Analyst Toolkit

One application is a complex series of parts.

Focusing a lens on the individual pieces that run inside an application can be a time-consuming undertaking. The Analyst Toolkit provides a way to consolidate and understand the services running inside an application, exposure to vendors and entities not previously known, and potential supply chain dependencies that could cause problems in the future.

Every modern website is assembled from parts supplied by other people. A single page load can quietly reach out to dozens of other companies: an analytics provider, an advertising network, a font service, a video player, a chat widget, a payment processor, a content delivery network, a fraud detection service. Each of those is a supplier. Each is a place where data can leave, where code you did not write can run, and where a problem in someone else's business can become a problem in yours.

That collection of suppliers is your digital supply chain, and for most organisations it is invisible. SCVue makes it visible.

What does the toolkit provide?

SCVue records the network activity of a web application, every request it makes, every file it loads, every server it talks to, every cookie it sets, and then analyses that recording from more than forty different angles: who the traffic went to, where in the world those servers sit, who owns them, what the code is doing, what personal information is being transmitted, whether security protections are configured correctly, and which real world companies sit behind it all.

SCVue risk factors report, showing findings graded High, Warning and Info with category, detail, originating host and URL for each.
Risk Factors: every finding for the current filter selection, sorted by severity, each linked to its evidence.

Questions it can answer

The toolkit has eight reporting sections to visualize and document many of the findings needed to answer questions about your digital supply chain. Over time, the web of services and vendors that influence an application can become a risk, and a risk not easy to react to in the short term.

Who are we actually sending our users' data to?
Not who the vendor contract says. Who the browser actually contacted, on the day you measured it.
Is any of this going somewhere it should not?
SCVue identifies the physical and legal location of the servers involved, so you can see when traffic crosses a border you care about, or lands in a jurisdiction that changes your obligations.
Are we exposed to a company we are not allowed to do business with?
SCVue cross-references the traffic against a curated intelligence catalogue of companies, their owners, their sanctions status, and the influence factors attached to them.
Did something change?
Suppliers change their code without telling you. SCVue captures a baseline and compares later captures against it, so an unannounced change in a third-party script becomes a visible event rather than an invisible one.
Can we prove it?
Every finding traces back to a specific recorded network call, with its address, its response, its content, and its timestamp. Everything can be exported as evidence.

Is it what you expected?

Capturing a live session from a browser will provide more insight into what runs in an application than a third-party vendor or internal development team can prove. The only way to see what code is running and generating traffic is to analyse it at a granular level. That is one of the advantages of using the Analyst Toolkit: it organizes and identifies the knowns and unknowns.

Overview

A portfolio dashboard, risk factors, supply chain map, change over time, and monitoring.

Traffic & Requests

The raw record of what the application did on the network.

Read more
Assets

Everything the application loaded, organised by what kind of thing it is.

Read more
Infrastructure & Hosting

Physical & corporate reality behind the traffic: whose servers, network, where.

Read more
Data Flow & Jurisdiction

Where information goes, where it comes to rest, and whose law governs it.

Read more
Security & Behaviour

Whether the application is configured to defend itself, runtime scripting.

Read more
Entities & Vendors

The real-world companies, people, and products behind the technology.

Read more
References & Exposure

Everything named inside the files, whether or not it was ever contacted.

Read more

Built for privacy and collaboration

Trustworthiness, reliability and resiliency are often based on principles adopted inside an organisation, and implementing that principled process is more complex than organisations give it credit for. Rarely is it one person's job to execute, and responsibility can be delegated to different people at different points in time.

The Analyst Toolkit provides real-time validation of an application's behaviour that can be shared with a team. Optional private or cloud storage for application captures and processing gives you the tools you need to protect and share this information the right way. Teams decide where evidence is stored and who can access it.

Private Workspace

All data stays in the browser. Nothing leaves the machine, nothing is uploaded, nothing is shared.

Cloud Workspace

Team access, cross-device work, and server-run monitoring make it easy for teams. PII is stripped from a capture at the moment it is uploaded, so none of it is ever stored in the cloud.

Named People, Named Roles

The toolkit reports and analytic functions are provided to named team members with the approved roles. Access can be changed at any time.

Evidence only, never a manifest

Nothing in the Analyst Toolkit asks to be taken on trust. Behind every row is the captured request that produced it, with its address, its headers, its content and its timestamp.

47

One capture is enough to start

Capture a session in the browser, import it, and read what comes back. A free community account is available immediately.