Skip to main content

Scheduled scans

Scheduled scans let you configure recurring assessment cadences on a project. You set a schedule and AISafe creates and runs assessments at the configured intervals.

Why schedule scans​

Codebases change over time. New dependencies appear, new endpoints open, and patterns that were safe become vulnerable through upstream changes. Scheduled scans catch this drift before it becomes an incident, so your security posture stays accurate over time.

Scheduled scans differ from monitoring: monitoring re-validates known findings, while a scheduled scan runs a full assessment that hunts for new vulnerabilities.

Configure a schedule​

You configure schedules on the project's settings page. Each schedule entry specifies:

  • Cadence: how often the scan runs (every 8 hours, every 12 hours, daily, weekly, every two weeks, or monthly). Eight hours is the shortest cadence. Assessment types that read your source can use it, because AISafe skips an occurrence without billing when there is no new commit behind it. A black-box assessment has nothing to compare, so it stays weekly.
  • Assessment type: an account-specific list loaded from AISafe's current availability rules. During the current workflow migration, scheduled code audit is the available full-assessment type.

When an occurrence is due, AISafe creates a normal assessment for it. Each scheduled assessment runs like any other: it loads context from the project's living knowledge base, produces findings, and reports on completion.

For a project with several connected repositories, AISafe checks every repository against the last completed run of that schedule. A new commit or scope in any of the repositories starts one combined scan. When every repository and the combined content match, AISafe skips the occurrence without a charge. If access to a repository has been revoked, AISafe skips the occurrence with a connection error before charging.

Each schedule shows the latest result, time, and a reason when it skipped or failed. If the same type is already running, AISafe skips that occurrence and moves to the next one instead of starting overlapping work.

Pausing a schedule removes its next run while keeping the cadence settings. When you resume it, AISafe schedules the next occurrence from that moment; it does not run a date that passed while the schedule was paused.

For step-by-step instructions, see Guide: Set up scheduled scans.