner. - [SAST scanner](/integrations/use-configuration-file/sast-scanner.md): Learn to configure the scans of the Fluid Attacks SAST scanner. - [SCA scanner](/integrations/use-configuration-file/sca-scanner.md): Learn to configure the scans of the Fluid Attacks SCA scanner. - [Secrets scanner](/integrations/use-configuration-file/secrets-scanner.md): Learn to configure the scans of the Fluid Attacks secrets scanner. - Platform API - [Platform API](/integrations/use-the-api.md): Advice for GraphQL newbies before using the Fluid Attacks API, including examples of retrieving role and group membership information to begin exploring it. - [API basics](/integrations/use-the-api/learn-basics.md): Learn how to authenticate to the Fluid Attacks GraphQL API, query it, and optimize your interactions with it. Includes code examples and best practices. - [Webhooks](/integrations/webhooks.md): This comprehensive guide explains the steps to configure and manage webhooks to get notified of events happening in a group on the Fluid Attacks platform. - Stack - [Stack](/stack.md): Get an introduction to the Stack section, where you can find information about the technology components chosen and used by the Fluid Attacks team. - Languages - [Bash](/stack/languages/bash.md): Learn about Bash, the main shell at Fluid Attacks. - [Python](/stack/languages/python.md): Learn about Python, the main back-end programming language at Fluid Attacks. - [Rust](/stack/languages/rust.md): Learn about Rust, the language for low level components at Fluid Attacks. - [Terraform](/stack/languages/terraform.md): Learn about Terraform, the tool Fluid Attacks chose for writing the entire infrastructure stack as code. - [TypeScript](/stack/languages/typescript.md): Learn about TypeScript, the main frontend programming language at Fluid Attacks. - Dependencies - [Ariadne](/stack/dependencies/ariadne.md): Learn about Ariadne, The main library Fluid Attacks uses for building its API. - [Commitlint](/stack/dependencies/commitlint.md): Learn about Commitlint, the tool chosen by Fluid Attacks for standardizing and validating commit messages through CI/CD tests. - [D3](/stack/dependencies/d3.md): Learn about D3.js and Billboard.js, the libraries Fluid Attacks uses for rendering analytics in its Platform. - [Dependency licenses](/stack/dependencies/dependency-licenses.md): Learn which third-party dependency licenses Fluid Attacks accepts across its components, why the boundary sits where it does, and how it is enforced. - [Docker](/stack/dependencies/docker.md): Learn about Docker, the containerization tool used by Fluid Attacks. - [ESLint](/stack/dependencies/eslint.md): Learn about ESLint, the TypeScript static linter used by Fluid Attacks. - [GPUI](/stack/dependencies/gpui.md): Learn about GPUI, the desktop UI technology Fluid Attacks uses to build native applications in its Rust-first stack. - [GraphQL](/stack/dependencies/graphql.md): Learn about GraphQL, the query language Fluid Attacks uses for its API. - [Hypercorn](/stack/dependencies/hypercorn.md): Learn about Hypercorn, the web-server used by Fluid Attacks' Platform. - [Kubernetes](/stack/dependencies/kubernetes.md): Learn about Kubernetes, the system chosen by Fluid Attacks for hosting, deploying, and managing applications. - [Labels](/stack/dependencies/labels.md): Learn about Labels, the product Fluid Attacks uses for building SBOMs. - [Mypy](/stack/dependencies/mypy.md): Learn about Mypy, the Python static type checking tool used by Fluid Attacks. - [Nix Flakes](/stack/dependencies/nix-flakes.md): Learn about Nix Flakes, Fluid Attacks' build system. - [Platform audit logs](/stack/dependencies/platform-audit-logs.md): Learn about how the Fluid Attacks platform performs audit logging flows. - [Platform authentication](/stack/dependencies/platform-authentication.md): Learn about how the Fluid Attacks platform performs authentication flows. - [Platform authorization](/stack/dependencies/platform-authorization.md): Learn about how the Fluid Attacks platform performs authorization flows. - [Platform integrations](/stack/dependencies/platform-integrations.md): Learn about how the Fluid Attacks platform integrates with third-party providers such as GitHub. - [Public hosting](/stack/dependencies/public-hosting.md): Learn about how Fluid Attacks serves every public HTTPS endpoint at *.fluidattacks.com, fronted by Cloudflare and Amazon CloudFront with Origin Access Control over either Amazon S3 or AWS Lambda. - [Pydantic AI](/stack/dependencies/pydantic-ai.md): Learn why Fluid Attacks chose Pydantic AI to develop its AI-MCP agent. - [Pydantic](/stack/dependencies/pydantic.md): Learn about Pydantic, the data validation library used across Fluid Attacks' Python components. - [React](/stack/dependencies/react.md): Learn about React, the main front-end library used by Fluid Attacks. - [Ruff](/stack/dependencies/ruff.md): Learn about Ruff, the Python linter used by Fluid Attacks. - [Sops](/stack/dependencies/sops.md): Learn about Sops, the tool chosen by Fluid Attacks for managing organizational secrets. - [Starlette](/stack/dependencies/starlette.md): Learn about Starlette, the backend framework Fluid Attacks uses for its Platform. - [Timestamp format](/stack/dependencies/timestamp-format.md): Learn about the canonical timestamp format used by Fluid Attacks across logs, databases, and APIs. - [Tree-sitter](/stack/dependencies/tree-sitter.md): Learn about Tree-sitter, The main library Fluid Attacks uses for Static Application Security Testing (SAST) - [Visual Studio Code](/stack/dependencies/visual-studio-code.md): Learn about Visual Studio Code, the code editor used by Fluid Attacks' engineering team. - Services - [AWS](/stack/services/aws.md): Learn about AWS, the primary Infrastructure as a Service (IaaS) provider chosen by Fluid Attacks. - [Batch](/stack/services/aws-batch.md): Learn about Batch, an AWS service employed by Fluid Attacks to execute batch processing tasks in the cloud. - [Bedrock](/stack/services/amazon-bedrock.md): Learn about Amazon Bedrock, the tool chosen by Fluid Attacks as main point of contact while interacting with LLMs. - [BigCodeBench](/stack/services/bigcodebench.md): Fluid Attacks uses BigCodeBench to define the best model to use in the features that suggest vulnerability fixes within the platform and VS Code extension. - [BugSnag](/stack/services/bugsnag.md): Learn about BugSnag, the error tracking platform chosen to be used at Fluid Attacks. - [Checkly](/stack/services/checkly.md): Learn about Checkly, a monitoring-as-code tool employed by Fluid Attacks to test its product's