AUTHORIZED SECURITY VALIDATION

Scope first. Test second.

A website inquiry starts a scope conversation. It does not authorize testing. Active validation begins only after the asset owner or authorized party signs the engagement scope and Rules of Engagement.

Public exposure

Passive DNS, TLS, headers, robots, sitemap and exposed-route review without bypassing access controls.

Backend & API

Authorization, tenant isolation, object access, rate limits and unsafe endpoint behavior within written scope.

Repository & configuration

Client-provided or explicitly scoped source, dependency, secret, environment and CI/CD exposure review.

AI agency

Prompt, tool, webhook, memory, source-leakage and approval-gate testing inside an authorized environment.

Infrastructure

Named cloud exposure, routing, services and public misconfiguration within the approved target set.

Proof & retest

Finding evidence, severity, reproduction conditions, containment/fix path and a retest decision.

Before active testing

  • Named targets: domains, IP ranges, APIs, cloud resources or repositories.
  • Proof that the customer can authorize testing of those targets, including third-party permission where required.
  • Start/end times, permitted windows and production constraints.
  • Allowed and prohibited methods, authentication contexts and business workflows.
  • Escalation contacts, stop conditions and incident procedure.
  • Evidence handling, retention, reporting and retest terms.

No cold intrusion. No credential theft. No persistence. No credential stuffing. No unauthorized bypass. No out-of-scope extraction.

Request access