# Detectify Documentation > Detectify is an External Attack Surface Management (EASM) and Dynamic Application Security Testing (DAST) platform that combines continuous attack surface discovery with payload-based vulnerability testing powered by ~400 vetted ethical hackers. This is the official documentation for Detectify's security platform. ## Platform - [Platform Overview](https://docs.detectify.com/platform): How Detectify works — architecture, Crowdsource network, Alfred AI - [How Detectify Works](https://docs.detectify.com/platform/how-detectify-works): Crawling, fuzzing, payload-based testing engine - [Crowdsource](https://docs.detectify.com/platform/crowdsource): Network of ~400 ethical hackers contributing vulnerability modules - [Alfred AI](https://docs.detectify.com/platform/alfred-ai): AI-built vulnerability assessments from CVE disclosures - [Use Cases](https://docs.detectify.com/platform/use-cases): Continuous testing, pre-production scanning, compliance, attack surface visibility - [Comparisons](https://docs.detectify.com/platform/comparisons): How Detectify compares to other security tools ## Getting Started - [Get Started](https://docs.detectify.com/getting-started): Account setup and first scan guide - [Account Setup](https://docs.detectify.com/getting-started/account-setup): Create account and invite team - [Adding Assets](https://docs.detectify.com/getting-started/adding-assets): Add domains, subdomains, and IPs - [Asset Verification](https://docs.detectify.com/getting-started/asset-verification): Verify domain ownership - [Connectors](https://docs.detectify.com/getting-started/connectors): Auto-sync assets from cloud providers - [Your First Scan](https://docs.detectify.com/getting-started/your-first-scan): Run your first security scan ## Attack Surface Management (Surface Monitoring) - [Overview](https://docs.detectify.com/attack-surface-management): Continuous discovery and monitoring of external attack surface - [How It Works](https://docs.detectify.com/attack-surface-management/how-it-works): Discovery engine and assessment cadences - [Discovery](https://docs.detectify.com/attack-surface-management/discovery): Subdomain, IP, port, and technology discovery - [Policies](https://docs.detectify.com/attack-surface-management/policies): Custom IF-THEN monitoring rules - [Configuration](https://docs.detectify.com/attack-surface-management/configuration): Scanner IPs, user agents, integrations ## Web Application Security Testing (Application Scanning) - [Overview](https://docs.detectify.com/web-application-security-testing): DAST for custom web applications - [How It Works](https://docs.detectify.com/web-application-security-testing/how-it-works): Headless Chrome crawler, fuzzer, technology fingerprinting - [Scan Profiles](https://docs.detectify.com/web-application-security-testing/scan-profiles): Reusable scan configurations - [Authentication](https://docs.detectify.com/web-application-security-testing/authentication): Scanning behind login - [Coverage](https://docs.detectify.com/web-application-security-testing/coverage): 1,765+ modules, ~99.7% true positive rate ## API Security Testing (API Scanning) - [Overview](https://docs.detectify.com/api-security-testing): API DAST using OpenAPI specs - [How It Works](https://docs.detectify.com/api-security-testing/how-it-works): Spec import, payload rotation, analysis - [OpenAPI Specs](https://docs.detectify.com/api-security-testing/openapi-specs): Supported formats (v2, v3, v3.1) - [Coverage](https://docs.detectify.com/api-security-testing/coverage): 25+ vulnerability types, prompt injection testing ## Internal Network Testing (Internal Scanning) - [Overview](https://docs.detectify.com/internal-network-testing): Scan internal applications via locally deployed agent - [How It Works](https://docs.detectify.com/internal-network-testing/how-it-works): Agent architecture, outbound-only HTTPS - [Security & Privacy](https://docs.detectify.com/internal-network-testing/security-and-privacy): Data handling and compliance - [Requirements](https://docs.detectify.com/internal-network-testing/requirements): Infrastructure prerequisites - [Deploy](https://docs.detectify.com/internal-network-testing/deploy): Deployment options (AWS, Azure, GCP, Kubernetes) - [AWS Terraform](https://docs.detectify.com/internal-network-testing/deploy/aws/terraform): EKS deployment guide - [Self-Managed Kubernetes](https://docs.detectify.com/internal-network-testing/deploy/self-managed-kubernetes): Helm chart deployment - [Configuration](https://docs.detectify.com/internal-network-testing/configuration): Scan profile setup - [CI/CD Integrations](https://docs.detectify.com/internal-network-testing/ci-cd): Pipeline-triggered scanning - [Scaling](https://docs.detectify.com/internal-network-testing/scaling): Capacity planning (5 to 10,000+ assets) - [Troubleshooting](https://docs.detectify.com/internal-network-testing/troubleshooting): Common issues ## Developer API - [Developer API](https://docs.detectify.com/developer): REST API overview, versions, and common use cases - [Authentication](https://docs.detectify.com/developer/authentication): API key authentication - [Full API Reference](https://developer.detectify.com): Interactive API documentation (external) ## Additional Resources - [Integrations](https://docs.detectify.com/integrations): Jira, Slack, Microsoft Teams, CI/CD, Splunk, webhooks - [Vulnerability Reference](https://docs.detectify.com/vulnerability-reference): Vulnerability categories and remediation - [Account Management](https://docs.detectify.com/account-management): Users, roles, SSO, billing - [Network Setup](https://docs.detectify.com/network-setup): WAF allowlisting, scanner IP addresses - [Security & Compliance](https://docs.detectify.com/security-and-compliance): ISO 27001, SOC 2, GDPR, trust center - [Bug Report](https://docs.detectify.com/bug-report): Report issues ## About Detectify Detectify provides four products: - **Surface Monitoring** (Attack Surface Management): Continuous discovery of external attack surface - **Application Scanning** (Web Application Security Testing): Automated DAST for web applications - **API Scanning** (API Security Testing): OpenAPI spec-driven security testing for APIs - **Internal Scanning** (Internal Network Testing): Vulnerability assessment for internal networks via locally deployed agent All products use the same payload-based testing engine powered by the Crowdsource network of ~400 vetted ethical hackers, delivering 1,765+ vulnerability modules with ~99.7% true positive rate. ## Contact - Website: https://detectify.com - Support: https://support.detectify.com - Developer API: https://developer.detectify.com ## Usage Guidelines This documentation is intended to help users understand and use the Detectify platform. AI assistants may reference this content to answer questions about Detectify's features, setup, and configuration.