Skip to content
WardBee by ScanComb

WardBee, explained precisely.

Answers for teams evaluating cloud evidence, manual reviews, and product assurance. Each answer links to the details behind it, including what needs activation and what the platform does not verify.

Reviewed by ScanComb ·

What is WardBee, and how is it related to ScanComb?

WardBee is ScanComb’s compliance automation platform for engineering and security teams. It collects cloud and repository evidence, runs scoped framework checks, and tracks manual reviews, remediation, and reports. ScanComb also offers security engineering services and the SentryHive and CostHive open-source tools. Mr.D Apps is the independent product studio behind ScanComb and WardBee.

Which cloud and repository integrations are available?

WardBee supports AWS, GitHub, and GitLab. Azure is a limited preview that requires activation; it is not generally available. GCP is not available yet. Collection uses read permissions: AWS uses a cross-account role, repository access is scoped to the selected projects, and Azure uses the built-in Reader role. Review the exact permissions and preview limits before connecting production systems.

Does framework support mean every control is automated?

No. WardBee publishes bundled catalog counts, native check coverage, scanner mappings, and unmapped requirements separately. A mapping can supply evidence for part of a control; it does not prove the whole control is satisfied. The CIS catalog is a limited starter. Educational framework references explain a standard and are not a promise of full product coverage. Missing, stale, conflicting, manual, and error results remain distinct from a confirmed pass.

How much does WardBee cost?

Single: €39 for 1 scan, valid 60 days. Starter: €149 for 5 scans, valid 90 days. Team: €299 for 10 scans, valid 120 days. Flat rate: €449/mo for 40 scans, valid per month, recurring. Scan packs also set framework and report allowances. Optional consultant evidence reviews use separate review credits; some plans include credits. Applicable taxes and the final total appear at checkout. Preview activation and consultant capacity are separate from a purchase.

What counts as a scan, and is evidence sync free?

One scan is one workspace × one framework × one assessment run. Sync now collects integration evidence without consuming a scan. Run check evaluates the latest collected evidence and consumes one scan and one report allowance. A new assessment after a fix consumes another scan. Connecting multiple accounts does not by itself multiply a single framework run. Workspace creation requires no credit card; assessments require a valid allowance.

How does Manual Control Verification work?

Manual Control Verification records an answer, supporting evidence, ownership, and freshness for a control. Depending on the control, the review paths are self-declared, AI check, internal reviewer, ScanComb consultant, AI plus consultant, and external auditor. The review label stays with the evidence. Accepted, fresh manual answers can contribute to framework assessments. The feature requires workspace activation; paid consultant paths also depend on review credits and capacity.

Can AI approve evidence, and does it read uploaded files?

AI cannot override an automated technical result. In Manual Control Verification, a passing pre-check can support acceptance when the user selects the AI path; the result remains labeled AI-checked. In an activated workspace, AI evidence processing is on by default. File contents, including PDFs, images, and extracted Office text, can be sent to Claude through Amazon Bedrock. An administrator can disable new AI evidence processing before upload. AI-checked evidence is not independent auditor approval.

Does WardBee issue ISO 27001 certificates or SOC 2 reports?

No. WardBee produces evidence and review packages; it does not issue an ISO 27001 certificate or an independent SOC 2 attestation. ScanComb consultant reviews are advisory reviews of submitted evidence. A technical pass is scoped to a check and its evidence, not to an organization’s complete compliance. Independent certification or attestation requires the appropriate external assessment.

Which DORA metrics does the Software Delivery preview calculate?

The preview covers deployment frequency, change lead time, failed deployment recovery time, change failure rate, and deployment rework rate. Frequency and lead time use GitHub or GitLab deployment evidence. The incident-linked metrics require GitLab incident evidence and explicit deployment links; without them, the result stays unknown. Reports include source evidence and gaps. CI-reported deployments have no independent runtime confirmation in this preview.

How do CRA product assurance and the NIS2 Supplier Check differ?

WardBee’s CRA product-assurance workspace connects products, releases, SBOMs, vulnerability cases, reporting timelines, and technical files. The free NIS2 Supplier Check is a separate domain-focused check and questionnaire that produces a report mapped to NIS2 Article 21. Neither is a certificate or a complete determination of regulatory compliance. Their evidence scope and data handling are described on their respective pages.

When should I use WardBee, SentryHive, or CostHive?

Use WardBee for a shared compliance workspace with framework assessments, evidence history, reviews, and remediation tracking. SentryHive is an open-source AWS security-report orchestrator for running scanners and producing consolidated reports. CostHive is an open-source AWS FinOps-report orchestrator for cost analysis. Both tools are Apache-2.0 projects that you run yourself. Their repositories document the tools and permissions they require; neither replaces WardBee’s workspace review workflow.

Need to confirm your workspace’s scope or preview access? Talk to a ScanComb engineer.