05 · OWASP standards
Every OWASP standard, built into the scan.
VamiAppSec maps every finding to OWASP verification standards and testing guides — so an assessment shows coverage per requirement and level, not just a list of bugs. Built for compliance-oriented assessments that auditors, notified bodies and customers recognise.
ASVS
Application Security Verification Standard
SAST, DAST and review findings mapped to ASVS 5.0 requirements — with coverage per chapter and verification level L1–L3.
Web apps & APIsCRA Annex I · ISO 27001
ISVS
IoT Security Verification Standard
Requirements for connected devices — ecosystem, user-space apps, software platform, communication and hardware platform — as the checklist for firmware and device assessments.
IoT & embeddedRED / EN 18031 · IEC 62443-4-2
MASVS
Mobile Application Security Verification Standard
The OWASP MAS baseline for iOS and Android — storage, crypto, auth, network, platform, code, resilience and privacy — mapped from mobile static and dynamic tests.
Mobile appsMDR companion apps · CRA
MASTG
Mobile Application Security Testing Guide (formerly MSTG)
The test cases behind MASVS — every mobile finding references the MASTG test that verifies it, so assessors can reproduce it.
Mobile testingMASVS evidence
WSTG
Web Security Testing Guide
The methodology behind our dynamic tests — VamiDAST, ZAP and Nuclei results carry WSTG test IDs for traceable, repeatable web assessments.
Web testingASVS evidence · pentest reports
AISVS
Artificial Intelligence Security Verification Standard
Verification requirements for AI and LLM systems — model supply chain, prompt-injection defences, output handling and data protection — for teams shipping AI features.
AI & LLM systemsEU AI Act Art. 15 · CRA