health. - [Cloudflare](/stack/services/cloudflare.md): Learn about Cloudflare, a Software as a Service provider employed by Fluid Attacks for various infrastructure solutions. - [CloudFront](/stack/services/amazon-cloudfront.md): Learn about CloudFront, an AWS service employed by Fluid Attacks as the origin-side content delivery network in front of every public HTTPS endpoint. - [CloudWatch](/stack/services/amazon-cloudwatch.md): Learn about CloudWatch, an AWS service employed by Fluid Attacks to monitor its entire cloud infrastructure. - [Cost Management](/stack/services/aws-cost-management.md): Learn about Cost Management, an AWS service employed by Fluid Attacks to control and optimize its expenses. - [Datadog](/stack/services/datadog.md): Learn about Datadog, Fluid Attacks' main observability tool. - [dbt](/stack/services/dbt.md): Learn about dbt, the tool Fluid Attacks uses for data transformation, documentation, and integrated testing. - [DynamoDB](/stack/services/amazon-dynamodb.md): Learn about DynamoDB, an AWS service employed by Fluid Attacks to store business-related data in its platform. - [EBS](/stack/services/amazon-ebs.md): Learn about EBS, an AWS service employed by Fluid Attacks for block-level storage. - [EC2](/stack/services/amazon-ec2.md): Learn about EC2, an AWS service employed by Fluid Attacks for running computing machines in the cloud. - [EKS](/stack/services/amazon-eks.md): Learn about EKS, an AWS service employed by Fluid Attacks to host Kubernetes Clusters in the cloud. - [ELB](/stack/services/aws-elb.md): Learn about ELB, an AWS service employed by Fluid Attacks to expose applications to the internet. - [Engineering metrics](/stack/services/engineering-metrics.md): Learn about how Fluid Attacks implements engineering metrics. - [ePayco](/stack/services/epayco.md): Learn about ePayco, a payment service employed by Fluid Attacks to bill clients in Colombia. - [EventBridge](/stack/services/amazon-eventbridge.md): Learn about EventBridge, an AWS service employed by Fluid Attacks to route events and schedule workloads. - [GitLab](/stack/services/gitlab.md): Learn about GitLab, the primary platform for software development within Fluid Attacks. - [GitLab CI](/stack/services/gitlab-ci.md): Learn about GitLab CI, the central orchestrator for Continuous Integration and Continuous Delivery workflows within the Fluid Attacks' development cycle. - [Google Workspace](/stack/services/google-workspace.md): Learn about Google Workspace, the official collaboration tool at Fluid Attacks. - [IAM](/stack/services/aws-iam.md): Learn about IAM, an AWS service employed by Fluid Attacks to manage authentication and authorization within the AWS platform. - [Iru](/stack/services/iru.md): Learn about Iru, the official MDM and EDR system at Fluid Attacks. - [KMS](/stack/services/aws-kms.md): Learn about KMS, an AWS service employed by Fluid Attacks for secure storage and use of cryptographic keys in the cloud. - [Lambda](/stack/services/aws-lambda.md): Learn about Lambda, an AWS service employed by Fluid Attacks to run serverless functions. - [Logfire](/stack/services/logfire.md): Learn about Pydantic Logfire, the LLM and application observability tool used by Fluid Attacks for tracing AI agents, MCP tools, and LLM calls. - [Meilisearch](/stack/services/meilisearch.md): Learn about Meilisearch, the search engine used by Fluid Attacks for keyword and semantic search across its documentation. - [Okta](/stack/services/okta.md): Learn about Okta, the platform chosen by Fluid Attacks for identity and access management purposes. - [OpenAI](/stack/services/openai.md): Learn about OpenAI, the tool chosen by Fluid Attacks as point of contact while interacting with LLMs. - [OpenSearch](/stack/services/opensearch.md): Learn about OpenSearch, an open-source search engine employed by Fluid Attacks to address some licensing issues between Amazon and Elastic. - [Organizations](/stack/services/organizations.md): Learn about AWS Organizations and the decision regarding its usage at Fluid Attacks. - [QuickSight](/stack/services/quicksight.md): Learn about QuickSight, the tool Fluid Attacks uses for dashboarding and reporting. - [S3](/stack/services/amazon-s3.md): Learn about S3, an AWS service employed by Fluid Attacks for cloud file storage. - [SageMaker](/stack/services/amazon-sagemaker.md): Learn about SageMaker, an AWS service employed by Fluid Attacks to develop machine learning solutions. - [Snowflake](/stack/services/snowflake.md): Learn about Snowflake, the database Fluid Attacks uses for analytical purposes. - [Statuspage](/stack/services/statuspage.md): Learn about Statuspage, Fluid Attacks' main communication tool with users regarding the health and incidents of its products. - [Step Functions](/stack/services/aws-step-functions.md): Learn about Step Functions, an AWS service employed by Fluid Attacks to orchestrate workflow execution in the cloud. - [Stripe](/stack/services/stripe.md): Learn about Stripe, which Fluid Attacks uses to manage payments and subscriptions for its international customers. - [Treli](/stack/services/treli.md): Learn about Treli, a billing service employed by Fluid Attacks to manage subscriptions with varying monthly costs. - [Vanta](/stack/services/vanta.md): Learn about Vanta, the official compliance automation tool at Fluid Attacks. - [Voyage AI](/stack/services/voyage-ai.md): Learn about Voyage AI, the tool chosen by Fluid Attacks for embedding models. - [VPC](/stack/services/amazon-vpc.md): Learn about VPC, an AWS service employed by Fluid Attacks to host a private network in the cloud. - [VPN](/stack/services/aws-vpn.md): Learn about VPN, an AWS service employed by Fluid Attacks to host its virtual private network in the cloud. - [Zoho One](/stack/services/zoho-one.md): Learn about Zoho One, Fluid Attacks' CRM. - [Zoho Sign](/stack/services/zoho-sign.md): Learn about Zoho Sign, Fluid Attacks' digital signature solution. - [Claude Sonnet 4](/stack/services/claude-sonnet-4.md): Fluid Attacks uses Claude Sonnet 4 to create the AI-assisted remediation guides and fixes offered in the VS Code extension and the platform. - [Pentesting tools](/stack/pentesting-tools.md): Explore the Fluid Attacks arsenal of pentesting tools. Used for network scanning, exploit development, etc., these tools power manual security assessments. - Compliance - [Compliance](/compliance.md): Security measures of Fluid Attacks to protect the information of clients while performing security testing in their systems. - Authentication - [Authentication](/compliance/authentication.md) - [Authentication for clients](/compliance/authentication/clients.md): Clients