Anagentrunsthepentest.Theengineholdsthebrakes.
An agent drives real security tools inside isolated containers, one engagement per scope. A pre-tool gate it cannot bypass checks every command, and every state-changing step waits for a person to approve it.
engagement
- pre
- recon
- threat
- vuln
- exploit
- post
- report
- finding
- SQLi candidate · /search
- runs via
- engine run-exploit
- scope
- in scope · acme.com
- until approved
- read-only
scope
- acme.com
- *.acme.com
- 198.51.100.0/24
anything else is blocked
audit log
CH.01·The problem
An agent with security tools and no brakes is a breach you paid for.
A coding agent can wield a scanner, a SQL-injection tool and an exploit framework in minutes. Left alone, it also chooses its own targets, runs destructive flags and decides a finding is real.
CH.02·Follow one engagement
One engagement, from the scope to the signed report.
Each phase writes a folder nobody can backdate. The operator picks the mode once, and the hard gates pause whatever the mode.
CH.03·The brakes
Safety is code that refuses, not a prompt it is asked to follow.
A hook runs before every command the agent sends. A failed check blocks the call, and the agent never sees past it.
Scope is fail-closed
A target in the written scope runs. A target that matches none, including when there is no engagement at all, is blocked.
Checked before it runs
The gate reads each command, matches the target, screens the text and blocks anything it does not allow.
A safe-mode floor it cannot lower
Exploit tools run only through the engine, which injects the safe flags, enforces a timeout and refuses a destructive-flag denylist.
Hard gates pause in both modes
Autonomous mode removes the busywork, not the brakes. The step that changes state waits for a person whatever the mode.
A finding moves only on evidence
The status climbs unconfirmed, probable, confirmed, and each step up needs proof attached. An unexploited weakness stays a coverage gap.
CH.04·Control
You set how much it decides. The gates stay where they are.
Two modes, and a console that can pause, steer, veto or stop an engagement at any point.
Mode
- InteractiveAsks for the inputs at every phase.
- AutonomousApplies documented defaults and asks nothing, except at a hard gate.
Steer note
“Hold off on the login form, the client is mid-migration there.”
Ana · operator · 14:20
- pause
- stop
- veto a candidate
- narrow the scope
- sign off a finding
Run it from the browser
A session's agent keeps running when you close the tab. Reopen it and the console replays what you missed.
Every decision, timed and attributed
Approvals, declines, steer notes and sign-offs append to a log, one line each, with the person and the minute.
- 14:20Anasteer note added
- 14:24Anaphase 3 → 4 approved
- 15:02Ruicandidate vetoed
- 15:40Ruifinding-007 signed off
CH.05·What you keep
A report you can hand a client, with the evidence attached.
A report a client can read
An executive summary, severity by finding and the technical detail, as prose and as a machine-readable export.
A dashboard built from the files
An interactive engagement report: the phases, the findings table, the audit trail and a CSV export. Light, dark and print-ready.
Four files, one source of truth
- report.mdclient prose
- findings-export.jsonmachine-readable
- engagement-report.htmlinteractive dashboard
- audit-log.ndjsonappend-only trail
The HTML is derived strictly from the files, so it can never claim more than the evidence does.
What it is not
- 01
A SaaS
It is deployed once, in your environment. Your targets and findings stay with you.
- 02
An autonomous attack
It stops at first proof and never chains an exploit on its own. The depth is a decision a person makes.
- 03
Unattended
Every state-changing step waits for an approval, logged, even when it runs in autonomous mode.
- 04
A black box
Every command, check, finding and decision is written to a log nobody can edit.
Bring a target you are authorized to test
We deploy into your environment, agree the scope and rules in writing, and run the engagement with the brakes on.
Nothing is tested until the scope is signed.