🛡️ Security Audit · 32 Modul Scanner · Evidence-Driven · Non-Destruktif

Audit Keamanan
Selengkap Platform Security.

Dari DNS sampai smart contract, dari server Linux sampai Kubernetes. Semua finding berbasis evidence, risiko dihitung kontekstual, coverage transparan, dan laporan historis PDF + SARIF.

32
Modul Scanner
9+
Domain Audit
100%
Evidence-Driven
PDF+SARIF
Laporan Standar

Cakupan Target

Satu Produk, Semua Aset Anda

Tambahkan target, verifikasi kepemilikan, lalu audit. Semua terhubung dalam satu project & satu laporan.

🌐

Domain / Website

DNS, TLS, HTTP, email, subdomain, DAST

📦

Repository

SAST, SCA, secret, SBOM, IaC, CI/CD, Noir

🐳

Docker Image

Trivy image, Dockerfile, supply chain

🖥️

Server / OS

SSH, 2FA, firewall, IDS/FIM, rootkit, sysctl

☸️

Kubernetes

RBAC, NetworkPolicy, PSS, workload

☁️

Cloud

AWS, GCP, Azure, Alibaba — read-only

🗄️

Database

PostgreSQL & MySQL read-only

⛓️

Web3 / Mobile

Smart contract (Slither), APK (MobSF)

32 Modul Scanner

Semua Fitur Audit, Tidak Ada yang Terlewat

Setiap scanner menghasilkan evidence mentah yang di-normalisasi ke Universal Finding Schema.

🌐 External & OSINT

external_dns

DNS Audit

Record DNS, SPF/DKIM/DMARC, MTA-STS, DNSSEC.

external_tls

TLS/SSL Audit

Sertifikat, cipher, protokol, kelemahan TLS.

external_http

HTTP & Header Audit

Security headers, redirect, konfigurasi web server.

external_email

Email Security

SPF, DKIM, DMARC, MTA-STS, DANE.

external_ports

Port & Service

Port terbuka & service exposure.

external_subdomain

Subdomain Enumeration

CT log (crt.sh), DNS resolve, CNAME takeover.

external_osint

OSINT / Email Harvest

theHarvester — email & breach exposure (opsional).

💻 Application & Supply Chain

app_sast

SAST — Semgrep

Static analysis OWASP/CWE: injection, XSS, SSRF.

app_sca

SCA — Trivy

CVE dependency & package vulnerability.

app_secrets

Secrets — Gitleaks

API key & credential terlanjur di repo.

app_sbom

SBOM — Syft

CycloneDX inventory komponen software.

docker_image

Docker Image — Trivy

Vulnerability container image + Dockerfile.

iac

IaC — Checkov

Misconfiguration Terraform/CloudFormation/K8s YAML.

cicd

CI/CD Security

GitHub Actions: third-party action, permission, OIDC.

app_surface

Attack Surface — Noir

Ekstrak endpoint/parameter/GraphQL/OpenAPI dari kode.

🛠️ DAST — Web Application Testing (Aman & Non-Destruktif)

dast

ZAP Baseline

Spider + passive scan tanpa active attack.

dast_active

Active Safe Probes

Headers, cookie flags, CORS, reflected input.

dast_fuzz

Fuzzing Aman

GET-only fuzzer + payload library (XSS/SQLi/SSTI).

dast_auth

Authenticated Testing

Login form + probe halaman authenticated (TTL credential).

dast_proxy

Proxy 3-Gate

Baseline → attack → compare untuk konfirmasi refleksi.

dast_browser

Browser DOM XSS

Puppeteer: cek refleksi di DOM setelah render.

dast_oob

OOB Testing

Out-of-band gate (menunggu callback server publik).

dast_advanced

Web2 Advanced

GraphQL introspection, cache poisoning, CRLF.

🏗️ Infrastructure & Cloud

server_os

Server Hardening

SSH/2FA, sudo, firewall, IDS/FIM, rootkit, AV, sysctl, AppArmor.

k8s

Kubernetes Audit

RBAC cluster-admin, NetworkPolicy, PSS, workload securityContext.

cloud

Cloud CIS

AWS IAM/S3/CloudTrail, GCP project, Azure account, Alibaba.

database

Database Audit

PostgreSQL/MySQL read-only: SSL, superuser, config.

🤖 Runtime · LLM · Web3 · Mobile

runtime

Runtime / eBPF

Deteksi behavioral (Falco/eBPF — placeholder fase lanjut).

llm

LLM Security

Prompt-injection & OWASP LLM Top 10 (placeholder).

web3_audit

Web3 / Smart Contract

Slither — audit kontrak Solidity.

mobile_audit

Mobile APK/IPA

MobSF — modul terpisah opsional.

