From salesforce, we send data to python(Heroku) and perform some calculations and send the response back to salesforce.
How do I scan python related stuff?
It sounds like you have a REST API versus a web application. No worries as you can scan APIs with Qualys WAS in addition to web applications. It doesn't matter if your API is written in Python or something else. There are different ways to set up scanning against your API. One option is Postman Collection (see https://blog.qualys.com/news/2019/10/07/enhanced-api-scanning-with-postman-support-in-qualys-was ). Another option is to have a Swagger file (see https://blog.qualys.com/technology/2018/04/23/qualys-was-swagger-for-rest-api-security-testing ). Finally, there is the proxy capture method which requires more work (see https://www.qualys.com/docs/qualys-was-crawling-rest-services.pdf ).
Retrieving data ...