From authorized scope to verified fix.

AISEC maps the public surface, drives real security tools, validates exploitability, and keeps the evidence attached to the issue. Your team decides scope and remediation. AISEC does the repetitive testing.

Scope
Verified
Agent
Authorized
Evidence
Attached
Retest
Ready
Project boundary / enforced by API
InputA target you own or are authorized to test
ContextScope, credentials, docs, and linked repositories
OutputProof-backed issues, evidence, and remediation steps
ClosureExact retests and continuous perimeter monitoring

One issue lifecycle. Seven clear stages.

The scanner is not a one-off report generator. Each stage leaves state the next stage can use, from the first verified root to the final retest.

01AuthorizeProve control and define scope.
02DiscoverMap hosts, APIs, routes, certificates, and technology.
03TestRun bounded tools and follow credible attack paths.
04ProveValidate impact and preserve reproduction evidence.
05RemediateAssign, track, and work the issue in context.
06RetestReplay the exploit and confirm the fix.
07ProtectWatch the perimeter between pentests with Sentinel.

Inputs are explicit. Results are inspectable.

A client should always know what AISEC needs, what it will do, and how to tell that the step worked.

Perimeter

Give AISEC a root domain and complete proof of control. Add explicit targets where inheritance is not appropriate.

You see the verified root, discovered assets, scope state, and source for every asset.

Repository context

Link only the repositories needed for the project. AISEC reads the selected repository context to recover routes and dependency versions that runtime discovery misses.

The linked repository, analyzed commit, sync state, and discovered context remain visible in Perimeter.

Assessment

Select a scan profile, supply approved credentials or headers when needed, and start the run.

Progress, tool output, findings, and terminal events stream into the scan record.

Issue workflow

Triage the issue, assign an owner, apply the remediation, and mark it ready for a retest.

Evidence, status history, audit events, and retest outcome stay attached to the issue.

Automation where repetition is expensive. Control where judgment matters.

Your team

  1. 01Owns authorization, scope, credentials, and maintenance windows.
  2. 02Reviews impact in business context and decides priority.
  3. 03Implements the fix and controls release timing.
  4. 04Approves integrations, roles, and outbound actions.

AISEC

  1. 01Continuously maps the authorized public attack surface.
  2. 02Drives security tools and follows evidence-backed hypotheses.
  3. 03Deduplicates findings into issues with proof and remediation context.
  4. 04Replays tests after fixes and watches for perimeter change.

Start with one verified project.

Add an authorized target, confirm the perimeter, and run the first bounded assessment from the dashboard.

Open AISEC