SwyftComply AI

SwyftComply AI is AppTrana's AI-assisted penetration testing and autonomous remediation capability. It finds vulnerabilities, virtually patches the qualifying ones at the WAAP edge, and produces an audit-ready report.

The three outcomes users should expect

Found. AI-assisted penetration testing (AI-PT) probes the application the way a real attacker would, in addition to AppTrana's existing automated assessment engine (AA).

Fixed. Qualifying findings are virtually patched at the WAAP edge automatically. No development sprint is required.

Audit-ready. Every cycle ends in an expert-verified vulnerability and remediation report, ready for auditors covering PCI, RBI, SEBI, IRDAI, and CERT-In.

Accessing SwyftComply AI

Option 1: From the Dashboard

Open the main Dashboard.

Find the promoted SwyftComply AI card at the top. It shows live summary numbers.

Click the card to open SwyftComply AI.

Summary card

SwyftComply AI's metrics are shown both as a summary card on the Dashboard and  as a detailed view inside SwyftComply AI itself.

Option 2: From the left navigation

 

  • Log in to the AppTrana Portal.
  • From the left navigation pane, click SwyftComply AI.

  • If multiple applications are onboarded, use the All Domains drop-down to select the required application.
  • Select the appropriate application

SwyftComply AI Dashboard

The SwyftComply AI Dashboard provides a centralized view of AI penetration testing and protection status across all onboarded applications.

SwyftComply AI -License Pool

The License Pool displays the total number of SwyftComply AI cycles available for the account.

Each time a user starts a new penetration testing cycle or requests a rescan, one cycle is deducted from the available license pool.

The License Pool displays the following information:

Field 

Description 

 Total Cycles  Total SwyftComply AI cycles purchased for the account. 
 Used  Number of cycles already consumed. 
 Remaining  Number of cycles still available for future scans. 

Every new scan consumes one license cycle.

Every rescan also consumes one license cycle.

Both Authenticated and Black-box scans consume one license.

If no cycles remain, new scans cannot be initiated until additional licenses are available.

Dashboard Summary Cards

The Summary Cards provide an overview of the security posture across all enrolled applications.

Apps with AI Pen-Test

The Apps with AI Pen-Test card displays the total number of applications that have successfully completed at least one SwyftComply AI cycle.

This helps administrators understand how many applications are currently covered by AI-assisted penetration testing.

Total Vulnerabilities Found

The Total Vulnerabilities Found card displays the combined vulnerabilities detected across all applications.

The count includes findings generated from:

  • AI Pen-Test (AI-PT)
  • Automated Assessment (AA)

The dashboard also categorizes vulnerabilities by severity: Critical/High/Medium 

This enables users to quickly understand the overall security risk across their applications.

AI-PT and AA Findings

The Total Vulnerabilities Found card separates findings based on their detection source.

Elements Description 
AI-PT Represents vulnerabilities detected using AI-assisted penetration testing. 
AA Represents vulnerabilities identified by AppTrana's Automated Assessment engine. 

Both AI-PT and AA findings are combined to provide a consolidated vulnerability count.

Virtually Patched (CHM)

The Virtually Patched card displays the number of Critical, High, and Medium severity vulnerabilities that have been protected using autonomous virtual patching.

Instead of waiting for application code changes, SwyftComply AI automatically deploys protection at the WAAP layer for eligible vulnerabilities. The percentage represents the overall virtual patch coverage.

Exploits Blocked (CHM)

The Exploits Blocked card displays the number of real attack attempts blocked by SwyftComply AI generated protection rules during the previous 30 days.

The counter only includes exploit attempts targeting Critical, High, and Medium severity findings. This metric helps security teams evaluate how effectively virtual patching is preventing real-world attacks.

Code Fix Required (CHM)

The Code Fix Required card displays the number of Critical, High, and Medium severity vulnerabilities that require modifications to the application's source code.

These findings generally include vulnerabilities that cannot be safely mitigated using WAAP rules and must be remediated by the development team. 

Critical Applications

The Critical Applications section provides a consolidated view of every application enrolled in SwyftComply AI. It enables administrators and security teams to monitor the security posture of individual applications, review the latest assessment results, and initiate additional penetration testing cycles when required.

Each application listed in the table represents a protected web application that has been onboarded to SwyftComply AI.

 

Column Description
Application Displays the name of the protected application or domain. 
Status Indicates the current progress of the SwyftComply AI assessment and remediation cycle. 
Last CycleDisplays the date and time when the latest AI Pen-Test cycle  completed.
Total CHM Findings Shows the combined vulnerabilities detected during the latest assessment.
Virtually Patched (CHM)Displays the number of Critical, High, and Medium severity vulnerabilities protected using autonomous virtual patching.
Code Fix Required Provides actions based on the application's current assessment status, such as Start First Cycle, View Results, or Request Rescan. 
Exploits Blocked (30D) Displays the number of exploit attempts blocked during the previous 30 days for the selected application.
ActionProvides actions based on the application's current assessment status, such as Start First Cycle, View Results, or Request Rescan. 

 

Status

The Status column indicates the current stage of the SwyftComply AI assessment lifecycle.

The status updates automatically as the penetration testing and remediation process progresses.

The following statuses may appear.

Status Description 
Never Run No SwyftComply AI cycle has been initiated for the application. Click Start First Cycle to begin the first assessment. 
Requested The AI-assisted penetration testing cycle is currently running. Findings are populated as the assessment progresses. 
Protection In Progress The vulnerability assessment has completed, and SwyftComply AI is validating findings, deploying virtual patches, and performing expert verification. 
Cycle Completed The assessment and remediation workflow has completed successfully. Users can review findings, download reports, or request a rescan. 
Patched All eligible vulnerabilities have been successfully protected through autonomous virtual patching. 

Action

The Action column provides context-sensitive operations based on the application's current assessment status.

The available options change depending on whether the application has already completed a SwyftComply AI cycle.

Action Description Reference 
Start First Cycle Initiates the first SwyftComply AI assessment cycle for applications that have not been previously assessed. See Start a New SwyftComply AI Cycle
View ResultsOpens the Application View to display the latest assessment results, vulnerability findings, protection status, and reports. See View Application Details
Request Rescan Starts a new SwyftComply AI assessment cycle for an application that has already completed a previous assessment. See Start a New SwyftComply AI Cycle