Skip to content
Solutions

One server-side evidence model, several operating views.

EcomScan records stores, scans, findings, alerts, incidents, threat intelligence, and agent health in a tenant-isolated API. The views below describe workflows the repository supports today.

For agencies

Review a high-limit fleet from one workspace.

The enterprise entitlement set supports a large store limit, fleet overview, shared-threat queries, agent status, and response runbook checklists. Per-client tenancy, white-labeling, and client billing are not implemented.

Fleet overviewShared threatsRunbook checklistsWhite-label · not implemented
For merchants

Inspect the server and application layers behind checkout.

Scan store files, optional platform databases, installed components, file changes, and supported host evidence. Findings preserve paths, signatures, severity, confidence, and investigation context.

MagentoWooCommerceHost evidencePCI-oriented assessment
For MSPs & MSSPs

Standardize investigation without pretending to automate containment.

Use generated and operator-authored runbooks as checklists, record notes and resolution, and export incident data. External providers can be configured and tested manually; automatic delivery is not enabled yet.

Incident workflowExportsIntegration testsAuto-dispatch · not implemented
For SOC teams

Add ecommerce file and host evidence to an investigation.

Query alerts, incidents, findings, IOC data, malware families, audit records, and MITRE identifiers through authenticated API routes. Use provider connection tests before wiring your own operational delivery path.

MITRE IDsIOC viewsAudit logTenant isolation
Evaluate the implemented path

Connect a store and inspect a real agent upload.

Start with the free workspace entitlement or review the scanner and API documentation first.