Skip to content
AutoST by Zyberum GmbH
Menu

Scoring & evidence

A number you can defend, evidence you can file.

AutoST turns a scan into a single risk score and a report you can put in front of an auditor or a manager, with the detail your engineers need underneath.

In short

AutoST scores the risk of an ECU from its enumeration results. A configurable catalogue of 26 ISO 14229 services carries a risky flag and a weight (0 to 5); the active, non-accepted risky services are summed and normalised to a 0-10 score, and an exposed XCP or CCP interface raises it. Each scan produces a PDF report with an overview, the findings and a non-repudiation footer. The fix plan exports as SARIF, CSV and JSON, and the CI plugin emits JSON and JUnit XML.

Two outputs

A score and a report

Risk score (0-10)

Weighted from 26 ISO 14229 services, configurable per tenant, with risk acceptance factored in. An exposed XCP/CCP interface raises it.

PDF report

An overview, the findings tables and a non-repudiation footer, suitable as verification evidence.

Configurable

Your risk model, not ours

The service risk catalogue is editable per tenant: change which services count as risky and how much each weighs, so the score reflects your threat model.

Risk acceptance and comments carry across re-scans, so an accepted residual risk stays accepted and the report tells the real story over time.

  • Per-tenant risky flags and weights
  • 0-10 normalised score
  • Risk acceptance carried across scans
  • PDF, SARIF, CSV, JSON and JUnit XML output

FAQ

Frequently asked questions

How is the risk score calculated?

From a configurable catalogue of 26 ISO 14229 services, each with a risky flag and a weight from 0 to 5. The active, non-accepted risky services are summed and normalised to a 0-10 score; an exposed XCP or CCP interface raises it.

What is in the PDF report?

An overview, the findings per arbitration ID and session, and a non-repudiation footer. It is designed to serve as verification evidence.

See it on your ECU

See AutoST run against your kind of ECU

Book a one-hour live demo. We scan a real target, walk through the findings and the Fix Plan, and answer whatever you throw at us.

  • A security engineer runs it, not a sales rep
  • Bring your own protocol and hardware questions
  • Free, and a clear next step afterwards
Tom Zaubermann

Your demo is withTom ZaubermannFounder of Zyberum, ex-lead of the VW InCar Security Testing Lab

Already trusted by Tier 1, Tier 2 suppliers and OEMs. References on request.

Call us: +49 176 439 17074automotive@zyberum.com

Or send us a message

We reply within one business day.

Call usBook a demo

Pick a time that suits you

Open in a new tab