RiskSnap runs on your own machine with Docker and you use it in your browser. This guide goes from nothing installed to a finished client review report.
Free to read — no account or registration. About the product · See a finished sample report
RiskSnap ships as a Docker image, so Docker has to be installed and running before the command below will work. If you do not have it: Docker Desktop for macOS and Windows, or Docker Engine on Linux. Open it and wait until it reports that it is running.
Then pick your system and paste the command into a terminal window. It creates a folder for your data, downloads RiskSnap the first time, and starts it in the background.
mkdir C:\risksnap-data
docker run -d --name risksnap `
-p 127.0.0.1:8501:8501 `
-v C:\risksnap-data:/data `
swynnjr/risksnap:0.8.0
mkdir -p ~/risksnap-data && \
docker run -d --name risksnap \
--user "$(id -u):$(id -g)" \
-p 127.0.0.1:8501:8501 \
-v ~/risksnap-data:/data \
swynnjr/risksnap:0.8.0
mkdir -p ~/risksnap-data && \
docker run -d --name risksnap \
--user "$(id -u):$(id -g)" \
-p 127.0.0.1:8501:8501 \
-v ~/risksnap-data:/data \
swynnjr/risksnap:0.8.0
The first run downloads RiskSnap, so it takes longer than later ones.
The command prints a long container ID and returns you to the prompt. That is what success looks like — there is no further output to wait for. Give it a few seconds, then open RiskSnap on your own machine:
http://localhost:8501
This link opens the copy of RiskSnap running on your own computer. It only works once you have run the command above — this website cannot start it for you. If the page does not load straight away, wait a moment and reload: RiskSnap finishes starting after the command returns. You can also check it is running with docker ps.
Why -p 127.0.0.1:8501:8501. This binds RiskSnap's web interface to the loopback address, so it is reachable from your own machine only and is not exposed to your network. Dropping the 127.0.0.1 would publish it on every interface.
Why --user on macOS and Linux. The image runs as a non-root user (uid 999). A Linux bind mount keeps the host directory's ownership, so the folder mkdir just created is not writable by that user. RiskSnap then falls back to a directory inside the container and your scans are lost when the container is removed — with only a line in the container log to say so. Running as $(id -u):$(id -g) makes the container write as you. Docker Desktop on Windows does not have this problem, which is why the Windows command does not need the flag.
Why not a named volume. /data does not exist in the image, so Docker creates a named volume owned by root and the same silent fallback happens. Use the folder mount above.
What has been tested. The Windows command was run end to end against published 0.8.0: scan saved through the browser, container removed and recreated, data still present. The Linux permission condition was reproduced and the --user form verified to fix it, though not on a native Linux host. The macOS command has not been tested.
There are two ways in. The first shows you the findings view in seconds; the second produces a real client report.
On the Scan tab, click Try with sample data. RiskSnap shows a scan result from data bundled with the application, so it needs no file of yours and no network access. From there you can see the findings view and the exports it offers.
What this demo does not do: it is not written to scan history, so it does not produce a baseline comparison or a client review summary. For those, use the full workflow.
Download these two synthetic inventories — a baseline and a later one for the same fictional project:
northwind_baseline.cdx.json
northwind_current.cdx.json
Start with the baseline. In the sidebar under Scan Controls, upload it. Under Scan History, leave Scan destination on Start new project, fill in New project name, and click Run scan.
Findings come from public vulnerability databases at the time you scan, so the exact counts you see will differ from any example on this site.
RiskSnap reads CycloneDX JSON, SPDX JSON, requirements.txt and package-lock.json. For other ecosystems, bring a CycloneDX or SPDX SBOM generated by your own tooling.
A client review summary needs two scans in one project, so RiskSnap has something to compare against.
Your consultancy’s name, contact line and logo go on the report from Settings → Consultancy branding, and apply to every export afterwards.
See a finished example of this report, including the PDF.
Scans, POA&M records, review text and your branding live in the folder you mounted — ~/risksnap-data, or C:\risksnap-data on Windows — not inside the container. Replacing or deleting the container does not lose them.
docker stop risksnapdocker start risksnapAfter starting it again, open http://localhost:8501 as before. Your projects and scans are still there.
RiskSnap is in early access, and every feature is currently available without a licence key. Nothing is gated today: the ⚙ Settings tab says so, and license on the command line reports “Early access — all features are unlocked. No license key is required.” You do not need to buy or enter anything to follow this guide.
That is the arrangement for the current release, not a permanent commitment. Future pricing has not been finalized. If licensing is introduced in a later version, the guidance below is how keys will be applied.
Keys are accepted but not checked in this release: --license-key and the RISKSNAP_LICENSE_KEY environment variable are kept so existing scripts keep working, and are ignored during early access.
On the command line, supply it as an environment variable, which keeps it out of your shell history:
docker run --rm -v ~/risksnap-data:/data \
-e RISKSNAP_LICENSE_KEY=YOUR_KEY \
swynnjr/risksnap:0.8.0 scan /data/your-inventory.json
Every command also accepts --license-key YOUR_KEY inline. Run license to see what the build you are running reports.
Branding is not gated either. Put your consultancy’s name, contact line and logo on reports from ⚙ Settings → Consultancy branding, as in step 3.
Everything the interface does is also available as commands, against the same data folder. Useful for automation; not needed for a first look.
docker run --rm --user "$(id -u):$(id -g)" \
-v ~/risksnap-data:/data swynnjr/risksnap:0.8.0 \
scan /data/your-inventory.json --project "Client A" --format both --output-dir /data
scan — scan an inventory, write PDF and CSVhistory list — projects and their scansdelta — compare two scans in a projectpoam sync, poam set, poam pdf — follow-up recordsbundle — the full evidence package as one ZIPAdd --help to any command for its options.
Questions or issues: security@wynn-systems.com — include a description of what you are seeing, and your licence key if you have one.
Renewals and cancellation: subscriptions renew annually and are billed automatically, with notice before each renewal. Cancel any time by emailing us; access continues to the end of the current paid term.
Full subscription terms are in the Terms and Conditions, §5 (Subscriptions) and §25 (License models).