Security
Introducing Risk Reruns: Granular Control for Agentic Deep Scans
Introducing Risk Reruns for Agentic Deep Scans—rerun specific risk investigations with customized effort levels, AI models, or parameters without re-uploading assets or starting over.
Thu 06 August 2026
Introducing the Ostorlab Platform MCP Server
Ostorlab now supports MCP, giving AI assistants and agents permission-controlled access to securi...
Thu 06 August 2026
Can SOC 2 Accept an AI-Conducted Penetration Test?
SOC 2 doesn't name a required testing method, so auditors judge evidence, not tools. Here's what ...
Thu 06 August 2026
Introducing Agentic Scan Knowledge: The Scanner That Never Forgets
Agentic Scan Knowledge gives Ostorlab security agents persistent application context, allowing ev...
Wed 05 August 2026
Introducing Ostorlab Mobile Shielding Scan
Ostorlab Mobile Shielding Scan tests Android and iOS protections against real bypasses, including root detection, anti-tampering, certificate pinning, and obfuscation.
Ostorlab vs Aikido: Securing the Full Application Stack
Ostorlab vs Aikido: AppSec Comparison for Web, Mobile, API, and Source Code
Latest posts
Setting the Record Straight: Ostorlab vs. Appknox
A technical correction to Appknox's "Top 10 MAST Tools in 2026" comparison, highlighting the difference between static scanners and Ostorlab's autonomous Agentic Deep Scan platform.
Wed 29 July 2026
XBOW vs Ostorlab, AI Pentesting Compared: Mobile, Web, Source Code & API Coverage
Compare XBOW and Ostorlab's AI pentesting platforms across mobile, web, API, and source code coverage, including shielding validation, app vetting, and post-scan investigation tools.
Tue 28 July 2026
How AI Catches Complex Vulnerabilities: Inside Agentic Pentesting and Exploit Chaining
Discover how agentic AI catches business logic flaws rule-based scanners miss. See a real exploit chain escalating a fixed finding to tenant-wide compromise.
Tue 28 July 2026
Beyond Legacy Mobile AppSec: Why Modern DevSecOps Teams Are Replacing NowSecure with Ostorlab
A detailed comparison of Ostorlab and NowSecure across six key areas, highlighting why modern DevSecOps teams are replacing legacy mobile AppSec tools.
Mon 27 July 2026
The Ostorlab Threat Center Now Supports the EU Vulnerability Database
Ostorlab Threat Center now brings EUVD intelligence alongside NVD data, giving security teams broader vulnerability visibility as they prepare for the EU Cyber Resilience Act.
Fri 24 July 2026
Source Code Security: From Signal to Validated Risk | Ostorlab
Learn how source code security testing works, why traditional SAST creates false positives, and how agentic analysis turns scanner signals into actionable findings.
Thu 16 July 2026
Breaking Down the Latest Version of GoPhish: Source-Code Assessment with Ostorlab Agentic Deep Scan
A technical assessment of the latest version of GoPhish that examines how the platform handles trust: identity, untrusted content, object ownership, credential lifecycle, and outbound requests. Source-code analysis with Ostorlab Agentic Deep Scan established the eight report-level findings, PoCs, and remediation priorities.
Thu 16 July 2026
The Definitive Guide to Mobile App Vetting: Securing the Enterprise App Ecosystem
This comprehensive guide covers the architecture, risk methodologies, and deployment frameworks required to architect an enterprise mobile app vetting strategy that protects corporate data assets without creating operational friction.
Fri 19 June 2026
Changelog
View all changesiOS TestFlight scan, Slack Integrations and other improvements
Mon 10 June 2024
Security Enhancements, Compliance Mapping, and User Experience Upgrades
Fri 13 October 2023