Use cases

How teams use Cloud Reviewer

Cloud Reviewer unifies SAST, SCA (SBOM), and DAST results and adds prioritization so teams can move from scan to action.

AppSec program overview

Track posture across products, monitor trends, and surface recurring weakness patterns (CWE) that drive risk.

Engineering triage

Filter by product/version, download SBOMs, and quickly identify dependency upgrades and remediation paths.

Release readiness

Run scans from CI/CD and keep results as a system-of-record for audits, comparisons, and regressions.

Scenarios

Example scenarios

A

Release candidate

A pipeline triggers SAST + SCA on a commit SHA; Cloud Reviewer ingests results, compares runs, and the team fixes the highest-impact issues first.

B

Third‑party dependency incident

SCA detects a critical CVE; SBOM confirms impacted services; teams prioritize upgrades across products and versions with traceable decisions.