programming
securely.
Let’s build something
Back to the journal

Building the scanning foundation for Mayo ASPM

Development is underway on a queued scanning service and the foundations for organizing application security findings.

Security findings become more useful when teams can put them in context and decide what deserves attention. Mayo ASPM is our application security posture management project, bringing together scanning results, prioritization, and policy workflows.

The October development work adds a private queued scanning service in the companion scanner repository. A queue and worker separate incoming scan requests from the work of running checks and collecting results. The implementation also adds checks around submitted inputs and the scanning workflow.

This builds on earlier platform work around parsers, authentication, and policies. It is a development milestone toward a usable security workspace, rather than a claim of comprehensive coverage or a production launch. We will share further updates as the platform and scanner come together.

Project status: actively in development. A public website is not available yet.

Development references