How-To: Visualize Security Posture and Compliance Radar

This guide covers viewing and interpreting the real-time Security Posture and Compliance Radar visualizer dashboard.


Accessing the Security Radar

The Security Radar is built directly into the SpecOps 2D visualizer. To start the local visualizer server:


spec-ops visualizer

Navigate to the Security tab or use the deep link:


http://127.0.0.1:8787/#tab=security

To export a self-contained, standalone single-file HTML visualizer bundle including the Security Radar:


spec-ops visualizer export --output dist/project-visualizer.html

The Six Security Posture Dimensions

The radar visualizes repository compliance across six security pillars (0 to 100% score for each axis):

  1. Supply-Chain Lockfile Integrity:
  1. Secret & Credential Detection:
  1. Autonomous Worker Sandboxing:
  1. Dependency Vulnerability & License Policy:
  1. Cryptographic Commit Verification & Dual Custody:
  1. Tamper-Evident Merkle Manifest Integrity:

Continuous CI Verification

To gate pull requests and CI pipelines on security compliance:


spec-ops health --security

Any detected high-entropy secret, lockfile drift, or unauthorized shell command exits with a non-zero code, blocking integration before merge.