authenticate on the Fluid Attacks platform using SSO with Bitbucket, Google, or Microsoft via OAuth 2.0 and JWT with no passwords stored. - [Password policy](/compliance/authentication/password-policy.md): Fluid Attacks follows a password policy covering minimum length, complexity requirements, expiration, account lockout, history, and generated password rules. - [Authentication for staff](/compliance/authentication/staff.md): Fluid Attacks staff authenticate using centralized IAM with passphrases, MFA, SAML, OAuth, biometrics, and other secure measures. - Authorization - [Authorization](/compliance/authorization.md) - [Access revocation](/compliance/authorization/access-revocation.md): Fluid Attacks follows a protocol of access revocation when employees take leave, have vacation, or leave the company. - [Authorization for clients](/compliance/authorization/clients.md): The Fluid Attacks platform has role-based access control (RBAC) at the organization and group levels for each project to protect client data. - [Employee termination](/compliance/authorization/employee-termination.md): The Fluid Attacks secure employee termination protocol covers key aspects like logical access revocation and hardware return. - [Endpoints](/compliance/authorization/endpoint-management.md): Fluid Attacks secures laptops and mobile phones with MDM, including hardening profiles, removable media restrictions, auditing, and inventory controls. - [Secret rotation](/compliance/authorization/secret-rotation.md): Fluid Attacks rotates KMS keys, JWT tokens, digital certificates, and IAM passphrases following specific cycles. - [Sessions](/compliance/authorization/session-management.md): Fluid Attacks manages user sessions with JWT, including token generation, encryption, expiration, revocation, and concurrent session handling. - [Authorization for staff](/compliance/authorization/staff.md): Fluid Attacks enforces least privilege for staff through IAM, KMS, and infrastructure-level controls to restrict access to assigned projects only. - Availability - [Availability](/compliance/availability.md) - [Distributed apps](/compliance/availability/distributed-applications.md): Fluid Attacks ensures high availability through autoscaling application clusters with distributed replicas and a global CDN for maximum speed and uptime. - [Distributed firewall](/compliance/availability/distributed-firewall.md): Fluid Attacks protects its domain with a distributed firewall that includes DDoS protection, rate limiting, anti-bot challenges, and OWASP Core Rule Set. - [Everything backed up](/compliance/availability/everything-is-backed-up.md): Fluid Attacks ensures data traceability via fully versioned data centers, 35-day point-in-time database recovery, and AWS-managed storage protection controls. - [Multiple zones](/compliance/availability/multiple-zones.md): Fluid Attacks ensures high availability by utilizing AWS global infrastructure, with primary operations in Northern Virginia and secondary ones in Ireland. - [Recovery objective](/compliance/availability/recovery-objective.md): Fluid Attacks maintains a strict recovery strategy with an RTO of 15 minutes and an RPO of 0, supported by a full backup schedule lasting up to 15 years. - Confidentiality - [Confidentiality](/compliance/confidentiality.md) - [Device (re)enrolling](/compliance/confidentiality/device-enrolling-and-re-enrolling.md): Fluid Attacks manages device security via Okta and Iru, following NIST and CIS hardening guidelines to ensure secure enrollment and remote data erasure. - [Direct hiring](/compliance/confidentiality/direct-hiring.md): Fluid Attacks hires all talent directly via indefinite-term contracts, avoiding contractors or third parties due to the nature of its business. - [Encryption at rest](/compliance/confidentiality/encryption-at-rest.md): Fluid Attacks protects sensitive data using AES-256 GCM encryption, KMS-managed secrets, and full-disk encryption (BitLocker, LUKS, FileVault) in all devices. - [Encryption in transit](/compliance/confidentiality/encryption-in-transit.md): Fluid Attacks ensures data security with TLSv1.3, HSTS, and 30-day certificate renewals, maintaining an SSL Labs A+ rating across all connections. - [Logical data separation](/compliance/confidentiality/logical-data-separation.md): Fluid Attacks enforces logical data separation between clients at both the database and application authorization layers. - [No personal gain](/compliance/confidentiality/no-personal-gain.md): Fluid Attacks prohibits the exploitation of discovered vulnerabilities for personal gain. It ensures confidentiality and integrity in all engagements. - [Personnel NDA](/compliance/confidentiality/personnel-nda.md): To ensure the security of client information, Fluid Attacks requires all new talent to sign a publicly available non-disclosure agreement (NDA). - [Secure deletion](/compliance/confidentiality/secure-deletion.md): Fluid Attacks uses AWS and MDM to securely delete data, in accordance with NIST 800-88 and ISO standards, ensuring information is unrecoverable across all company devices. - Integrity - [Integrity](/compliance/integrity.md) - [Applicant evaluation](/compliance/integrity/applicant-evaluation.md): Learn about the hiring process that Fluid Attacks conducts for its development and pentesting teams. - [Awareness](/compliance/integrity/awareness.md): Fluid Attacks promotes security awareness using EasyLlama courses that cover cyber risks, phishing, data privacy, GDPR, social engineering, and ethics. - [Certified cloud provider](/compliance/integrity/certified-cloud-provider.md): Fluid Attacks runs on AWS, a cloud provider with multiple ISO and Cloud Security Alliance certifications for secure cloud environments. - [Certified security analysts](/compliance/integrity/certified-security-analysts.md): Fluid Attacks security analysts hold industry certifications in penetration testing and security tools and are encouraged to certify further. - [Comprehensive reporting](/compliance/integrity/comprehensive-reporting.md): The expert team of Fluid Attacks conducts thorough security testing and delivers accurate findings, ensuring no vulnerabilities go unnoticed. - [Developing for integrity](/compliance/integrity/developing-for-integrity.md): Fluid Attacks development practices for integrity, including monorepo, infrastructure as code, CI/CD pipelines, trunk-based development, and peer review. - [Monitoring](/compliance/integrity/monitoring.md): Fluid Attacks monitors its infrastructure using AWS CloudWatch, GuardDuty, Inspector, and Datadog for log management, threat detection, and