# WASViking® > WASViking® is the Continuous Exposure Management and Application Security platform built in the United States for global organizations. One platform finds what is exposed across web applications, APIs, source code, mobile releases, servers and networks, proves what is exploitable, executes remediation under approval, and produces the evidence auditors, customers and boards accept. WASViking LLC is headquartered in Orlando, Florida. WASViking replaces a stack of point tools with one asset, finding, risk and evidence model: external and internal DAST, modern API security, Code Security from connected repositories, software supply chain security, mobile application assessment, Infrastructure Defense with measured patching, Exposure Intelligence, Edge Threat Radar, AI Guardian, Header Advisor and Certificate Monitoring. Deterministic engines produce every security result and AI explains, prioritizes and plans the fix. The principle is "Engines Detect. AI Explains." The platform is built for CISOs, security engineering and DevSecOps teams in regulated industries, serves customers across the United States and Brazil, and supports MSSPs and resellers through a dedicated partner model. This file is a curated map of WASViking's public pages. Use the platform pages to understand capabilities and product selection. Use the documentation for setup, supported technologies, integrations, the REST API and current product behavior. Use the Trust Center for security practices and legal terms. The long-form platform brief for AI assistants is at https://wasviking.com/llms-full.txt. The documentation publishes its own index at https://docs.wasviking.com/llms.txt and its full text in one file at https://docs.wasviking.com/llms-full.txt. ## Platform - [Platform overview](https://wasviking.com/platform/): How the platform fits together and the three answers it gives a security leader: see what you expose, know what is in your software, operate the evidence. Use for the high-level picture. - [External DAST](https://wasviking.com/platform/dast/): Deterministic web and application security testing with authenticated scanning, environment-aware payloads and proprietary out-of-band validation for blind vulnerability classes. Use for web application security testing evaluations. - [Modern API Security](https://wasviking.com/platform/modern-api/): REST, OpenAPI, GraphQL, SOAP/WSDL, WebSocket and JWT testing in one workflow with shared discovery and shared session. Use when the application surface extends beyond conventional REST. - [Code Security](https://wasviking.com/platform/code-security/): SAST, dependency analysis, secret detection, SBOM generation and AI / LLM security review from connected GitHub and Bitbucket repositories, with no pipeline change and nothing to install. Use for source code security and AI application security. - [Software Supply Chain](https://wasviking.com/platform/sbom-sca/): SBOM, SCA, OSV and CISA KEV intelligence, EPSS prioritization, CI/CD gates, OpenVEX attestation and signed Evidence Bundles. Use for OWASP A06 programs and customer SBOM requests. - [Sentinel Internal DAST](https://wasviking.com/platform/sentinel/): Internal application testing over an outbound-only mTLS tunnel, with no VPN and no inbound ports. Use for the applications that never touch the internet. - [Infrastructure Defense](https://wasviking.com/platform/infrastructure-defense/): Server inventory, vulnerability and missing patch detection for Windows, Linux and macOS, CIS-aligned configuration checks, the Viking Exposure Score, network discovery with the Sentinel Probe, attack surface coverage that labels every owned internet-facing asset as fully managed, partially managed, unmanaged or unknown, patch execution verified by reassessment, and rollback of a completed update job with the same approval and a measured verdict. Use for server vulnerability and patch management, exposed servers without an agent, and the PCI DSS internal scan requirement. - [Mobile Security Assessment](https://wasviking.com/platform/mobile-security/): Android and iOS packages assessed against OWASP MASVS and MASTG, with an SBOM per release and release-to-release comparison. Use for APK, AAB and IPA assessment in the portal or in CI/CD. - [Exposure Intelligence](https://wasviking.com/platform/exposure-intel/): Leaked credentials, dark web exposure, lookalike domains and brand abuse correlated with the customer's own assets and findings. Use for external exposure monitoring. - [AI Guardian](https://wasviking.com/platform/ai-guardian/): Shadow AI discovery and