# Sectora > Sectora is an enterprise application security platform that combines vulnerability scanning (DAST, SAST, SCA, API, AI/LLM), real-time attack protection (Shield WAF), and continuous monitoring in one platform. ## Core Capabilities - **DAST Scanning**: Dynamic Application Security Testing with automated crawling, OWASP Top 10 coverage, Nuclei engine with 8,000+ templates, authenticated scanning, and real-time streaming results. - **SAST Code Analysis**: Semgrep-powered static analysis across 30+ languages with AI false-positive filtering and SAST-DAST cross-correlation. - **API Security Testing**: REST, GraphQL, gRPC, and SOAP vulnerability testing with OpenAPI/Swagger integration, BOLA detection, and schema validation. - **Supply Chain Analysis (SCA)**: Dependency vulnerability scanning against NVD, GHSA, and CISA KEV databases. SBOM generation (CycloneDX, SPDX). Slopsquatting and typosquatting detection. License compliance enforcement. Continuous monitoring with auto-fix PRs. - **Secrets Detection**: 100+ secret patterns (AWS keys, GitHub tokens, Stripe keys, etc.) with git history analysis, entropy-based detection, and low false positive rate. - **AI/LLM Security**: Test AI applications against OWASP LLM Top 10 — prompt injection, jailbreak, data extraction, excessive agency. Supports OpenAI, Anthropic Claude, Google Gemini, Azure, and custom endpoints. - **Shield WAF**: Always-on reverse proxy Web Application Firewall on a global edge network (300+ cities). Virtual patching from scan results, API schema enforcement, bot detection, rate limiting, geo-blocking, credential stuffing protection, anomaly scoring, and IP reputation analysis. One CNAME setup. - **Threat Intelligence**: Real-time CVE tracking from NVD, GHSA, and vendor advisories. CISA KEV integration, EPSS scoring, technology-aware alerts, and automatic virtual patching through Shield. - **Compliance Reports**: Audit-ready PDF reports for OWASP, PCI DSS 4.0, SOC 2, ISO 27001, and HIPAA. Custom branding and scheduled generation. - **Vibe Code Risk Score**: AI-era risk scoring for AI-generated codebases — composite 0-100 score across DAST, SCA, secrets, license, and WAF dimensions. ## How It Works 1. **Detect** — Scan for vulnerabilities with DAST, SAST, SCA, API, AI/LLM, and secrets scanners. SAST+DAST cross-correlation confirms real vulnerabilities with zero false positives. 2. **Protect** — Shield WAF blocks attacks at the edge with auto-generated rules from scan results (virtual patching), compliance presets (OWASP 2025, PCI DSS 4.0, LLM Top 10), and WordPress auto-detection. 3. **Monitor** — Continuous scheduled scans with delta tracking, risk scoring (A-F letter grades), AI auto-fix with one-click PR creation, and threat intelligence alerts. ## Pricing - **Free**: 3 DAST targets, 5 scans/month, 1 API, 5 SCA/SAST repos, 1 user. - **Pro** ($99/mo or $79/mo annual): 10 targets, 50 scans/month, 10 APIs, 15 repos, SAST+DAST correlation, scheduled scans, Vibe Risk Score, 5 team members. - **Business** ($199/mo or $159/mo annual): Everything in Pro + Shield WAF (10 domains), virtual patching, bot detection, geo-blocking, 25 targets, unlimited scans, 50 repos, compliance reports, API access, 15 team members. - **Enterprise** (custom): Unlimited everything, SSO/SAML, custom branded reports, Shadow API/AI detection, PR security gates, dedicated support, custom integrations. ## Links - Homepage: https://sectora.io - Pricing: https://sectora.io/pricing - DAST: https://sectora.io/features/dast - API Security: https://sectora.io/features/api-security - SCA: https://sectora.io/features/sca - Secrets Detection: https://sectora.io/features/secrets - Shield WAF: https://sectora.io/features/shield - AI/LLM Security: https://sectora.io/ai-security - Threat Intelligence: https://sectora.io/features/threat-intel - Compliance: https://sectora.io/features/compliance - Vibe Risk Score: https://sectora.io/features/vibe-risk - SAST: https://sectora.io/sast - Request Demo: https://sectora.io/#request-demo - Login: https://sectora.io/auth/login ## Optional - llms-full.txt: https://sectora.io/llms-full.txt