Security across your entire stack
Find what puts your data at risk.
Native security for your applications, cloud, AI, data, and APIs. Find the risks that matter. Move forward with evidence and AI-assisted fixes.
Start for free · Explore the platform
Free forever plan · No credit card required
The HTSOne Platform
Five security disciplines. Our own scanning engines. Discover the risks that matter, investigate with evidence, and act with supported fixes.
Application Security (ASPM)
Bring native scanning, application posture, and AI-assisted triage into one place. Review coverage, investigate prioritized findings, and move supported fixes into your development workflow. Includes SAST, SCA, DAST, secrets, container, IaC, and mobile scanning with SBOM, CryptoBOM, correlation, and configurable dependency/container update proposals.
Cloud Security (CSPM)
Review the posture of your cloud assets, investigate misconfigurations, and explore connected attack paths. Brings cloud asset inventory, IAM analysis, Kubernetes security, compliance posture, and attack-path analysis into your investigation.
AI Security (AI-SPM)
Track AI security posture and changes across discovered components. Explore AI inventory, agents, and MCP, with discovery coverage and an AI bill of materials (AI-BOM) to support your review.
Data Security (DSPM)
Discover data stores and review how sensitive data is classified. Connect classification evidence with public access, encryption, and scan coverage — including repository data classification, data flows, and framework mappings — to see where investigation is needed.
API Security
Discover APIs from observed traffic and investigate endpoint risk with request, response, and sensitive-data context. Review inventory, runtime relationships, risky endpoints, and security findings in a dedicated workspace.
Hire Your AI Security Engineer
Every paid plan includes 10 team members. Add seats anytime at a fixed price — no per-developer surprises. All prices in INR, exclusive of 18% GST.
Free — ₹0, free forever
Perfect for getting started. 2 members included.
- 3 repositories
- All code scanners — SAST, SCA, Secrets, IaC, Container
- Cloud Security (CSPM) — 1 account
- AI auto-fix — 10 fixes / month
- 3 PR checks & 3 rescans / day
- Email support
Basic — ₹14,080/mo billed annually (₹16,000/mo monthly)
For small teams. 10 members included · ₹1,000/mo per extra seat.
- Everything in Free, plus:
- 100 repositories
- AI auto-fix — 100 fixes / month
- Unlimited PR checks · 25 rescans / day
- Kubernetes security scanning
- Exposure Management
- Build-break CI gates
- 3 cloud accounts
Pro (Recommended) — ₹39,600/mo billed annually (₹45,000/mo monthly)
For growing organizations. 10 members included · ₹1,500/mo per extra seat.
- Everything in Basic, plus:
- 200 repositories
- Unlimited AI auto-fixes
- Advanced K8s & IAM posture — RBAC, policies
- AI Security monitoring (AI-SPM)
- AI Assistant
- Mobile app security
- Jira integration
- SBOM generation
- 10 cloud accounts
Advanced — ₹83,600/mo billed annually (₹95,000/mo monthly)
For organizations with advanced security needs. 10 members included · ₹2,000/mo per extra seat.
- Everything in Pro, plus:
- API Security (runtime API observability)
- Data Security (DSPM)
- 500 repositories
- 20 cloud accounts
Enterprise — Custom Pricing
For large-scale security. Unlimited members — flat rate, known upfront.
- Everything in Advanced, plus:
- Unlimited repositories & cloud accounts
- Multi-tenant architecture
- RBAC, SSO (SAML) & audit logs
- 99.9% uptime SLA
- On-prem scanning & India data residency
- Dedicated support & custom integrations
Frequently Asked Questions
How does HTSOne find vulnerabilities?
HTSOne uses its own scanning engines across application security (ASPM), cloud security (CSPM), AI Security, data security (DSPM), and API Security. Investigate findings with source and asset context, use AI insights during triage, and prepare supported fixes or tickets from the platform.
How does AI help with triage?
AI insights add context to findings, help identify potential false positives, and provide fix recommendations. Your team can review the evidence, update finding status, and decide what needs action.
How do automatic fixes work?
Tinker provides configurable dependency and container autofix settings. It can prepare update pull requests for review. Individual findings also expose available autofix and ticket actions; support depends on the finding and configured workflow.
Which package ecosystems are supported?
The dependency workflow covers npm, PyPI, Maven, Gradle, Go, Cargo, RubyGems, NuGet, and Composer. Tinker includes settings for severity, version strategy, and handling transitive dependencies.
Can I connect my existing development workflow?
HTSOne includes GitHub and GitLab connections, pull request security gates, Jira ticketing, and AWS EventBridge integration. Configure the integrations and policies your team needs.
What happens when a private repository becomes public?
Exposure Management tracks visibility events alongside fork and clone activity. Auto-revert can be configured for eligible repositories, with exceptions and review controls. Repository provider restrictions still apply, including restrictions on making public forks private.