Provable authorization
Ownership challenges, signed scope, and a tamper-evident proof pack — the artifact that separates testing from trespass.
The record
Authorization, testing, and delivery live in the same record. If a control has not been connected, the screen says so rather than implying coverage.
Prove control of the target with a DNS TXT or HTTP challenge, then capture scope, window, and sign-off as a single record.
Run against that record. Time windows, scanner IP validation, and an emergency stop gate every action at the source.
Findings carry CVSS, CWE, evidence, and compliance mapping into one exportable deliverable your client can defend.
Capabilities
Ownership challenges, signed scope, and a tamper-evident proof pack — the artifact that separates testing from trespass.
Testing windows, source validation, and an emergency stop. Nothing runs outside the authorization you recorded.
Nuclei, Nessus, Tenable, Qualys, Rapid7, Burp, OpenVAS, Nmap, Acunetix, SARIF, and CSV normalize into one finding model.
Cross-scanner dedup keys on asset, weakness, and severity so the same issue from three tools is one line in the report.
Map each finding to SOC 2, ISO 27001, PCI DSS, and HIPAA controls without re-labelling evidence by hand.
Every authorization, run, and export lands in the activity trail with actor and timestamp attached.
Where the evidence lives
Findings carry the tool they came from, the asset they hit, their CVSS and CWE identifiers, and the control they map to. Exports are reproducible from the same underlying data, not retyped for a deck.