Getting started
How Amnify works
The loop from a connected source to a merged fix.
Quickstart
Connect a source and run your first scan.
Manage findings
Triage, prioritize and act on confirmed issues.
Users and organization
Roles, invitations and what each one can do.
Connect your stack
Sources
Connect your code and cloud, and choose exactly what is in scope.
Integrations
Ticketing, documentation and the channels your team already works in.
AI coding agents
Reach your Amnify data from your own AI agents.
Scanning capabilities
Code scanning
Injection, broken authorization, unsafe patterns, exposed secrets, CI/CD weaknesses.
Dependencies and CVE disclosures
Known vulnerabilities in what you run, checked hourly against new advisories.
Infrastructure as code
Insecure infrastructure caught before it reaches an account.
Cloud scanning
Misconfiguration, over permissive identity, public exposure, encryption and logging gaps.
Scan automation
Schedules, scan on push, and what runs on its own.
Penetration testing
Set up a pentest
Authorize an application, verify the domain, choose how deep to go.
How a pentest runs
The phases, and why nothing is reported without proof.
Developer workflow
Pull request review
An inline security review on every pull request, before it merges.
Fixes and pull requests
From a plan you approve to a merge ready pull request.
Knowledge, insight and trust
Context
Your documents and decisions. Answer once, and every future finding is judged against it.
Activity and audit trail
A tamper evident record of everything that happened.
Data security
Isolation, encryption, credentials and hosting.