Find vulnerabilities, prioritize them, and remediate
Vulinder User Guide
A security analysis (ASPM) platform that helps you find vulnerabilities in one place, from source code to containers, web services, and server infrastructure, and remediate the most dangerous ones first. This guide walks you through the exact order of work, from registering a service to running analyses and handling the vulnerabilities you find.
In the Quick Start, you can follow the entire flow from sign-up to your first service registration, first scan, and reviewing results in under 10 minutes.
What does Vulinder do
Vulinder brings scattered security checks into a single organization view. It normalizes results from different tools into the same language (severity, KEV, compliance) to answer the question "what should I address first." It works along two axes.
- Security analysis : Runs SAST, SCA, DAST, SBOM, IaC, and Secret analyses on your registered services and visualizes results by severity.
- Server monitoring : Installs a lightweight runtime collector on servers to receive and alert on runtime security events centrally.
The goal is to correlate the results of both axes so you can also judge whether a vulnerable component is actually being exploited.

Where to start
As results accumulate
Analysis results become an organization-wide risk view rather than a scattered list. Discovered items are prioritized by severity and KEV, organized as false positive or accepted risk, and tracked down to how well you meet each standard.
How this guide is organized
This guide is organized around service types. Once you pick the target you want to register, the analyses available for that type and how to read the results are all gathered in one section. You can expand each section in the left sidebar.
- Getting started : Quick Start, Core concepts and terms.
- Source code : SAST, SCA, Secret, IaC, SBOM · License.
- Container image : Image SCA, SBOM · Hardening.
- Web service (DAST) : Domain ownership verification and dynamic checks.
- Server / host : OS vulnerabilities, Infrastructure checks, Runtime monitoring.
- SBOM upload : Analyze component vulnerabilities and licenses with an SBOM you already have.
- Use results : Dashboard, Triage, Compliance, Security score, Reports · VEX, Security news.
- Organization and operations : Members and Roles, SLA, Notification channels, Audit log, Billing · Plans.
- Reference : Plans and feature coverage, Status dictionary, Glossary, FAQ.