CSOAI OS · cyber self-scan
Scan your own business. The Council assistant fixes it.
A CISO-grade stack of reputable open-source tools to test your own cyber — network, web, cloud, containers, code, supply chain. Run them, bring the findings, and the Council assistant triages, maps them to the regulations that bite, and guides the fix. Signed to Layer 0.
Map your external footprint — subdomains, exposed services.
amass enum -d yourdomain.comFind exposed emails, hosts, and leaked surface for your org.
theHarvester -d yourdomain.com -b allDiscover open ports and services across your estate.
nmap -sV -sC -oX scan.xml TARGETFull network vulnerability assessment with CVE scoring.
greenbone / gvm-cli — scan TARGETFast template-based checks for known CVEs + misconfigs.
nuclei -u https://yourapp.comDynamic app scan — injection, XSS, auth, session flaws.
zap.sh -quickurl https://yourapp.com -quickout zap.htmlQuick web-server misconfiguration + known-issue scan.
nikto -h https://yourapp.comAWS/Azure/GCP security posture vs CIS + best practice.
prowler awsMulti-cloud config audit with an HTML report.
scout awsScan images, filesystems, and IaC for CVEs + secrets.
trivy image yourimage:tagCheck Kubernetes against the CIS Kubernetes Benchmark.
kube-bench runScan Terraform/CloudFormation/K8s for misconfig before deploy.
checkov -d .Static analysis of Terraform for security issues.
trivy config .Detect hardcoded secrets/keys across your repos + history.
gitleaks detect --source .Fast SAST — find insecure code patterns in your source.
semgrep --config auto .Find known-vulnerable dependencies from the OSV database.
osv-scanner -r .Generate an SBOM (CycloneDX/SPDX) of everything you ship.
syft yourimage:tag -o cyclonedx-jsonAudit Linux/Unix host hardening + compliance posture.
lynis audit systemAutomated compliance scanning against SCAP baselines.
oscap xccdf eval --profile cis ...You are interacting with an AI system.
The triage box sends pasted scanner output to the live Council chat endpoint (councilof.ai/api/gspc), where a model ranks the findings and maps them to frameworks. The Article 50(1) notice is mounted above the input.
Disclosed under EU AI Act Article 50(1). Every surface and its classification
Paste raw output from any tool above. The Council assistant ranks by real risk, gives concrete fixes, and maps each to the frameworks it affects. Your findings stay in your browser.
- ✓You run the tools — your data never leaves your control. Open source, no lock-in.
- ✓The Council assistant maps every finding to the frameworks that bite (NIS2, DORA, CRA, ISO 27001, SOC 2) — not just a scary list.
- ✓Remediation guidance you can act on, prioritised by real risk — then re-scan to prove it's fixed.
- ✓Every fix signed to Layer 0 — provable evidence for auditors and regulators.
- ✓Value back to you and your team — not a five-figure certificate from a governance middleman.