Fitur Platform

Lebih dari Scanner — Platform Posture Lengkap

🔬

Evidence Immutable

Raw output + SHA-256 + scanner version + timestamp. Tidak ada finding tanpa bukti.

🧮

Risk Engine Kontekstual

CVSS + exploitability + exposure + criticality + threat intel. Versioned & reproducible.

📊

Security Score + Coverage

Skor jujur, coverage %, blind spot eksplisit. NOT ASSESSED ≠ PASS.

🕰️

Historis & Compare

Audit immutable, bandingkan #N vs #M, deteksi regresi & tren skor.

📄

PDF + SARIF

Executive & Technical PDF, plus export SARIF 2.1.0 untuk CI/CD.

🤖

AI Analyst

Menjelaskan finding & executive summary di atas evidence — tidak mengarang.

🛰️

Threat Intel

EPSS, CISA KEV, OSV, URLhaus — enrichment otomatis per finding.

🕸️

Attack Path

Graph + recursive CTE: Internet → target → finding → data.

⚖️

Compliance Mapping

OWASP Top 10 & CIS Controls v8 — status PASS/FAIL/WARNING per control.

🔐

Authorization Gate

DNS TXT, HTTP file, meta tag, GitHub, agent, kubeconfig, cloud role, DB marker.

🚦

Rules of Engagement

Staging-only default, throttle, avoid/focus, max duration, kill-switch.

7-Question Gate

Validasi setiap finding: evidence, severity, remediasi, bebas secret/PII.

📚

Bug-Hunting KB

17 kelas vulnerability + CWE/OWASP + safe payloads + remediasi.

🗂️

Risk Register & Ops

Risk register, exceptions (TTL), incidents, detections, BAS runs.

🤝

Webhooks & API

HMAC webhook critical finding + REST API token scope `security`.

🧩

Agents & Integrations

Agent server read-only + integration kubeconfig/DB/cloud encrypted.

📁

Projects & Multi-Target

Kelola banyak project, banyak target per project, dan riwayat audit terpisah.

📋

Audit Management

Queue scan jobs, status QUEUED/RUNNING/PARTIAL/COMPLETED/FAILED, detail per job.

🔄

Finding Lifecycle

Status lengkap: OPEN → ACKNOWLEDGED → IN_PROGRESS → MITIGATED → RESOLVED, plus ACCEPTED/FALSE_POSITIVE/REOPENED.

📈

Score Trend

Grafik tren skor lintas audit & project — lihat perbaikan atau regresi secara historis.

💳

Plan Quota & Usage

Dashboard kuota: target aktif, audit bulan ini, concurrent audit, AI reports, retensi.

Pemakaian AI

AI Membantu Menjelaskan, Bukan Mengarang

AI Analyst bekerja di atas evidence final — tidak pernah mengubah finding, severity, atau skor.

📝

Executive Summary Otomatis

Ringkasan eksekutif untuk PDF: kondisi keseluruhan, risiko utama, dan rekomendasi prioritas — semua merujuk evidence_id.

🔍

Explain Finding

Klik satu finding → AI menjelaskan dampak, akar masalah, dan langkah remediasi dengan sitasi evidence yang bisa diverifikasi.

⚙️

Ditenagai AI Gateway FlazHost

Tanpa BYOK — semua pemakaian AI lewat AI Gateway FlazHost. Kuota token & harga overage mengikuti plan AI Gateway; overage otomatis dipotong dari saldo.

🛡️

Safety-First AI

Output disimpan terpisah di AI Notes, ada disclaimer + review manusia, dan dilindungi dari prompt injection.

Kuota AI per plan — token quota AI Gateway + laporan informatif:
Free
Nonaktif
AI tidak tersedia — upgrade untuk mengaktifkan
Pro
Token AI Gateway
Kuota token/bulan + overage per 1k token dari saldo · 10 AI report informatif
Enterprise
Custom
Kuota token lebih besar + dukungan khusus

Contoh Output

Lihat Seperti Apa Hasil Audit

Contoh ilustrasi — angka bukan hasil audit asli Anda.

