Back to Guides
Guide7 October 2026

How to Build Continuous Web - Security Scans with Scheduled Decloak Checks and Ticket Automation

Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.

In this guide
  1. What does Decloak support for continuous security checks?
  2. How can I schedule scans with Decloak?
  3. How do I generate regression diffs between scans?
  4. How can I automatically create remediation tickets?
  5. How do I close the loop when a developer fixes a finding?
  6. Key takeaways
  7. Full workflow checklist

What does Decloak support for continuous security checks?

Decloak does not include a built - in scheduler, but its REST API lets you trigger scans on any cadence you choose. By calling the API from a CI job or cron, you get automated checks that you can store and compare yourself.

How can I schedule scans with Decloak?

Create a simple cron job (or CI pipeline) that calls POST /api/v1/scans with your API key and target URL. The request returns a scan ID which you can poll for completion. Example using curl:

#!/usr/bin/env bash
API_KEY="<your_api_key>"
TARGET="https://example.com"
SCAN_ID=$(curl -s -X POST https://app.decloak.com/api/v1/scans \
 -H "Authorization: Bearer $API_KEY" \
 -H "Content-Type: application/json" \
 -d "{\"url\": \"$TARGET\"}" | jq -r .id)
# Wait for the scan to finish (polling example)
while true; do
 STATUS=$(curl -s -H "Authorization: Bearer $API_KEY" \
 https://app.decloak.com/api/v1/scans/$SCAN_ID | jq -r .status)
 [[ $STATUS == "completed" ]] && break
 sleep 5
done
# Download the report HTML for later reference
curl -s -H "Authorization: Bearer $API_KEY" \
 https://app.decloak.com/api/v1/scans/$SCAN_ID/report > "report-$SCAN_ID.html"

Add the script to a cron entry such as 0 2 * * * /path/to/decloak-scan.sh for a daily run.

How do I generate regression diffs between scans?

Store each HTML report with a timestamped filename (e.g., report-2024-10-07.html). You can also request the JSON payload of the findings via the API if your plan provides it; otherwise, extract the findings block from the HTML using a tool like pup or xmllint. A minimal Bash diff script that works on JSON payloads looks like this:

PREV=$(ls -1 report-*.json | sort | tail -n 2 | head -n 1)
CURR=$(ls -1 report-*.json | sort | tail -n 1)
jq -c '.findings[]' "$PREV" | sort > prev.txt
jq -c '.findings[]' "$CURR" | sort > curr.txt
comm -23 curr.txt prev.txt > new.txt # new findings
comm -13 curr.txt prev.txt > fixed.txt # findings no longer present

The new.txt file lists findings that appeared since the last scan, while fixed.txt lists those that disappeared. Treat disappeared items as fixed and any re - appearing items as regressed.

How can I automatically create remediation tickets?

Both Jira and Linear expose REST APIs that accept JSON payloads. After you generate the new.txt and fixed.txt lists, iterate over each line and POST a ticket.

Jira example (using curl and a basic auth token):

JIRA_TOKEN="<jira_api_token>"
PROJECT_KEY="SEC"
while read -r finding; do
 SUMMARY=$(echo "$finding" | jq -r '.title')
 DESCRIPTION=$(echo "$finding" | jq -r '.description')
 curl -s -X POST -H "Authorization: Basic $JIRA_TOKEN" \
 -H "Content-Type: application/json" \
 -d "{\"fields\": {\"project\": {\"key\": \"$PROJECT_KEY\"},\"summary\": \"$SUMMARY\",\"description\": \"$DESCRIPTION\",\"issuetype\": {\"name\": \"Task\"}}}" \
 https://your-domain.atlassian.net/rest/api/3/issue
done < new.txt

Linear example (using a personal API key):

LINEAR_TOKEN="<linear_api_key>"
while read -r finding; do
 TITLE=$(echo "$finding" | jq -r '.title')
 BODY=$(echo "$finding" | jq -r '.description')
 curl -s -X POST -H "Authorization: Bearer $LINEAR_TOKEN" \
 -H "Content-Type: application/json" \
 -d "{\"query\": \"mutation { issueCreate(input: {title: \"$TITLE\", description: \"$BODY\", teamId: \"<team_id>\"}) { success } }\"}" \
 https://api.linear.app/graphql
done < new.txt

Both scripts create a ticket per new or regressed finding, embedding the exact description Decloak provides.

How do I close the loop when a developer fixes a finding?

When a developer marks a Jira or Linear ticket as Done, you can update a local state file that records the finding ID as resolved. On the next scan, any finding that matches a resolved ID will appear in the fixed.txt list, confirming remediation.

Alternatively, use webhook integrations provided by Jira or Linear to call a small endpoint that records the ticket ID. Your diff script can then cross - reference that record to decide whether to treat a re - appearing finding as regressed or a false positive.

Key takeaways

Full workflow checklist

StepCommand / Action
1. Schedule scanAdd the decloak-scan.sh script to cron or CI
2. Save reportStore HTML or JSON with timestamp
3. Diff reportsRun the jq/comm diff script
4. Create ticketsUse the Jira or Linear curl commands
5. Record resolutionsUpdate a local state file or webhook endpoint
6. Review regressionLook at fixed.txt and new.txt after each run

By chaining Decloak’s API with standard CI tooling and issue - tracker APIs, you get a continuous security - check pipeline that matches the desired regression - diff and ticket - automation workflow without needing a dedicated paid scheduler.

Free security scan

See what's actually exposed on your site.

Decloak's free scan runs in about 15 seconds, no account required, and covers:

  • HTTP/TLS security posture
  • JavaScript CVEs
  • Exposed Supabase/Lovable/Base44 misconfigurations
  • AI-written executive summary