JustScan Documentation
Set up JustScan

Core concepts

Understand JustScan's scan engines, workspaces, evidence, and policy results.

Scan engines

JustScan can scan with Trivy, optionally augment Trivy results with Grype, or use Artifactory Xray. The selected registry provider determines how an image is analyzed.

Workspaces and organizations

Personal workspaces hold work owned by one user. Organizations provide shared scans, registries, policies, tokens, members, and audit history. Ownership and organization grants control who can see and manage a resource.

Scan evidence

A completed scan includes image metadata, vulnerability findings, SBOM data when available, scanner progress, policy evaluation, and optional comments or manual findings. Scans can be rescanned, compared, exported, shared, or assigned to an organization.

Policy verdicts

Organization policies evaluate scan findings. CI/CD callers receive a final verdict so a workflow can pass, fail, or report an operational error predictably.

On this page