Learn from people who do the work.
Practitioner writing, live training and real customer detail.
Not vendor content marketing. Everything here is written or recorded by people who run vulnerability management for a living.
Resources
Everything we publish, in one place: the blog, case studies, white papers, news, events, the community, and the docs.
Blog
Practitioner writing from the people who ship the platform. How-tos, product deep dives, and the hard lessons of running vulnerability management at scale.
12 posts / 3 authors BrowseCase Studies
Named teams, real numbers, no composite personas.
02 on record BrowseWhite Papers
Buyers guides and eBooks written to be forwarded internally.
07 papers BrowseNews
Press releases and company announcements, straight from the source.
10 releases BrowseEvents
Live training, office hours, and conference talks. Recordings stay ungated.
37 sessions BrowseCommunity
The Slack, the GitHub roadmap, and every release note in the open.
10,000+ organizations BrowseDocumentation
Install, parsers, connectors, and the full API reference.
docs.defectdojo.com BrowseGetting started with DefectDojo
New to DefectDojo? Start with the guides that take you from your first scan import to a prioritized, deduplicated queue.
Install the Community Edition
Clone the repository and run the stack locally. The open source edition is the same core engine, with the parsers and the deduplication model included.
Get it on GitHubImport your first scan
Point a scanner report at DefectDojo and watch it normalize. The docs cover every supported parser and the exact report format each one expects.
Read the docsJoin the community
Ask questions, follow the release notes, and see what other teams are running. The Slack workspace and the release feed are both open.
Go to communityBuild the internal case
Buyers guides and eBooks written to be forwarded: the evaluation criteria, the questions worth asking a vendor, and the numbers that get a budget line approved.
Most downloaded / Buyers Guide
The ASPM Buyers Guide
A structured framework for cutting through scanner noise and unifying application risk across your entire tool stack, with the vendor question set we would ask.
Get the guide
Buyers GuideThe Unified Vulnerability Management Buyers GuideHow to consolidate fragmented scanner data into a single system of action across the full vulnerability lifecycle.
Get
Buyers GuideThe DevSecOps Buyers GuideSelecting a platform that embeds security into every stage of the development lifecycle without slowing engineering.
Get
eBookImplementing AI Across Enterprise Vulnerability ManagementHow AI acts as a force multiplier for teams stuck in manual triage, deduplication, and reporting.
Get See all 07 papersProof, not personas
We only publish what customers put on record. Named teams, measured results, and the part of the program that actually changed.
What is coming up
Live training, monthly office hours, and conference talks. If you miss one, the recording goes up without a gate.
A Slack where people actually answer.
The maintainers are in there. So are the people running Dojo across 10,000 organizations. Ask a real question, get a real answer.
The roadmap, the issues, and every release note live in the open on GitHub. Nothing about how this gets built is a surprise.