Cloud SIEM. - [Production data isolation](/compliance/integrity/production-data-isolation.md): Fluid Attacks prevents production data from being used for test and development environments. - [Secure emails](/compliance/integrity/secure-emails.md): Fluid Attacks secures its email domain with several protocols to help recipients verify message authenticity and prevent phishing. - [SLSA compliance](/compliance/integrity/slsa-compliance.md): Fluid Attacks meets SLSA Level 2 for supply chain integrity, covering source, build, provenance, and common requirements using GitLab CI/CD and Nix. - [Standard timezone](/compliance/integrity/standard-timezone.md): Fluid Attacks uses UTC as the standard timezone across infrastructure, applications, logs, and databases for reliable event correlation. - [Static website](/compliance/integrity/static-website.md): The Fluid Attacks website is static, serving only plain HTML files with no application server, which reduces its attack surface. - [Training plan](/compliance/integrity/training-plan.md): Fluid Attacks employees undergo secure code and code review training to develop high-quality technology and detect vulnerabilities efficiently. - Non-repudiation - [Non-repudiation](/compliance/non-repudiation.md) - [Everything as code](/compliance/non-repudiation/everything-as-code.md): Fluid Attacks manages its platform, infrastructure, documentation, and other systems as code in Git, ensuring full traceability of changes made by team members. - [Extensive logs](/compliance/non-repudiation/extensive-logs.md): Fluid Attacks maintains immutable, non-expiring logs for its platform, CI pipelines and infrastructure to ensure non-repudiation and real-time threat detection. - Privacy - [Privacy](/compliance/privacy.md) - [Data privacy policy](/compliance/privacy/data-privacy-policy.md): Fluid Attacks data privacy policy covering data subject rights, processing purposes, collection principles, and deletion. - [Data retention policy](/compliance/privacy/data-retention-policy.md): Fluid Attacks retains some data after a group is deleted from the platform and keeps its confidentiality. - [Data use policy](/compliance/privacy/data-use-policy.md) - [Email obfuscation](/compliance/privacy/email-obfuscation.md): Fluid Attacks uses email obfuscation on its websites to prevent malicious web crawlers from harvesting company email addresses. - [Time tracking](/compliance/privacy/employee-time-tracking.md): Fluid Attacks tracks employee work time and takes periodic screenshots which can be accessed only by managers for incident review. - [Manual for the NDR](/compliance/privacy/manual-for-ndr.md): Information registered by Fluid Attacks in Colombia's National Database Registry (NDR), including data controller details and data subject rights. - [Subprocessor OpenAI](/compliance/privacy/openai-subprocessor.md): Fluid Attacks uses OpenAI with Zero Data Retention enabled. Learn what data is sent, how it is processed, what security measures apply, and more. - [OTR messaging](/compliance/privacy/otr-messaging.md): Fluid Attacks uses Off-the-Record messaging with end-to-end encryption and daily chat history resets to prevent internal communications leaks. - [Polygraph tests](/compliance/privacy/polygraph-tests.md): Fluid Attacks runs regular polygraph tests on staff with access to sensitive information in its efforts to prevent confidential data disclosure. - [Project pseudonymization](/compliance/privacy/project-pseudonymization.md): Fluid Attacks assigns pseudonyms to all projects so that employees without direct access cannot identify the client behind a project in internal systems. - [Data transmission](/compliance/privacy/sensitive-data-transmission.md): Fluid Attacks transmits sensitive data to clients securely using DLP, onion routing, and watermarked reports. - [Unsubscribe email](/compliance/privacy/unsubscribe-email.md): Fluid Attacks lets users unsubscribe from commercial and informative emails to stop receiving messages, in compliance with the right to withdraw consent. - [Use of cookies](/compliance/privacy/use-of-cookies.md): Fluid Attacks handles cookies on its platform and website with a consent module following GDPR where users control which cookies are allowed in their browser. - Resilience - [Resilience](/compliance/resilience.md) - [Equipment and telecommuting](/compliance/resilience/equipment-and-telecommuting.md): Fluid Attacks provides all remote talent with job-specific hardware through Kernelship SAS and implements strict requirements to ensure secure telecommuting. - [Everything is decentralized](/compliance/resilience/everything-is-decentralized.md): Fluid Attacks uses decentralized, multi-region data centers (without requiring local networks) and SSO-authenticated Wi-Fi with WPA2-AES encryption. - [Regenerative infrastructure](/compliance/resilience/regenerative-infrastructure.md): Fluid Attacks ensures resilience through regenerative infrastructure and an "everything as code" approach, redeploying and testing its own systems daily. - [Role coverage](/compliance/resilience/role-coverage.md): Fluid Attacks ensures operational continuity by maintaining at least two people per role, preventing service gaps during talent absences or emergencies. - Transparency - [Transparency](/compliance/transparency.md) - [Complaint management](/compliance/transparency/complaint-management.md): Fluid Attacks manages client complaints, ensuring structured investigation, clear resolution timelines, and a defined escalation matrix for accountability. - [Data leakage policy](/compliance/transparency/data-leakage-policy.md): Fluid Attacks notifies affected parties when a data breach is detected, including what was compromised, when, and for how long. - [Ethics hotline](/compliance/transparency/ethics-hotline.md): Fluid Attacks' employees or external parties can create, submit, and keep track cases such as anonymous complaints in our ethics hotline. - [Help channel](/compliance/transparency/help-channel.md): Fluid Attacks' Help channel manages client and internal inquiries, developer access requests, and role changes, with confidential handling and priority SLAs. - [Incident management](/compliance/transparency/incident-management.md): Fluid Attacks follows a structured incident response plan, utilizing an Incident Desk for rapid resolution and publishing detailed postmortems for transparency. - [Information security responsibility](/compliance/transparency/information-security-responsibility.md): Fluid Attacks assigns information security responsibility to the CTO, who defines and enforces policies to protect customer