# Osto Documentation ## Docs - [Welcome to Osto](https://docs.osto.one/index.md): One platform for security, compliance, and VAPT — built for fast-moving startups and scaling businesses. - [High Level Architecture](https://docs.osto.one/overview/high-level-architecture.md): A look at how Osto sits between the public internet and your environment. - [What is Web Application Protection](https://docs.osto.one/overview/what-is-web-app-protection.md): How Osto's reverse-proxy protection model safeguards your web applications and APIs. - [WAF Availability & Uptime](https://docs.osto.one/overview/waf-availability.md): How Osto keeps your Web App & API Protection (WAF) layer online — our uptime target, how we measure it, the architecture behind it, and how we respond to incidents. - [Core Concepts](https://docs.osto.one/getting-started/core-concepts.md): A short tour of the model Osto uses across every module. - [Quick Start Guide](https://docs.osto.one/getting-started/quick-start.md): Five steps from a brand-new Osto account to a dashboard reporting live security telemetry. Most teams finish in under an hour. - [Asset Management](https://docs.osto.one/how-to-guides/asset-management/index.md): Everything you onboard into Osto for protection — domains, users, servers, and certificates. - [Managing Websites & Subdomains](https://docs.osto.one/how-to-guides/asset-management/managing-websites.md): Add the websites and subdomains you want Osto to protect. - [Managing SSL Certificates](https://docs.osto.one/how-to-guides/asset-management/managing-ssl-certificates.md): Upload and manage the certificates Osto uses to encrypt traffic between your origin and the internet. - [Managing Secure Servers](https://docs.osto.one/how-to-guides/asset-management/managing-secure-servers.md): Register the servers you want Osto to broker Zero Trust access to. - [Managing Users & Groups](https://docs.osto.one/how-to-guides/asset-management/managing-users-groups.md): Onboard your team into Osto and organize them into Usergroups for role-based policy targeting. - [Objects Management](https://docs.osto.one/how-to-guides/objects/index.md): Reusable building blocks — domain categories, application groups, port objects, and schedules — that you reference when defining policies. - [Policy Configuration](https://docs.osto.one/how-to-guides/policy-configuration/index.md): Policies are how you tell Osto what to enforce — what's allowed, what's blocked, and how. - [Website Protection Policy](https://docs.osto.one/how-to-guides/policy-configuration/website-protection-policy.md): Configure how Osto inspects inbound web traffic to your registered domains — global and per-domain policies. - [How to Create a Policy Exception on the Dashboard](https://docs.osto.one/how-to-guides/policy-configuration/how-to-create-a-policy-exception.md): Create a new policy exception in the Osto dashboard to control how traffic matching certain conditions is handled for a selected website. - [User Protection Policy](https://docs.osto.one/how-to-guides/policy-configuration/user-protection-policy.md): Control what people on your team can do from their managed devices — apps, peripherals, websites, and data. - [Secure Server Access Policy](https://docs.osto.one/how-to-guides/policy-configuration/secure-server-access-policy.md): Define who can reach which Secure Server, on which ports, and what happens to unmatched traffic. - [Cloud Security](https://docs.osto.one/how-to-guides/posture-management/index.md): Connect your cloud accounts to Osto for continuous visibility, asset inventory, and security findings across AWS, Azure, and GCP. - [Connecting AWS to Osto](https://docs.osto.one/how-to-guides/posture-management/connecting-aws.md): Securely connect your AWS account to Osto for continuous cloud security posture management. - [Connecting GCP to Osto](https://docs.osto.one/how-to-guides/posture-management/connecting-gcp.md): Securely connect your Google Cloud Platform project to Osto for continuous cloud security posture management. - [Connecting Microsoft Azure to Osto](https://docs.osto.one/how-to-guides/posture-management/connecting-azure.md): Securely connect your Azure subscription to Osto for continuous cloud security posture management. - [Scanner](https://docs.osto.one/how-to-guides/scanner/index.md): Scan your websites and mobile apps for security vulnerabilities with Osto's Web Scanner and App Scanner. - [Web Scanner](https://docs.osto.one/how-to-guides/scanner/web-scanner.md): Scan your registered domains for web vulnerabilities, track a security score, and generate scheduled security reports. - [App Scanner](https://docs.osto.one/how-to-guides/scanner/app-scanner.md): Upload an Android or iOS app package to scan it for vulnerabilities, privacy risks, and hardcoded secrets. - [SAST](https://docs.osto.one/how-to-guides/code-security/sast.md): Connect your Git provider to run static analysis, dependency scanning, and secret detection across your source code. - [AutoComply](https://docs.osto.one/how-to-guides/compliance/autocomply.md): Get your workspace audit-ready — activate a compliance framework, generate policies, track controls and tasks, and run security awareness training. - [Awareness Training](https://docs.osto.one/how-to-guides/compliance/awareness-training.md): Build security awareness training programs, assign them to employees, and track completion — plus the employee experience for completing training and acknowledging policies. - [Logs](https://docs.osto.one/how-to-guides/logs/index.md): Searchable, filterable records of web traffic and threats, secure-server sessions, domain filtering, incidents, admin actions, and authentication events. - [Web App Logs](https://docs.osto.one/how-to-guides/logs/web-app-logs.md): A live record of traffic hitting your protected websites — detected threats, the full access log, and policy violations. - [Secure Server Logs](https://docs.osto.one/how-to-guides/logs/secure-server-logs.md): A record of sessions opened to your secure servers. - [Domain Filtering Logs](https://docs.osto.one/how-to-guides/logs/domain-filtering-logs.md): Endpoint domain requests and the filtering decision applied to each. - [Incident Logs](https://docs.osto.one/how-to-guides/logs/incident-logs.md): A consolidated view of security incidents across the platform. - [Audit Logs](https://docs.osto.one/how-to-guides/logs/audit-logs.md): An accountability trail of configuration and admin actions taken in your workspace. - [Auth Logs](https://docs.osto.one/how-to-guides/logs/auth-logs.md): A record of authentication and session events, including role switches. - [Best Practices](https://docs.osto.one/support/best-practices.md): Recommendations to optimize your security posture and manage the platform efficiently. - [Frequently Asked Questions](https://docs.osto.one/support/faqs.md): Answers to common questions about the Osto platform. - [Troubleshooting Common Issues](https://docs.osto.one/support/troubleshooting.md): Solutions to common problems you may encounter with the Osto platform. - [Glossary](https://docs.osto.one/support/glossary.md): Definitions for the key terms used across Osto and this documentation. - [Getting Help](https://docs.osto.one/support/getting-help.md): How to get support, what to include, and where to find the information Osto's team needs. - [Release Notes](https://docs.osto.one/release-notes.md): Latest updates and improvements to the Osto platform. ## Optional - [Website](https://osto.one) - [Support](mailto:connect@osto.one)