New · Release 2026.04, Multi-tenant audit exports & SLA dashboards now live See changelog →
Continuous security

Continuous security scanning on every commit and deploy

Shift-left scanning on commits and deploys with live dashboards, webhooks, and severity gates.

Product illustration · sample data
Security & VAPT
A+ score
EngagementHTTP LabReport PDF
A+
Last scan · 2 hours ago
Critical vulnerabilities0
High severity2
Manual + imported4
Engagement reportReady
Product proof

Already live in the product

Infronest module

This engagement can align with shipped product capabilities in your tenant workspace.

Protected app route: /vapt-realtime
Platform

Included in the Infronest workspace

These capabilities ship in the product today—consulting adds human validation and attestation where required.

  • Automated web scanning
  • Scoped engagements
  • HTTP Lab
  • Manual & imported findings
  • Analyst workbench
  • Audit-ready reports
Capabilities

What you get

Delivered with AI-assisted engineering and human review on architecture, security, and production readiness.

Trigger scans on commit or deploy
Realtime finding stream
Concurrent scan management
Historical timeline per repo
Workflow

What teams can do here

Step 1
Connect Git provider
Step 2
Set thresholds
Step 3
Gate releases
Step 4
Alert on criticals
How it works

How it works

01
Connect your Git provider
Wire up GitHub, GitLab or Jenkins through the integrations hub using webhooks, so scans can trigger on the events you choose — commit, pull request or deploy.
02
Set severity thresholds
Define the gate: which severities are allowed to pass and which should fail the pipeline. Policy can differ per repository.
03
Scan on every change
When the trigger fires, the configured scan profile runs automatically and the results stream to the realtime dashboard. This is shift-left automated scanning, not a continuous human pentest.
04
Gate, alert and trend
Builds that breach the threshold are flagged or blocked, criticals raise alerts, and a per-repository timeline shows whether your security posture is improving or regressing over time.
Example

A worked example

A typical setup: a 15-developer platform team wires its main GitHub repository to a webhook and sets the gate to fail on any new high or critical. A pull request bumps a dependency to a version with a known CVE; the triggered scan streams the finding to the realtime dashboard mid-run and the pipeline step fails before merge. The developer pins the patched release, the next run passes, and the repository’s trend line records a regression caught and closed inside a day — instead of surfacing months later in the next scheduled assessment.

FAQ

Frequently asked questions

What triggers a continuous scan — commit, deploy, or schedule?
Any of them. Webhooks let you fire scans on commit, on pull request, or on deploy, and you can also schedule runs. You pick the events per repository so scanning matches how your team ships.
Which CI/CD systems can this plug into?
GitHub, GitLab and Jenkins are supported through the integrations hub, with webhooks and a CLI entry point for pipelines. Findings can be pushed onward to alerting channels.
Can a scan block or fail a build or release?
Yes. You set severity thresholds, and a run that breaches them can fail the pipeline step so risky changes do not ship. Teams often start in report-only mode and tighten the gate once the baseline is clean.
What does continuous scanning cost compared to a one-time pentest?
Continuous scanning is part of the VAPT module subscription rather than priced per run — see the VAPT hub. For comparison, one-time engagements in the Indian market typically cost ₹1.5–4 lakh (USD 2,000–5,000) for a focused web application test and ₹5–15 lakh (USD 6,000–18,000) for combined network + web VAPT on a mid-size environment; Infronest one-time engagements start at ₹36,750 per application.
How long do setup and each scan run take?
Connecting a webhook and setting thresholds is a same-day task. Per-run time scales with the profile — quick profiles are built for in-pipeline feedback, full profiles run longer and suit nightly or deploy triggers. A formal point-in-time engagement, by contrast, typically takes one to three weeks industry-wide.
Is continuous scanning the same as a continuous manual pentest?
No, and we are clear about that. This is automated scanning wired into your pipeline for fast, repeatable feedback. Human penetration testing is a separate engagement — the two complement each other rather than replace one another.
How is this different from a one-time engagement?
A one-time engagement is a scoped, point-in-time assessment with a dated report. Continuous security runs automatically on every change and tracks trend over time, so new regressions are caught between formal assessments.

See also: VAPT product hub · Remediation & re-test · Pentesting as a service / PTaaS (blog) · VAPT tools compared (blog) · Book a demo

VAPT

All VAPT services

Related

Explore connected offerings

Catch the regression before it merges

Webhook-triggered scans with severity gates turn security from a quarterly event into a pipeline step — every pull request checked, every trend visible.