Overview
A portfolio dashboard, risk factors, supply chain map, change over time, and monitoring.
Focusing a lens on the individual pieces that run inside an application can be a time-consuming undertaking. The Analyst Toolkit provides a way to consolidate and understand the services running inside an application, exposure to vendors and entities not previously known, and potential supply chain dependencies that could cause problems in the future.
Every modern website is assembled from parts supplied by other people. A single page load can quietly reach out to dozens of other companies: an analytics provider, an advertising network, a font service, a video player, a chat widget, a payment processor, a content delivery network, a fraud detection service. Each of those is a supplier. Each is a place where data can leave, where code you did not write can run, and where a problem in someone else's business can become a problem in yours.
That collection of suppliers is your digital supply chain, and for most organizations it is invisible. SCVue makes it visible.
SCVue records the network activity of a web application, every request it makes, every file it loads, every server it talks to, every cookie it sets, and then analyzes that recording from more than forty different angles: who the traffic went to, where in the world those servers sit, who owns them, what the code is doing, what personal information is being transmitted, whether security protections are configured correctly, and which real world companies sit behind it all.
The toolkit has eight reporting sections to visualize and document many of the findings needed to answer questions about your digital supply chain. Over time, the web of services and vendors that influence an application can become a risk, and a risk not easy to react to in the short term.
Capturing a live session from a browser will provide more insight into what runs in an application than a third-party vendor or internal development team can prove. The only way to see what code is running and generating traffic is to analyze it at a granular level. That is one of the advantages of using the Analyst Toolkit: it organizes and identifies the knowns and unknowns.
A portfolio dashboard, risk factors, supply chain map, change over time, and monitoring.
The raw record of what the application did on the network.
Read moreEverything the application loaded, organized by what kind of thing it is.
Read morePhysical & corporate reality behind the traffic: whose servers, network, where.
Read moreWhere information goes, where it comes to rest, and whose law governs it.
Read moreWhether the application is configured to defend itself, runtime scripting.
Read moreThe real-world companies, people, and products behind the technology.
Read moreEverything named inside the files, whether or not it was ever contacted.
Read moreTrustworthiness, reliability and resiliency are often based on principles adopted inside an organization, and implementing that principled process is more complex than organizations give it credit for. Rarely is it one person's job to execute, and responsibility can be delegated to different people at different points in time.
The Analyst Toolkit provides real-time validation of an application's behavior that can be shared with a team. Optional private or cloud storage for application captures and processing gives you the tools you need to protect and share this information the right way. Teams decide where evidence is stored and who can access it.
All data stays in the browser. Nothing leaves the machine, nothing is uploaded, nothing is shared.
Team access, cross-device work, and server-run monitoring make it easy for teams. PII is stripped from a capture at the moment it is uploaded, so none of it is ever stored in the cloud.
The toolkit reports and analytic functions are provided to named team members with the approved roles. Access can be changed at any time.
Nothing in the Analyst Toolkit asks to be taken on trust. Behind every row is the captured request that produced it, with its address, its headers, its content and its timestamp.
47
Capture a session in the browser, import it, and read what comes back. A free community account is available immediately.