Open Architecture: Ounce works the way you do.


Ounce protects your investment in your existing enterprise SDLC and security infrastructure with an open architecture for seamless integration and maximum return.

  • Defect Tracking System: Ounce provides a DTS integration framework that enables you to seamlessly integrate with your existing DTS. The framework enables you to dispatch Ounce issues in conjunction with your existing processes, using your priority and severity nomenclature, and your workflow.

  • SCM and Build Management: The Ounce Automation Server works with a wide range of build processes including IBM Rational BuildForge, Cruise Control, Continuum, Microsoft Team Build, and others. In support of the open source community, Ounce donated a Maven plug-in to Apache to facilitate source code scanning as part of the Maven build process.

  • Dynamic analysis and web application firewalls: Ounce provides an Open API to the assessment database, enabling the manipulation of data for integration with other security systems. Correlate data from a penetration test to pinpoint issues at the line of code, identifying the source of an exploit. Use the results of your Ounce scan to better tune your firewall to protect assets while you work to fix vulnerabilities.


    • Analysis and reporting customization: With Ounce, you can customize the Ounce analysis to fit your policies and critical security concerns. Add vulnerabilities specific to your organization, adjust the severity of existing vulnerabilities, and adjust the priority of those finding of highest criticality to you. Ounce provides the most flexible and customized reporting available: you decide how the information is selected, grouped and represented, for remediation, compliance and risk management reporting you can use.


    WHY OUNCE?
    Enterprise Automation
    | Smarter Results | Open Architecture