One run against your live product. Every finding proven with a working exploit, every fix verified by a second attack. We test only what you authorise.
You confirm you own the target, or hold written authorisation to have it tested. A scope you do not control is never accepted, and the scope gate is a deterministic rule — not a judgement call.
The agent reads and probes. Writes, deletions and anything persistent require an explicit flag and a second confirmation from you.
Proof is demonstrated with the smallest safe effect — a harmless echo, a canary, a boolean delta. No destructive commands, no binaries fetched, no persistence left behind.
Every attack lands on a disposable copy, never on the product your customers are using. Raw secrets stay out of the report and the logs — only the fact of exposure is recorded.
Rate limiting at ≤10 requests per second, timeouts, a circuit breaker on 5xx storms and an SSRF guard on internal addresses. You can stop a run at any moment.
One run produces one report: what was tested, what was proven, the recommended fix and the re-test result. Remediation is advised — your team applies it; the agent never writes to your code.
Thanks — we've got your details and will get in touch shortly to confirm scope, price and next steps. Nothing is tested before you approve the scope in writing.