and company data. - [Quality policy](/compliance/transparency/quality-policy.md): Discover the Fluid Attacks Quality policy, driving secure software development through customer focus, expert teams, accurate testing, and clear SLAs. - [Status page](/compliance/transparency/status-page.md): Fluid Attacks provides monitoring and public incident reports via its Status page, offering full transparency on uptime, root causes, and preventive measures. - [Testing our technology](/compliance/transparency/testing-our-technology.md): Fluid Attacks tests its own technology to ensure the security of its solution. - [Vulnerability releasing](/compliance/transparency/vulnerability-releasing.md): Learn about the thoroughness with which Fluid Attacks handles vulnerability reports. - Compare - [Compare](/compare.md): Compare Fluid Attacks with other security testing solutions and see how we stand out. - [42Crunch](/compare/42crunch.md): Compare security testing capabilities between the solutions of Fluid Attacks and 42Crunch. - [7 Way Security](/compare/7-way-security.md): Compare security testing capabilities between the solutions of Fluid Attacks and 7 Way Security. - [ACID](/compare/acid.md): Compare security testing capabilities between the solutions of Fluid Attacks and ACID. - [Aikido](/compare/aikido.md): Compare security testing capabilities between the solutions of Fluid Attacks and Aikido. - [Aisle](/compare/aisle.md): Compare security testing capabilities between the solutions of Fluid Attacks and Aisle. - [Akto](/compare/akto.md): Compare security testing capabilities between the solutions of Fluid Attacks and Akto. - [Anchore](/compare/anchore.md): Compare security testing capabilities between the solutions of Fluid Attacks and Anchore. - [Anvil Secure](/compare/anvil-secure.md): Compare security testing capabilities between the solutions of Fluid Attacks and Anvil Secure. - [Apiiro](/compare/apiiro.md): Compare security testing capabilities between the solutions of Fluid Attacks and Apiiro. - [AppCheck](/compare/appcheck.md): Compare security testing capabilities between the solutions of Fluid Attacks and AppCheck. - [Appdome](/compare/appdome.md): Compare security testing capabilities between the solutions of Fluid Attacks and Appdome. - [Appknox](/compare/appknox.md): Compare security testing capabilities between the solutions of Fluid Attacks and Appknox. - [Aqua Security](/compare/aqua.md): Compare security testing capabilities between the solutions of Fluid Attacks and Aqua Security. - [Archipelo](/compare/archipelo.md): Compare security testing capabilities between the solutions of Fluid Attacks and Archipelo. - [Armorcode](/compare/armorcode.md): Compare security testing capabilities between the solutions of Fluid Attacks and Armorcode. - [Armosec](/compare/armosec.md): Compare security testing capabilities between the solutions of Fluid Attacks and Armosec. - [Arnica](/compare/arnica.md): Compare security testing capabilities between the solutions of Fluid Attacks and Arnica. - [Artemis](/compare/artemis.md): Compare security testing capabilities between the solutions of Fluid Attacks and Artemis. - [Aryon](/compare/aryon.md): Compare security testing capabilities between the solutions of Fluid Attacks and Aryon. - [Astra Security](/compare/astra-security.md): Compare security testing capabilities between the solutions of Fluid Attacks and Astra Security. - [Axonius](/compare/axonius.md): Compare security testing capabilities between the solutions of Fluid Attacks and Axonius. - [Backline](/compare/backline.md): Compare security testing capabilities between the solutions of Fluid Attacks and Backline. - [Backslash](/compare/backslash.md): Compare security testing capabilities between the solutions of Fluid Attacks and Backslash. - [Base4](/compare/base4.md): Compare security testing capabilities between the solutions of Fluid Attacks and Base4. - [Beazley Security](/compare/beazley-security.md): Compare security testing capabilities between the solutions of Fluid Attacks and Beazley Security. - [Bishop Fox](/compare/bishop-fox.md): Compare security testing capabilities between the solutions of Fluid Attacks and Bishop Fox. - [Bitfront](/compare/bitfront.md): Compare security testing capabilities between the solutions of Fluid Attacks and Bitfront. - [Black Duck](/compare/black-duck.md): Compare security testing capabilities between the solutions of Fluid Attacks and Black Duck. - [Black Hills](/compare/black-hills.md): Compare security testing capabilities between the solutions of Fluid Attacks and Black Hills. - [BoostSecurity](/compare/boostsecurity.md): Compare security testing capabilities between the solutions of Fluid Attacks and BoostSecurity. - [BreachLock](/compare/breachlock.md): Compare security testing capabilities between the solutions of Fluid Attacks and BreachLock. - [Bright Security](/compare/bright-security.md): Compare security testing capabilities between the solutions of Fluid Attacks and Bright Security. - [Bugcrowd](/compare/bugcrowd.md): Compare security testing capabilities between the solutions of Fluid Attacks and Bugcrowd. - [Burp Suite](/compare/burpsuite.md): Compare security testing capabilities between the solutions of Fluid Attacks and Burp Suite. - [CAI](/compare/cai.md): Compare security testing capabilities between the solutions of Fluid Attacks and CAI. - [Casco](/compare/casco.md): Compare security testing capabilities between the solutions of Fluid Attacks and Casco. - [Checkmarx](/compare/checkmarx.md): Compare security testing capabilities between the solutions of Fluid Attacks and Checkmarx. - [Claude Security](/compare/claude-security.md): Compare security testing capabilities between the solutions of Fluid Attacks and Claude Security. - [Clearly AI](/compare/clearly-ai.md): Compare security testing capabilities between the solutions of Fluid Attacks and Clearly AI. - [CloudGuard](/compare/cloudguard.md): Compare security testing capabilities between the solutions of Fluid Attacks and CloudGuard. - [Cloudsmith](/compare/cloudsmith.md): Compare security testing capabilities between the solutions of Fluid Attacks and Cloudsmith. - [Cobalt](/compare/cobalt.md): Compare security testing capabilities between the solutions of Fluid Attacks and 7 Way Security. - [Codacy](/compare/codacy.md): Compare security testing capabilities between the solutions of Fluid Attacks and Codacy. - [CodeMender](/compare/codemender.md): Compare security testing capabilities between the solutions of Fluid Attacks and CodeMender. - [CodeThreat](/compare/codethreat.md): Compare security testing capabilities