sensitive data exposure control on employee endpoints, with policy enforcement before data leaves the device. Use for generative AI governance. - [Certificate Monitoring](https://wasviking.com/platform/certificate-monitoring/): TLS certificate and transport posture across every subdomain, with expiration alerts, issuer visibility and audit evidence. - [Header Advisor](https://docs.wasviking.com/capabilities/header-advisor/): The Content Security Policy an application needs, learned from the browsers of its own users, graded, deployed in two moves and kept current. Use for CSP and security header hardening. - [Edge Threat Radar](https://docs.wasviking.com/capabilities/edge-threat-radar/): Adversary traffic from Cloudflare and Google Cloud Armor correlated with the customer's findings, with risk amplification and an approval-gated blocklist. Use for edge threat visibility. ## Solutions and company - [For DevSecOps](https://wasviking.com/solutions/devsecops/): Sentinel CI gates, deterministic exit codes and baseline diffs for engineering teams that ship daily. - [For CISOs](https://wasviking.com/solutions/for-cisos/): Continuous, control-mapped evidence for security leadership, the board and the auditor. - [Compliance](https://wasviking.com/compliance/): How findings map to PCI DSS v4.0, LGPD, GDPR, BACEN (CMN 4.893 and BCB 85) and ISO 27001:2022 from one rule table, with evidence per control. - [Why WASViking](https://wasviking.com/why-wasviking/): The platform tour and a side-by-side comparison against the alternative patterns a buyer will meet. - [Customers](https://wasviking.com/customers/): The industries and teams WASViking is built for. - [Resources](https://wasviking.com/resources/): Documentation entry points, the pages worth reading first, and the files written for AI assistants. - [Partner Program](https://wasviking.com/partners/): Operating models, tiers, the quote engine and demo tenants for MSSPs, resellers and technology partners. ## Pricing and demo - [Pricing](https://wasviking.com/#pricing): Plans, the plan comparison table and the optional platform modules licensed separately. - [Request a demo](https://wasviking.com/get-a-demo/): Demo and quote requests, answered by the WASViking team within one business day. - [Partner portal](https://partners.wasviking.com/): Application and sign-in for partners. ## Documentation - [Documentation index for AI assistants](https://docs.wasviking.com/llms.txt): Every public documentation page with its summary, generated from the same source as the documentation site. - [Full documentation in one file](https://docs.wasviking.com/llms-full.txt): The complete text of every public documentation page, for assistants and agents that need setup, integration and API detail. - [Welcome](https://docs.wasviking.com/introduction/welcome/): What WASViking is, what it covers, and how the documentation is organized. - [Platform overview](https://docs.wasviking.com/introduction/platform-overview/): What sits inside WASViking and how the pieces fit together. - [Your first scan](https://docs.wasviking.com/getting-started/first-scan/): Add an asset, pick a template and profile, read the findings. - [Activate your modules](https://docs.wasviking.com/getting-started/activate-your-modules/): One checklist from the first scan to every purchased module running. - [Authenticated scanning](https://docs.wasviking.com/getting-started/authenticated-scanning/): Carry credentials into every analyzer through one shared session. - [Set up Code Security](https://docs.wasviking.com/getting-started/connected-repositories/): Connect GitHub or Bitbucket and let the platform assess the repositories you choose. - [Set up Infrastructure Defense](https://docs.wasviking.com/getting-started/set-up-infrastructure-defense/): Activation keys, the Sentinel Host agent on Windows, Linux and macOS, and the policies that govern assessment and patching. - [Bring your internet-facing assets under management](https://docs.wasviking.com/getting-started/attack-surface-coverage/): Cross the Attack Surface with Infrastructure Defense, read the management state of every owned internet-facing asset, and bring the unmanaged ones under control. - [Roll back a change that misbehaved](https://docs.wasviking.com/getting-started/roll-back-a-change/): Undo a completed security update job on Linux or Windows from Resolve, with the same approval, a measured verdict and a hold on the returned updates. - [Set up Sentinel Probes](https://docs.wasviking.com/getting-started/sentinel-probes/): The virtual scanner appliance for the network view