Heimdall©

Security Data Visualization App

Heimdall© is a lightweight NodeJS app that lets you view, store, and compare automated security control scan results.

Heimdall© can ingest data from most commercially available security scanning tools and formats. Just load your data into the application and the MITRE SAF© converter library will do the rest for you.

Check out our demo versions of Heimdall:

  • Heimdall Lite©, which includes the frontend web application for parsing security results
  • Heimdall Demo©, which includes a backend database for storing data (please do not upload anything sensitive)

Heimdall© can be easily deployed as a Docker container. See the docs for installation instructions. Heimdall© can be deployed to Kubernetes via Helm chart.

Visualize Your Security Posture

Load data into Heimdall© for easy sorting, filtering, and summarizing of your security results. Focus on information relevant to security assessments.

Picture of Heimdall application displaying several graphics that summariz security data

Aggregate Your Security Data

Heimdall© automatically converts input security data into a common format (OASIS Heimdall Data Format). Unite all of your security scan output under a single pane of glass. Export your aggregated data into a multitude of common formats supporting assessments.

Picture of Heimdall application demonstrating how mutliple security scans can be displayed at once

Deep Dive Into Your Data

Use Heimdall© to examine each control in your test suite in detail. Determine root causes of failures and see the exact test code that led to each result.

Unknown Image

Prove Security Over Time

Heimdall©’s comparison view shows the delta between two test runs. Tell at a glance if your security posture is improving or needs attention.

Picture of Heimdall application comparing two scans over time
Deploys by Netlify

Copyright © 1997-2026, The MITRE Corporation. All rights reserved.

MITRE is a registered trademark of The MITRE Corporation. Material on this site may be copied and distributed with permission only.