Application Security Posture Management (ASPM) platform that aggregates SAST/DAST/SCA scanner findings into a unified dashboard for triaging, tracking, and remediating security vulnerabilities across your application portfolio.
| Feature | Free | Pro |
|---|---|---|
| Findings management & lifecycle | ✓ | ✓ |
| Dashboard with enriched stats | ✓ | ✓ |
| Team-based collaboration | ✓ | ✓ |
| Webhook notifications | ✓ | ✓ |
| RBAC | ✓ | ✓ |
| Issue Tracker (GitHub, GitLab) | ✓ | ✓ |
| Resource-level permissions | ✓ | ✓ |
| Scanner ingest (Semgrep, Trivy, etc.) | ✓ | ✓ |
| Version comparison | ✓ | ✓ |
| SSO / OIDC | ✓ | |
| Audit log | ✓ | |
| MCP Server | ✓ | |
| SLA management (planned) | ✓ | |
| Advanced reporting (planned) | ✓ |
Interactive mode (prompts for admin password, domain, registration):
curl -fsSL https://servasec.com/install.sh | sh -s -- -iBuild from source (local build instead of pulling published images):
curl -fsSL https://servasec.com/install.sh | sh -s -- --local-buildInstall with pro features:
# Pull mode: uses the private backend-pro image from the servasec-pro project (authenticate first)
docker login registry.gitlab.com -u $CUSTOMER_UUID -p $CUSTOMER_TOKEN
curl -fsSL https://servasec.com/install.sh | sh -s -- --proPro features are available with a valid subscription of servasec.
Please refer to servasec.com/pricing to obtain one.
Manual setup (without the install script):
git clone https://github.com/servasec/servasec.git
cd servasec
cp .env.example .env
# Edit secrets (JWT_SECRET, REFRESH_SECRET, CSRF_SECRET, SSC_ADMIN_PASSWORD)
# Pull the published images from registry.gitlab.com
make community
# Or build from source instead
make community-buildLook at https://docs.servasec.com/scanners/overview/ for the complete list of scanners supported.
Yes, servasec is licensed under AGPLv3. Self-host it for free, forever. A separate commercial license is required only for Pro features (audit log, MCP Server, SSO, etc).
servasec ingests Semgrep, Trivy, Gitleaks, OSV-Scanner, tfsec, SARIF exports and a lot more ! See supported scanners for details.
See https://docs.servasec.com/getting-started/configuration/
servasec is dual-licensed:
- AGPLv3 - Free, open-source. All standard features included.
- Commercial License - Required for pro features (audit log, MCP, SLA management, advanced reporting).
See LICENSE and COMMERCIAL_LICENSE.md.
# Start dev stack with hot-reload
make dev
# View logs
make logs
# Stop
make downRequires: Docker, Docker Compose, make.