between the solutions of Fluid Attacks and CodeThreat. - [Codex Security](/compare/codex-security.md): Compare security testing capabilities between the solutions of Fluid Attacks and Codex Security. - [Contrast Security](/compare/contrast-security.md): Compare security testing capabilities between the solutions of Fluid Attacks and Contrast Security. - [Conviso](/compare/conviso.md): Compare security testing capabilities between the solutions of Fluid Attacks and Conviso. - [Corgea](/compare/corgea.md): Compare security testing capabilities between the solutions of Fluid Attacks and Corgea. - [Corridor](/compare/corridor.md): Compare security testing capabilities between the solutions of Fluid Attacks and Corridor. - [CovertSwarm](/compare/covertswarm.md): Compare security testing capabilities between the solutions of Fluid Attacks and CovertSwarm. - [CrowdStrike](/compare/crowdstrike.md): Compare security testing capabilities between the solutions of Fluid Attacks and CrowdStrike. - [Cure53](/compare/cure53.md): Compare security testing capabilities between the solutions of Fluid Attacks and Cure53. - [Cybeats](/compare/cybeats.md): Compare security testing capabilities between the solutions of Fluid Attacks and Cybeats. - [Cycode](/compare/cycode.md): Compare security testing capabilities between the solutions of Fluid Attacks and Cycode. - [CyCognito](/compare/cycognito.md): Compare security testing capabilities between the solutions of Fluid Attacks and CyCognito. - [Cyscope](/compare/cyscope.md): Compare security testing capabilities between the solutions of Fluid Attacks and Cyscope. - [Cytix](/compare/cytix.md): Compare security testing capabilities between the solutions of Fluid Attacks and Cytix. - [Cyver Core](/compare/cyver.md): Compare security testing capabilities between the solutions of Fluid Attacks and Cyver Core. - [Data Theorem](/compare/data-theorem.md): Compare security testing capabilities between the solutions of Fluid Attacks and Data Theorem. - [DataDog](/compare/datadog.md): Compare security testing capabilities between the solutions of Fluid Attacks and DataDog. - [DC Expert](/compare/dc-expert.md): Compare security testing capabilities between the solutions of Fluid Attacks and DC Expert. - [DeepSource](/compare/deepsource.md): Compare security testing capabilities between the solutions of Fluid Attacks and DeepSource. - [DefectDojo](/compare/defectdojo.md): Compare security testing capabilities between the solutions of Fluid Attacks and DefectDojo. - [Depi](/compare/depi.md): Compare security testing capabilities between the solutions of Fluid Attacks and Depi. - [Depthfirst](/compare/depthfirst.md): Compare security testing capabilities between the solutions of Fluid Attacks and Depthfirst. - [DerScanner](/compare/derscanner.md): Compare security testing capabilities between the solutions of Fluid Attacks and DerScanner. - [Detectify](/compare/detectify.md): Compare security testing capabilities between the solutions of Fluid Attacks and Detectify. - [Devel](/compare/devel.md): Compare security testing capabilities between the solutions of Fluid Attacks and Devel. - [DragonJAR](/compare/dragonjar.md): Compare security testing capabilities between the solutions of Fluid Attacks and DragonJAR. - [Dreadnode](/compare/dreadnode.md): Compare security testing capabilities between the solutions of Fluid Attacks and Dreadnode. - [Dryrun Security](/compare/dryrun-security.md): Compare security testing capabilities between the solutions of Fluid Attacks and Dryrun Security. - [Dvuln](/compare/dvuln.md): Compare security testing capabilities between the solutions of Fluid Attacks and Dvuln. - [Dynatrace](/compare/dynatrace.md): Compare security testing capabilities between the solutions of Fluid Attacks and Dynatrace. - [Edgescan](/compare/edgescan.md): Compare security testing capabilities between the solutions of Fluid Attacks and Edgescan. - [Endor Labs](/compare/endor-labs.md): Compare security testing capabilities between the solutions of Fluid Attacks and Endor Labs. - [Escape](/compare/escape.md): Compare security testing capabilities between the solutions of Fluid Attacks and Escape. - [Ethiack](/compare/ethiack.md): Compare security testing capabilities between the solutions of Fluid Attacks and Ethiack. - [Evolve Security](/compare/evolve-security.md): Compare security testing capabilities between the solutions of Fluid Attacks and Evolve Security. - [Faraday Security](/compare/faraday.md): Compare security testing capabilities between the solutions of Fluid Attacks and Faraday Security. - [Finite State](/compare/finite-state.md): Compare security testing capabilities between the solutions of Fluid Attacks and Finite State. - [FortiDevSec](/compare/fortidevsec.md): Compare security testing capabilities between the solutions of Fluid Attacks and FortiDevSec. - [Fortify](/compare/fortify.md): Compare security testing capabilities between the solutions of Fluid Attacks and Fortify. - [FOSSA](/compare/fossa.md): Compare security testing capabilities between the solutions of Fluid Attacks and FOSSA. - [FuzzingLabs](/compare/fuzzinglabs.md): Compare security testing capabilities between the solutions of Fluid Attacks and FuzzingLabs. - [Gecko Security](/compare/gecko.md): Compare security testing capabilities between the solutions of Fluid Attacks and Gecko Security. - [GitHub Advanced Security (GHAS)](/compare/ghas.md): Compare security testing capabilities between the solutions of Fluid Attacks and GitHub Advanced Security. - [Ghost Security](/compare/ghost-security.md): Compare security testing capabilities between the solutions of Fluid Attacks and Ghost Security. - [GitGuardian](/compare/gitguardian.md): Compare security testing capabilities between the solutions of Fluid Attacks and GitGuardian. - [GitLab Ultimate](/compare/gitlab-ultimate.md): Compare security testing capabilities between the solutions of Fluid Attacks and GitLab Ultimate. - [GuardRails](/compare/guardrails.md): Compare security testing capabilities between the solutions of Fluid Attacks and GuardRails. - [HackerOne](/compare/hackerone.md): Compare security testing capabilities between the solutions of Fluid Attacks and HackerOne. - [HackerSec](/compare/hackersec.md): Compare security testing capabilities between the solutions of Fluid Attacks and HackerSec. - [Hackmetrix](/compare/hackmetrix.md): Compare security testing capabilities between the solutions of Fluid Attacks and Hackmetrix. - [Hacktron AI](/compare/hacktron-ai.md): Compare security testing capabilities between the solutions of Fluid Attacks and Hacktron