Introduction
Hashiro is a Continuous Threat Exposure Management (CTEM) platform that gives security teams full visibility into their external attack surface, cloud infrastructure, and vulnerability posture from a single console.
Who is Hashiro for?
- Security teams and SOCs: centralize asset discovery, vulnerability tracking, and remediation across your organization.
- Penetration testers: manage engagements end-to-end with scoping, asset enumeration, finding documentation, attack chains, and report generation.
- MSSPs and security providers: serve multiple clients from one platform with tenant isolation, white-labeled reporting, and aggregated estate dashboards.
- Enterprises: maintain continuous visibility into your external exposure and cloud posture without assembling a patchwork of point tools.
Core Capabilities
Attack Surface Management (EASM)
Continuously discover and monitor your external attack surface. Hashiro enumerates subdomains, probes HTTP services, detects technologies, captures screenshots, and flags exposed services on a schedule you define.
Cloud Security
Connect your cloud accounts (AWS, Azure, GCP) to detect misconfigurations, track compliance against CIS benchmarks, and monitor your security posture across providers.
Projects
Manage security assessment engagements: penetration tests, bug bounty programs, and security reviews. Define scope, track assets, document findings, build attack chains, and generate PDF reports.
AI-Powered Assessments
Run autonomous security assessments driven by AI agents. Configurable agent types execute multi-stage pipelines (discovery, vulnerability analysis, exploitation, and reporting) with human-in-the-loop or fully autonomous modes.
Vulnerability Management
Track security findings through their full lifecycle: draft, open, retesting, remediation, and closure. CVSS v3.1 scoring, audit trails, AI-assisted review, and candidate verification workflows keep your team aligned.
Inventory & Explore
Search and filter across all assets, URLs, services, and findings across every project in your organization. Faceted filtering by technology, web server, CDN, and more.
Templates
Reusable vulnerability templates, custom Nuclei scanning templates, and LaTeX-based report templates accelerate consistent, professional output.
Integrations
Bidirectional Jira integration, API tokens, the Galileo CLI, and webhook support connect Hashiro into your existing workflows.
How the Platform is Organized
| Section | Purpose |
|---|---|
| Dashboard | At-a-glance KPIs, trends, and alerts |
| Attack Surface | EASM asset discovery and monitoring |
| Cloud | Cloud security posture management |
| Projects | Security assessment engagements |
| Inventory | Cross-project asset search |
| Explore | Full-text and regex search across all data |
| Calendar | Project timeline planning |
| Templates | Vulnerability, Nuclei, and report templates |
| AI Library | Agent types, checklists, schedules, connectors |
| Organization | Team, roles, integrations, settings |
Multi-tenant by design
Hashiro supports provider organizations (security firms) managing multiple client organizations, as well as standalone organizations using the platform directly. Tenant isolation is enforced at every layer.
Next Steps
- Quick Start: set up your account and run your first scan
- Authentication: learn about login, MFA, and API tokens