RHEL 8/9 • Debian • ASD ISM • Essential Eight • DISA STIG

Turn Raw OpenSCAP XML Scans Into Landscape Audit PDFs & Ansible Playbooks

Stop manually inspecting raw oscap xccdf eval XML files. POST evaluation payloads directly to TinySAAS to generate executive landscape PDFs and pre-compiled Ansible remediation playbooks for failing rules.

View cURL Example

Ingestion & Processing Pipeline

No agent required. Uses standard OpenSCAP CLI and standard HTTPS cURL requests.

STEP 1

Run Local OpenSCAP Evaluation

Execute oscap xccdf eval using SCAP Security Guide profiles (e.g., ISM, Essential Eight, or DISA STIG) on target nodes.

STEP 2

POST Results JSON/XML

Send evaluation outputs via POST request to /v1/telemetry using your Organization API key.

STEP 3

Download Reports & Fixes

Retrieve WeasyPrint landscape audit PDFs showing rule-by-rule diffs alongside tailored Ansible remediation playbooks.

Terminal Execution bash

# 1. Run local OpenSCAP scan

$ oscap xccdf eval --profile xccdf_org.ssgproject.content_profile_ism \

--results /tmp/results.xml /usr/share/xml/scap/ssg/content/ssg-rhel8-ds.xml

# 2. Transmit scan payload to API

$ curl -X POST https://api.tinysaas.com.au/v1/telemetry \

-H "X-API-Key: YOUR_API_KEY" \

-H "Content-Type: application/json" \

-d '{"hostname": "rhel8-node-01", "results_file": "/tmp/results.xml"}'

[HTTP 202] Processing scan payload for host: rhel8-node-01

[+] Generated: report_rhel8-node-01_ism.pdf (WeasyPrint Engine)

[+] Generated: fix_rhel8-node-01_remediation.yml (Ansible Playbook)

Engineered Core Outputs

Designed specifically to satisfy compliance auditors and system administration teams.

WeasyPrint Landscape PDFs

Outputs structured landscape PDF documents containing pass/fail ratios, failing rule IDs, and historical compliance score trends over time.

Ansible & Bash Playbooks

Extracts failed rule IDs (such as sshd, auditd, or sysctl settings) and maps them to idempotent Ansible playbooks and shell scripts.

Multi-Host Accordion View

Organizes evaluations by target hostname inside an expandable web dashboard to track compliance across multiple Linux hosts.

Access & Licensing

Select a developer key for testing or request self-hosted container deployment.

Developer / Lab

For standalone testing and development hosts.

$0 / month
  • Up to 3 Target Host Nodes
  • PDF Report & Playbook Downloads
  • 30-Day History Retention

Managed Fleet

For IT consultancies and multi-host environments.

$199 / month
  • Up to 50 Target Host Nodes
  • Multi-Host Accordion Web Dashboard
  • 1-Year History Retention

Self-Hosted / On-Prem

Air-gapped Podman / Quadlet container deployment.

Custom
  • Unlimited Host Nodes
  • Air-Gapped Container Setup
  • Custom XCCDF Profile Support