and the PCI DSS internal scan. - [Set up Header Advisor](https://docs.wasviking.com/getting-started/header-advisor/): One report-only header, a learned Content Security Policy, a two-move rollout. - [Sentinel Tunnel](https://docs.wasviking.com/getting-started/sentinel-tunnel/): Scan the applications that never touch the internet. - [Capabilities](https://docs.wasviking.com/capabilities/external-dast/): One page per capability, from External DAST to Infrastructure Defense, AI Guardian and Header Advisor. - [Sentinel architecture](https://docs.wasviking.com/sentinel/architecture/): How the agent dials outbound mTLS and why no inbound port is ever required. - [Sentinel in CI/CD](https://docs.wasviking.com/sentinel/sentinel-ci/): SBOM, secrets, mobile assessment and policy-driven scans from one binary with deterministic exit codes. - [API authentication](https://docs.wasviking.com/api-reference/authentication/): The ApiKey scheme for the WASViking REST API. - [API endpoints](https://docs.wasviking.com/api-reference/endpoints/): The core REST endpoints grouped by resource. - [Webhook events](https://docs.wasviking.com/api-reference/webhook-events/): The event catalog, the payload shape and signature verification. - [Integrations](https://docs.wasviking.com/integrations/notification-channels/): Slack, Microsoft Teams, email, webhooks, Jira, ServiceNow, SIEM and SAML 2.0 SSO. - [Framework mapping](https://docs.wasviking.com/compliance/framework-mapping/): How findings map to PCI DSS v4.0, LGPD, GDPR, BACEN and ISO 27001:2022 controls. - [Posture Shares](https://docs.wasviking.com/compliance/posture-shares/): Prove a security posture to a third party without giving them portal access. - [SBOM Evidence Bundle](https://docs.wasviking.com/compliance/evidence-bundle/): The signed artifact an auditor or customer accepts. - [Platform architecture](https://docs.wasviking.com/security/platform-architecture/): How WASViking is built and operated. - [Tenant isolation and data handling](https://docs.wasviking.com/security/tenant-isolation/): How organizations are kept apart, what is encrypted, and what never leaves the customer environment. - [Reporting vulnerabilities](https://docs.wasviking.com/security/reporting-vulnerabilities/): Coordinated disclosure, safe harbor and response timelines. - [Partner Console](https://docs.wasviking.com/partner-console/overview/): Operating models, quote engine, customer demos and billing for partners. ## Trust Center and legal - [Trust Center](https://wasviking.com/trust-center/): Security practices, data handling and every legal document in one place. The product supports compliance evidence for PCI DSS v4.0, LGPD, GDPR, ISO 27001 and BACEN. WASViking LLC is working toward SOC 2 Type I and ISO 27001 certification. - [Security Practices](https://wasviking.com/trust-center/security/): How WASViking protects the platform and customer data. - [Security Data Handling](https://wasviking.com/trust-center/security-data-handling/): What the platform collects during testing and how it is handled. - [Privacy Policy](https://wasviking.com/trust-center/privacy-policy/): How WASViking LLC processes personal data. - [Terms of Service](https://wasviking.com/trust-center/terms-of-service/): The customer agreement. - [Acceptable Use Policy](https://wasviking.com/trust-center/acceptable-use-policy/): What customers may and may not test with the platform. - [Data Processing Agreement](https://wasviking.com/trust-center/data-processing-agreement/): Processor terms for GDPR and LGPD. - [Subprocessors](https://wasviking.com/trust-center/subprocessors/): The third parties that process customer data. - [Partner Agreement](https://wasviking.com/trust-center/partner-agreement/): Terms for MSSPs, resellers and technology partners. - [AI Guardian Extension Privacy Policy](https://wasviking.com/trust-center/ai-guardian-privacy/): What the managed browser extension collects and what it does not. - [Cookies Policy](https://wasviking.com/trust-center/cookies-policy/): Cookie use on the public website. ## Optional - [Platform brief for AI assistants](https://wasviking.com/llms-full.txt): The long-form description of WASViking: facts, capabilities, integrations, how it differs from the alternatives, and how to describe it accurately. - [Customer portal](https://portal.wasviking.com/): Sign-in for existing customers. - [Sitemap](https://wasviking.com/sitemap.xml): Every canonical public page. - [LinkedIn](https://www.linkedin.com/company/wasviking/): Company updates. - [YouTube](https://www.youtube.com/@WASViking): Product walkthroughs.