Security Score — flazhost.com
74.2/100
AUDIT #12 · COMPLETED
2
CRITICAL
5
HIGH
8
MEDIUM
12
LOW/INFO
Audit Coverage 64% — score dihitung hanya dari domain yang dinilai.
Blind spots: database (0%), cloud (0%), k8s (0%)
Attack Path Teratas
Internet app.flazhost.com SQL Injection Sensitive Data
Risk path: 82.5 · 4 hop · 1 finding HIGH
Compliance (contoh)
OWASP A03 — InjectionFAIL
OWASP A05 — MisconfigWARNING
CIS 4.1 — Secure ConfigPASS
FindingSeverityRiskStatusEvidence
SQL Injection pada /api/searchHIGH72.4OPEN3 evidence · SHA-256
Security headers tidak lengkapMEDIUM41.0OPEN2 evidence · SHA-256
Subdomain takeover potensial: staging.flazhost.comHIGH68.8OPENCNAME → GitHub Pages
CORS memantulkan origin arbitrerHIGH65.1OPENdast_active · request/response
GraphQL introspection terbukaMEDIUM44.0OPENdast_advanced · introspection JSON

Export SARIF 2.1.0

untuk GitHub Code Scanning / CI-CD
{
  "$schema": "https://json.schemastore.org/sarif-2.1.0.json",
  "version": "2.1.0",
  "runs": [{
    "tool": { "driver": { "name": "FlazHost Security Audit", "version": "1.0.0" } },
    "results": [{
      "ruleId": "sqli-7f3a...",
      "level": "error",
      "message": { "text": "SQL Injection pada /api/search" },
      "locations": [{ "physicalLocation": { "artifactLocation": { "uri": "app.flazhost.com" } } }]
    }]
  }]
}

Cara Kerja

Dari Aset ke Keputusan

01

Tambah & Verifikasi

Domain, repo, server, k8s, cloud, DB — dengan Ownership & Authorization Gate.

02

Scan → Evidence

32 scanner berjalan di sandbox, evidence disimpan immutable + SHA-256.

03

Normalize → Risk

Universal Finding Schema + Risk Engine + 7Q Gate + Threat Intel.

04

Skor & Laporan

Dashboard, PDF Executive/Technical, SARIF, compliance, attack path.

Keamanan Platform

Audit Kuat, Tetap Aman

🧱

Sandbox Docker

--cap-drop ALL, no-new-privileges, memory/cpu/pids limit, egress terbatas.

🛡️

SSRF Guard

Semua koneksi ke target divalidasi — blokir IP privat/metadata & DNS rebinding.

🚦

Staging-Only Default

Active test hanya di staging; produksi butuh override + alasan.

🔑

Kredensial Encrypted

cryptoService + TTL pendek + mask di UI, tidak pernah plaintext.

Harga Transparan

Pilih Sesuai Kebutuhan Kamu

Semua harga dalam Rupiah. Tanpa biaya tersembunyi. Upgrade kapan saja.

Security Audit Free

Audit eksternal 1 domain + 4 audit/bulan + retensi 7 hari. Cocok untuk mencoba produk.

Gratis
  • 1 target aktif
  • 4 audit/bulan
  • Retensi histori 7 hari
  • Audit Domain / Website / API (DNS, TLS, HTTP, Email)
  • AI Analyst nonaktif
  • PDF Executive Report (watermark)
Mulai Sekarang →

Security Audit Pro

Hingga 10 target, 60 audit/bulan, retensi 90 hari, PDF Executive + Technical, API & webhook, AI Analyst terbatas.

Rp 149.000 /bln
Rp 1.609.200/thn (hemat ~10%)
  • 10 target aktif
  • 60 audit/bulan
  • Retensi histori 90 hari
  • Audit Domain / Website / API (DNS, TLS, HTTP, Email)
  • Audit Source Code Repository (SAST, SCA, Secrets, SBOM, IaC, CI/CD)
  • Audit Server / OS (via agent)
  • Audit Kubernetes Cluster
Mulai Sekarang →

Butuh paket khusus atau volume enterprise? Hubungi tim sales kami →

Siap Membuktikan Keamanan Anda?

Mulai dari paket Free — audit domain pertama gratis. Upgrade untuk repo, server, cloud, K8s, DAST, dan AI Analyst.

Daftar & Mulai Audit →

FAQ

Pertanyaan yang Sering Ditanyakan

Masih ada pertanyaan? Hubungi support kami →

Kenapa FlazHost?

Platform yang Developer Percaya

🇮🇩

Server Lokal Indonesia

Data center di Indonesia. Latency rendah, koneksi cepat untuk user lokal.

🛡️

99.9% Uptime SLA

Infrastruktur enterprise-grade dengan monitoring 24/7 dan auto-recovery.

💬

Support Bahasa Indonesia

Tim support teknis berbahasa Indonesia, siap membantu kapan saja.

💰

Harga Transparan

Semua harga dalam Rupiah. Tidak ada biaya tersembunyi. Bayar sesuai pemakaian.

🚀

Siap Mulai?

Daftar gratis, tidak perlu kartu kredit. Mulai menggunakan layanan FlazHost dalam hitungan menit.

Sudah punya akun? Masuk di sini