Stop manually inspecting raw oscap xccdf eval XML files. POST evaluation payloads directly to TinySAAS to generate executive landscape PDFs and pre-compiled Ansible remediation playbooks for failing rules.
No agent required. Uses standard OpenSCAP CLI and standard HTTPS cURL requests.
Execute oscap xccdf eval using SCAP Security Guide profiles (e.g., ISM, Essential Eight, or DISA STIG) on target nodes.
Send evaluation outputs via POST request to /v1/telemetry using your Organization API key.
Retrieve WeasyPrint landscape audit PDFs showing rule-by-rule diffs alongside tailored Ansible remediation playbooks.
# 1. Run local OpenSCAP scan
$ oscap xccdf eval --profile xccdf_org.ssgproject.content_profile_ism \
--results /tmp/results.xml /usr/share/xml/scap/ssg/content/ssg-rhel8-ds.xml
# 2. Transmit scan payload to API
$ curl -X POST https://api.tinysaas.com.au/v1/telemetry \
-H "X-API-Key: YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{"hostname": "rhel8-node-01", "results_file": "/tmp/results.xml"}'
[HTTP 202] Processing scan payload for host: rhel8-node-01
[+] Generated: report_rhel8-node-01_ism.pdf (WeasyPrint Engine)
[+] Generated: fix_rhel8-node-01_remediation.yml (Ansible Playbook)
Designed specifically to satisfy compliance auditors and system administration teams.
Outputs structured landscape PDF documents containing pass/fail ratios, failing rule IDs, and historical compliance score trends over time.
Extracts failed rule IDs (such as sshd, auditd, or sysctl settings) and maps them to idempotent Ansible playbooks and shell scripts.
Organizes evaluations by target hostname inside an expandable web dashboard to track compliance across multiple Linux hosts.
Select a developer key for testing or request self-hosted container deployment.
For standalone testing and development hosts.
For IT consultancies and multi-host environments.
Air-gapped Podman / Quadlet container deployment.