Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.
In this guide
What does Decloak support for continuous security checks?
Decloak does not include a built - in scheduler, but its REST API lets you trigger scans on any cadence you choose. By calling the API from a CI job or cron, you get automated checks that you can store and compare yourself.
How can I schedule scans with Decloak?
Create a simple cron job (or CI pipeline) that calls POST /api/v1/scans with your API key and target URL. The request returns a scan ID which you can poll for completion. Example using curl:
#!/usr/bin/env bash
API_KEY="<your_api_key>"
TARGET="https://example.com"
SCAN_ID=$(curl -s -X POST https://app.decloak.com/api/v1/scans \
-H "Authorization: Bearer $API_KEY" \
-H "Content-Type: application/json" \
-d "{\"url\": \"$TARGET\"}" | jq -r .id)
# Wait for the scan to finish (polling example)
while true; do
STATUS=$(curl -s -H "Authorization: Bearer $API_KEY" \
https://app.decloak.com/api/v1/scans/$SCAN_ID | jq -r .status)
[[ $STATUS == "completed" ]] && break
sleep 5
done
# Download the report HTML for later reference
curl -s -H "Authorization: Bearer $API_KEY" \
https://app.decloak.com/api/v1/scans/$SCAN_ID/report > "report-$SCAN_ID.html"
Add the script to a cron entry such as 0 2 * * * /path/to/decloak-scan.sh for a daily run.
How do I generate regression diffs between scans?
Store each HTML report with a timestamped filename (e.g., report-2024-10-07.html). You can also request the JSON payload of the findings via the API if your plan provides it; otherwise, extract the findings block from the HTML using a tool like pup or xmllint. A minimal Bash diff script that works on JSON payloads looks like this:
PREV=$(ls -1 report-*.json | sort | tail -n 2 | head -n 1)
CURR=$(ls -1 report-*.json | sort | tail -n 1)
jq -c '.findings[]' "$PREV" | sort > prev.txt
jq -c '.findings[]' "$CURR" | sort > curr.txt
comm -23 curr.txt prev.txt > new.txt # new findings
comm -13 curr.txt prev.txt > fixed.txt # findings no longer present
The new.txt file lists findings that appeared since the last scan, while fixed.txt lists those that disappeared. Treat disappeared items as fixed and any re - appearing items as regressed.
How can I automatically create remediation tickets?
Both Jira and Linear expose REST APIs that accept JSON payloads. After you generate the new.txt and fixed.txt lists, iterate over each line and POST a ticket.
Jira example (using curl and a basic auth token):
JIRA_TOKEN="<jira_api_token>"
PROJECT_KEY="SEC"
while read -r finding; do
SUMMARY=$(echo "$finding" | jq -r '.title')
DESCRIPTION=$(echo "$finding" | jq -r '.description')
curl -s -X POST -H "Authorization: Basic $JIRA_TOKEN" \
-H "Content-Type: application/json" \
-d "{\"fields\": {\"project\": {\"key\": \"$PROJECT_KEY\"},\"summary\": \"$SUMMARY\",\"description\": \"$DESCRIPTION\",\"issuetype\": {\"name\": \"Task\"}}}" \
https://your-domain.atlassian.net/rest/api/3/issue
done < new.txt
Linear example (using a personal API key):
LINEAR_TOKEN="<linear_api_key>"
while read -r finding; do
TITLE=$(echo "$finding" | jq -r '.title')
BODY=$(echo "$finding" | jq -r '.description')
curl -s -X POST -H "Authorization: Bearer $LINEAR_TOKEN" \
-H "Content-Type: application/json" \
-d "{\"query\": \"mutation { issueCreate(input: {title: \"$TITLE\", description: \"$BODY\", teamId: \"<team_id>\"}) { success } }\"}" \
https://api.linear.app/graphql
done < new.txt
Both scripts create a ticket per new or regressed finding, embedding the exact description Decloak provides.
How do I close the loop when a developer fixes a finding?
When a developer marks a Jira or Linear ticket as Done, you can update a local state file that records the finding ID as resolved. On the next scan, any finding that matches a resolved ID will appear in the fixed.txt list, confirming remediation.
Alternatively, use webhook integrations provided by Jira or Linear to call a small endpoint that records the ticket ID. Your diff script can then cross - reference that record to decide whether to treat a re - appearing finding as regressed or a false positive.
Key takeaways
- Decloak’s API lets you trigger scans on any schedule; use cron or CI to automate.
- Store each scan’s report (HTML or JSON) and diff the
findingsarray to see new, fixed, or regressed issues. - Push new and regressed findings to Jira or Linear via their REST APIs for developer - friendly tickets.
- Track ticket resolution to label findings as fixed in subsequent diffs.
Full workflow checklist
| Step | Command / Action |
|---|---|
| 1. Schedule scan | Add the decloak-scan.sh script to cron or CI |
| 2. Save report | Store HTML or JSON with timestamp |
| 3. Diff reports | Run the jq/comm diff script |
| 4. Create tickets | Use the Jira or Linear curl commands |
| 5. Record resolutions | Update a local state file or webhook endpoint |
| 6. Review regression | Look at fixed.txt and new.txt after each run |
By chaining Decloak’s API with standard CI tooling and issue - tracker APIs, you get a continuous security - check pipeline that matches the desired regression - diff and ticket - automation workflow without needing a dedicated paid scheduler.
Related guides
How can Decloak give auditor - ready proof for SOC 2 and ISO 27001 without weeks of manual work?
Decloak’s free and paid scans generate evidence packages and framework mappings that satisfy SOC 2 and ISO 27001 auditors quickly and automatically.
How can I quickly scan my single-page app for exposed secrets and vulnerable third - party scripts?
Use Decloak’s free 15 - second scan to detect hard - coded keys, outdated libraries, missing SRI and mixed content in a single - page app before a formal audit.
How to Fix a Missing Content - Security - Policy Header
Learn concrete steps to add, test, and harden a Content - Security - Policy header, from server configuration to iterative reporting and verification.