AI. - [Hadrian](/compare/hadrian.md): Compare security testing capabilities between the solutions of Fluid Attacks and Hadrian. - [Halo Security](/compare/halo-security.md): Compare security testing capabilities between the solutions of Fluid Attacks and Halo Security. - [Harness](/compare/harness.md): Compare security testing capabilities between the solutions of Fluid Attacks and Harness. - [HCL AppScan](/compare/hcl-appscan.md): Compare security testing capabilities between the solutions of Fluid Attacks and HCL AppScan. - [Heeler](/compare/heeler.md): Compare security testing capabilities between the solutions of Fluid Attacks and Heeler. - [Hopper Security](/compare/hopper-security.md): Compare security testing capabilities between the solutions of Fluid Attacks and Hopper Security. - [Horizon3.ai](/compare/horizon3.md): Compare security testing capabilities between the solutions of Fluid Attacks and Horizon3.ai. - [HuntedLabs](/compare/hunted-labs.md): Compare security testing capabilities between the solutions of Fluid Attacks and HuntedLabs. - [ImmuniWeb](/compare/immuniweb.md): Compare security testing capabilities between the solutions of Fluid Attacks and ImmuniWeb. - [Incalmo](/compare/incalmo.md): Compare security testing capabilities between the solutions of Fluid Attacks and Incalmo. - [Inspectiv](/compare/inspectiv.md): Compare security testing capabilities between the solutions of Fluid Attacks and Inspectiv. - [Intigriti](/compare/intigriti.md): Compare security testing capabilities between the solutions of Fluid Attacks and Intigriti. - [Intruder](/compare/intruder.md): Compare security testing capabilities between the solutions of Fluid Attacks and Intruder. - [Invicti](/compare/invicti.md): Compare security testing capabilities between the solutions of Fluid Attacks and Invicti. - [Ionix](/compare/ionix.md): Compare security testing capabilities between the solutions of Fluid Attacks and Ionix. - [JFrog Advanced Security](/compare/jfrog-advanced-security.md): Compare security testing capabilities between the solutions of Fluid Attacks and JFrog Advanced Security. - [JFrog Xray](/compare/jfrog-xray.md): Compare security testing capabilities between the solutions of Fluid Attacks and JFrog Xray. - [JFrog](/compare/jfrog.md): Compare security testing capabilities between the solutions of Fluid Attacks and JFrog. - [Jit](/compare/jit.md): Compare security testing capabilities between the solutions of Fluid Attacks and Jit. - [Kiuwan](/compare/kiuwan.md): Compare security testing capabilities between the solutions of Fluid Attacks and Kiuwan. - [Legit Security](/compare/legit-security.md): Compare security testing capabilities between the solutions of Fluid Attacks and Legit Security. - [Lineaje](/compare/lineaje.md): Compare security testing capabilities between the solutions of Fluid Attacks and Lineaje. - [Mandiant](/compare/mandiant.md): Compare security testing capabilities between the solutions of Fluid Attacks and Mandiant. - [Maze](/compare/maze.md): Compare security testing capabilities between the solutions of Fluid Attacks and Maze. - [Mend](/compare/mend.md): Compare security testing capabilities between the solutions of Fluid Attacks and Mend. - [Metis](/compare/metis.md): Compare security testing capabilities between the solutions of Fluid Attacks and Metis. - [Miggo](/compare/miggo.md): Compare security testing capabilities between the solutions of Fluid Attacks and Miggo. - [Mindgard](/compare/mindgard.md): Compare security testing capabilities between the solutions of Fluid Attacks and Mindgard. - [Mobb](/compare/mobb.md): Compare security testing capabilities between the solutions of Fluid Attacks and Mobb. - [Moderne](/compare/moderne.md): Compare security testing capabilities between the solutions of Fluid Attacks and Moderne. - [Naxus](/compare/naxus.md): Compare security testing capabilities between the solutions of Fluid Attacks and Naxus. - [NetSPI](/compare/netspi.md): Compare security testing capabilities between the solutions of Fluid Attacks and NetSPI. - [Network Secure](/compare/network-secure.md): Compare security testing capabilities between the solutions of Fluid Attacks and Network Secure. - [NowSecure](/compare/nowsecure.md): Compare security testing capabilities between the solutions of Fluid Attacks and NowSecure. - [NTT DATA](/compare/nttdata.md): Compare security testing capabilities between the solutions of Fluid Attacks and NTT DATA. - [Nucleus Security](/compare/nucleus-security.md): Compare security testing capabilities between the solutions of Fluid Attacks and Nucleus Security. - [Oligo Security](/compare/oligo-security.md): Compare security testing capabilities between the solutions of Fluid Attacks and Oligo Security - [Open-Sec](/compare/open-sec.md): Compare security testing capabilities between the solutions of Fluid Attacks and Open-Sec. - [Opengrep](/compare/opengrep.md): Compare security testing capabilities between the solutions of Fluid Attacks and Opengrep. - [Orca Security](/compare/orca-security.md): Compare security testing capabilities between the solutions of Fluid Attacks and Orca Security. - [Ostorlab](/compare/ostorlab.md): Compare security testing capabilities between the solutions of Fluid Attacks and Ostorlab. - [Oversecured](/compare/oversecured.md): Compare security testing capabilities between the solutions of Fluid Attacks and Oversecured. - [OX Security](/compare/ox-security.md): Compare security testing capabilities between the solutions of Fluid Attacks and OX Security. - [PentestGPT](/compare/pentestgpt.md): Compare security testing capabilities between the solutions of Fluid Attacks and PentestGPT. - [Phoenix Security](/compare/phoenix-security.md): Compare security testing capabilities between the solutions of Fluid Attacks and Phoenix Security. - [Pi Security](/compare/pi-security.md): Compare security testing capabilities between the solutions of Fluid Attacks and Pi Security. - [PlexTrac](/compare/plextrac.md): Compare security testing capabilities between the solutions of Fluid Attacks and PlexTrac. - [PointGuard AI](/compare/pointguard-ai.md): Compare security testing capabilities between the solutions of Fluid Attacks and PointGuard AI. - [Praetorian](/compare/praetorian.md): Compare security testing capabilities between the solutions of Fluid Attacks and Praetorian. - [Prancer](/compare/prancer.md): Compare security testing capabilities between the solutions of Fluid Attacks and Prancer. - [Prisma Cloud](/compare/prisma-cloud.md): Compare security testing capabilities between the solutions of Fluid Attacks and Prisma