Skip to main content

Set up scheduled scans

Configure recurring scan cadences on a project. AISafe runs assessments at regular intervals without manual intervention.

Prerequisites​

  • An AISafe account with manager or higher role
  • A Project created for the repository or target you want to scan

Why schedule scans?​

Codebases change as your team adds dependencies, endpoints, and code paths. A one-off scan shows your security at a single point in time. Scheduled scans check your security posture repeatedly over time, so they catch drift before it turns into an incident.

Step 1: Open the project​

  1. Navigate to Projects in the AISafe dashboard.
  2. Open the project you want to schedule scans for.

Step 2: Configure a schedule​

  1. Go to the Scheduled Scans tab or settings section.
  2. Click Add schedule.
  3. Configure the schedule entry:
    • Cadence: every 8 hours, every 12 hours, daily, weekly, every two weeks, or monthly, at an hour you pick. The form shows that hour in your own time zone and prints the UTC equivalent beside it; the schedule stores UTC, so the local hour moves by one when daylight saving changes. For the cadences that run more than once a day, the hour you pick sets the start of the series, and the other runs follow at the interval you chose: every 8 hours from 09:00 runs at 09:00, 17:00 and 01:00. The free code scan, code audit, and white-box can run as often as every 8 hours, because AISafe skips an occurrence that has no new commit behind it, and a skipped occurrence costs nothing. Black-box has no source to compare, so every run is a full paid pentest, and the most frequent cadence you can choose for it is weekly.
    • Assessment type: choose from the types AISafe marks available for your account. During the current workflow migration, scheduled code audit is the available full-assessment type.
  4. Read the line under the form. It tells you whether this schedule is free or comes out of credits, and roughly what a month of it costs.
  5. Save the schedule.

Step 3: How scheduled scans run​

AISafe's scheduler checks for due occurrences and creates assessments:

  1. At the configured cadence, AISafe checks whether your source changed since the schedule's last completed run. If the source has not changed, AISafe skips the occurrence, shows "No changes since last scan", and bills nothing.
  2. AISafe creates a normal assessment with origin="scheduled".
  3. The assessment runs like any other: it starts from the context in the project's living knowledge base, produces findings, and fires webhook events on completion.
  4. You receive notifications via configured webhooks or Slack integration.

Step 4: Monitor scheduled scans​

Scheduled assessments appear in the normal assessments list, tagged with their origin. You can filter by origin=scheduled to see only scheduled runs. Each scheduled assessment produces findings, reports, and webhook events like a scan you trigger by hand.

The schedule card also shows its latest result and time. A skipped or failed result includes a short reason, such as an overlapping run, a removed source, or a workflow that could not start. If an occurrence would overlap a run that is still going, AISafe uses up that occurrence and the schedule moves on to the next date. AISafe does not run two scans of the same type at the same time.

Combining with monitoring​

Scheduled scans and endpoint monitoring complement each other:

  • Scheduled scans run full assessments on a cadence to find new vulnerabilities
  • Monitoring re-validates existing finding PoCs to catch regressions

Enable both for comprehensive continuous coverage.

Next steps​