Skip to content

Watch every change. Prove every fix.

Technical documentation for Pitangus, the self-hosted, open-source application security platform for small teams.

Pitangus analyzes repositories and container images without running their code. It combines open-source engines, prioritizes findings with exploit intelligence, explains the fix, verifies remediation, and keeps evidence for your team.

Install and run

Check the prerequisites, start the Docker Compose stack, create the first administrator, and run the included demonstration.

Follow the quickstart

Connect your workflow

Connect a GitHub App, review pull requests, import SARIF from CI, route findings to Jira, and send notifications.

Explore integrations

Operate it safely

Configure HTTPS, PostgreSQL, backups, workers, periodic jobs, metrics, and secret storage for a production deployment.

Plan a deployment

Understand the system

Read how the FastAPI API, React panel, workers, PostgreSQL, scan engines, and modular-monolith boundaries fit together.

Read the architecture