Cloud. - [Prowler](/compare/prowler.md): Compare security testing capabilities between the solutions of Fluid Attacks and Prowler. - [Qodex](/compare/qodex.md): Compare security testing capabilities between the solutions of Fluid Attacks and Qodex. - [Qualys](/compare/qualys.md): Compare security testing capabilities between the solutions of Fluid Attacks and Qualys. - [Rapid7](/compare/rapid7.md): Compare security testing capabilities between the solutions of Fluid Attacks and Rapid7. - [RapidFort](/compare/rapidfort.md): Compare security testing capabilities between the solutions of Fluid Attacks and RapidFort. - [Raptor](/compare/raptor.md): Compare security testing capabilities between the solutions of Fluid Attacks and Raptor. - [Raven](/compare/raven.md): Compare security testing capabilities between the solutions of Fluid Attacks and Raven. - [RunSybil](/compare/runsybil.md): Compare security testing capabilities between the solutions of Fluid Attacks and RunSybil. - [RunZero](/compare/runzero.md): Compare security testing capabilities between the solutions of Fluid Attacks and RunZero. - [Safety](/compare/safety.md): Compare security testing capabilities between the solutions of Fluid Attacks and Safety. - [Scribe Security](/compare/scribe-security.md): Compare security testing capabilities between the solutions of Fluid Attacks and Scribe Security. - [Securetia](/compare/securetia.md): Compare security testing capabilities between the solutions of Fluid Attacks and Securetia. - [Securitum](/compare/securitum.md): Compare security testing capabilities between the solutions of Fluid Attacks and Securitum. - [SecurityBoat](/compare/securityboat.md): Compare security testing capabilities between the solutions of Fluid Attacks and SecurityBoat. - [Seemplicity](/compare/seemplicity.md): Compare security testing capabilities between the solutions of Fluid Attacks and Seemplicity. - [Semgrep](/compare/semgrep.md): Compare security testing capabilities between the solutions of Fluid Attacks and Semgrep. - [Snyk](/compare/snyk.md): Compare security testing capabilities between the solutions of Fluid Attacks and Snyk. - [Socket](/compare/socket.md): Compare security testing capabilities between the solutions of Fluid Attacks and Socket. - [SonarQube](/compare/sonarqube.md): Compare security testing capabilities between the solutions of Fluid Attacks and SonarQube. - [Sonatype Lifecycle](/compare/sonatype-lifecycle.md): Compare security testing capabilities between the solutions of Fluid Attacks and Sonatype Lifecycle. - [SOOS](/compare/soos.md): Compare security testing capabilities between the solutions of Fluid Attacks and SOOS. - [SpartanX](/compare/spartanx.md): Compare security testing capabilities between the solutions of Fluid Attacks and SpartanX. - [Spectra Assure](/compare/spectra-assure.md): Compare security testing capabilities between the solutions of Fluid Attacks and Spectra Assure. - [StackHawk](/compare/stackhawk.md): Compare security testing capabilities between the solutions of Fluid Attacks and StackHawk. - [Stacklok](/compare/stacklok.md): Compare security testing capabilities between the solutions of Fluid Attacks and Stacklok. - [StealthNet AI](/compare/stealthnet-ai.md): Compare security testing capabilities between the solutions of Fluid Attacks and StealthNet AI. - [Strike](/compare/strike.md): Compare security testing capabilities between the solutions of Fluid Attacks and Strike. - [Strix](/compare/strix.md): Compare security testing capabilities between the solutions of Fluid Attacks and Strix. - [Synack](/compare/synack.md): Compare security testing capabilities between the solutions of Fluid Attacks and Synack. - [Synacktiv](/compare/synacktiv.md): Compare security testing capabilities between the solutions of Fluid Attacks and Synacktiv. - [Synapseguard](/compare/synapseguard.md): Compare security testing capabilities between the solutions of Fluid Attacks and Synapseguard. - [Tempest](/compare/tempest.md): Compare security testing capabilities between the solutions of Fluid Attacks and Tempest. - [Tenable Nessus](/compare/tenable-nessus.md): Compare security testing capabilities between the solutions of Fluid Attacks and Tenable Nessus. - [Theori](/compare/theori.md): Compare security testing capabilities between the solutions of Fluid Attacks and Theori. - [ThreatModeler](/compare/threatmodeler.md): Compare security testing capabilities between the solutions of Fluid Attacks and ThreatModeler. - [TIC Defense](/compare/tic-defense.md): Compare security testing capabilities between the solutions of Fluid Attacks and TIC Defense. - [Trail of Bits](/compare/trail-of-bits.md): Compare security testing capabilities between the solutions of Fluid Attacks and Trail of Bits. - [True Positives](/compare/true-positives.md): Compare security testing capabilities between the solutions of Fluid Attacks and True Positives. - [ULTRA RED](/compare/ultra-red.md): Compare security testing capabilities between the solutions of Fluid Attacks and ULTRA RED. - [Veracode](/compare/veracode.md): Compare security testing capabilities between the solutions of Fluid Attacks and Veracode. - [Veria Labs](/compare/verialabs.md): Compare security testing capabilities between the solutions of Fluid Attacks and Veria Labs. - [Vicarius](/compare/vicarius.md): Compare security testing capabilities between the solutions of Fluid Attacks and Vicarius. - [Vidoc](/compare/vidoc.md): Compare security testing capabilities between the solutions of Fluid Attacks and Vidoc. - [Wabbi](/compare/wabbi.md): Compare security testing capabilities between the solutions of Fluid Attacks and Wabbi. - [White Jaguars](/compare/white-jaguars.md): Compare security testing capabilities between the solutions of Fluid Attacks and White Jaguars. - [Wiz](/compare/wiz.md): Compare security testing capabilities between the solutions of Fluid Attacks and Wiz. - [XBOW](/compare/xbow.md): Compare security testing capabilities between the solutions of Fluid Attacks and XBOW. - [Xygeni](/compare/xygeni.md): Compare security testing capabilities between the solutions of Fluid Attacks and Xygeni. - [YesWeHack](/compare/yeswehack.md): Compare security testing capabilities between the solutions of Fluid Attacks and YesWeHack. - [ZAP](/compare/zap.md): Compare security testing capabilities between the solutions of Fluid Attacks and ZAP. - [Zast](/compare/zast.md): Compare security testing capabilities between the solutions of Fluid Attacks and Zast. - [ZeroPath](/compare/zeropath.md): Compare security testing capabilities between the solutions of Fluid Attacks and ZeroPath.