Application Vulnerability Assessment
Know exactly what's in your code — and what's at risk.
AppVa scans every dependency in your repositories and container images, generates a complete Software Bill of Materials, and maps each component against live CVE databases — so you can fix real risks before they become breaches.
Platform features
Full-spectrum dependency intelligence, from code to container
SBOM Generation
Powered by Syft, AppVa produces a complete Software Bill of Materials for every repository and image — cataloguing all open-source libraries, transitive dependencies, and their exact versions.
CVE Vulnerability Scanning
Grype cross-references every component in your SBOM against live CVE databases, surfacing exploitable vulnerabilities with CVSS scores and affected version ranges so you know exactly what to patch.
Multi-Source Repository Support
Connect GitHub repositories via HTTPS with optional branch selection and access tokens, upload ZIP archives of source code, or scan Docker images and .tar archives — all from a single interface.
Dashboard & Analytics
Aggregate statistics across all repositories: vulnerability severity distribution charts, top vulnerable packages, license distribution analysis, and trend views to track your security posture over time.
Scheduled Scanning
Define cron-based scan schedules per repository with 30-second check intervals. Pause and resume schedules without deletion — maintain continuous coverage without manual intervention.
Notification Channels
Receive automated scan summaries via Slack, Microsoft Teams, or any webhook endpoint. Multiple channels per repository, with add, edit, test, and enable/disable controls for each integration.
PDF Reporting
Export full scan results as PDF reports including CVE IDs, affected packages, CVSS scores, and SBOM component lists — ready for audits, compliance reviews, or executive briefings.
Role-Based Access & 2FA
TOTP two-factor authentication at login and admin-controlled reset capability. Three permission levels — viewer, operator, and admin — ensure the right people have the right access to scan data and configuration.
Latest updates
From the SOCFortress blog

Aug 26 2026
SOCFortress AppVA Update — Aug 2026
AppVA adds Trivy secret and misconfiguration scanning alongside its existing Syft + Grype pipeline, catching hardcoded credentials and insecure IaC that CVE-focused scanning can't see.
Read on Medium

Aug 20 2026
You Didn't Choose Half the Code in Your App
A hands-on walkthrough of deploying AppVA, scanning a deliberately vulnerable demo app, and opening an automated fix pull request for the vulnerable dependencies it finds.
Read on Medium

Jul 31 2026
Meeting the CISA 2026 SBOM Minimum Elements with SOCFortress AppVA
A field-by-field walkthrough of how AppVA's CycloneDX SBOMs, PURL-based component identifiers, and scan history satisfy CISA's updated 2026 SBOM minimum elements.
Read on Medium

Jul 24 2026
Beyond CVEs: Adding AI-Assisted Security Code Review to Your SBOM Pipeline using SOCFortress AppVA
How AppVA's optional AI Code Review layer flags logic-level weaknesses — auth bypasses, injection flaws, hardcoded secrets — that dependency scanning alone can't catch.
Read on Medium

Apr 23 2026
SOCFortress — Application Vulnerability Assessment
An introduction to AppVA — a containerized SBOM and vulnerability scanning tool built on Syft and Grype for repositories, source archives, and container images.
Read on Medium
Ready to see every dependency risk across your codebase?
Request access Frequently asked questions
Search keywords..
What types of repositories and sources can AppVa scan?
How does the SBOM and vulnerability scanning pipeline work?
Is there a cost to use AppVa?
Can AppVa notify our team automatically when a scan finds new vulnerabilities?
Didn’t find the answer you were looking for?
Contact us, we’re here to help