Frequently asked questions

About Maphra

What does Maphra need to get started?
A domain name. Maphra works from the outside in, so it needs no agent, no credential into your estate and no network access. Discovery begins from public data the same way an attacker would begin.
How is Maphra different from a vulnerability scanner?
A scanner tests a list of assets you give it. Maphra finds the assets first — including the ones nobody remembered — attributes them to your organisation, then analyses them. The discovery step is the product.
Does Maphra attack our systems?
Active validation runs only inside an explicit scope boundary you define, and the scope gate prevents active checks from reaching third-party hosts that merely appear in your surface.
How does Maphra handle findings that are not real?
Every finding carries the evidence that produced it, and findings are deduplicated across scans and tracked through new, reopened and fixed states rather than re-reported each run.

About AppSecD

Does AppSecD replace our existing scanners?
It consolidates them. SAST, DAST, SCA, secrets, IaC, container, Kubernetes and API security all run from one platform against one deduplicated finding model, so the same vulnerability is not tracked three times in three tools.
How does it avoid burying developers in false positives?
Two ways. Reachability analysis determines whether a vulnerable path can actually be reached before anything is raised, and an AI triage layer labels likely false positives — with the label itself tracked, so triage quality is measurable.
Where does it fit in our pipeline?
It triggers on webhooks, scheduled runs, CI, ZIP upload or manually, and it gates pull requests and commits by policy. Developers also get results inside VS Code, Cursor, Windsurf and JetBrains before they push.
Can a developer close their own finding?
Not where you do not want them to. The lifecycle supports maker-checker approval, so a finding marked fixed or false-positive can require a second person to confirm it.

About both

What is the difference between the two products?
Maphra works outside-in: What can an attacker reach without any credentials? AppSecD works inside-out: What are we shipping into production right now? They overlap very little and most teams run both.
Who builds them?
DedSec Technologies LLP. Maphra by DedSec runs at https://maphra.dedsecops.com and Navigator AppSecD runs at https://appsecd.com.
How do we get started?
Maphra needs a domain name and nothing else, so the quickest first step is a walkthrough against an estate you already worry about. Email [email protected] or use the contact page.