Contrast Scan is a Static Application Security Testing (SAST) solution designed to identify application and API vulnerabilities by observing data flows. It utilizes a demand-driven and risk-based static analysis engine to pinpoint exploitable data paths, which is intended to minimize false positives. The system supports over 30 languages and frameworks, delivering analysis directly within developer workflows.
As a pipeline-native tool, Contrast Scan integrates into continuous integration and continuous delivery (CI/CD) pipelines, developer repositories, and build automation processes. It performs code scanning to provide rapid feedback and risk insights during development stages such as commits or pull requests, with the goal of accelerating vulnerability remediation.