From authorized scope to verified fix.
AISEC maps the public surface, drives real security tools, validates exploitability, and keeps the evidence attached to the issue. Your team decides scope and remediation. AISEC does the repetitive testing.
- Scope
- Verified
- Agent
- Authorized
- Evidence
- Attached
- Retest
- Ready
One issue lifecycle. Seven clear stages.
The scanner is not a one-off report generator. Each stage leaves state the next stage can use, from the first verified root to the final retest.
Inputs are explicit. Results are inspectable.
A client should always know what AISEC needs, what it will do, and how to tell that the step worked.
Perimeter
Give AISEC a root domain and complete proof of control. Add explicit targets where inheritance is not appropriate.
You see the verified root, discovered assets, scope state, and source for every asset.
Repository context
Link only the repositories needed for the project. AISEC reads the selected repository context to recover routes and dependency versions that runtime discovery misses.
The linked repository, analyzed commit, sync state, and discovered context remain visible in Perimeter.
Assessment
Select a scan profile, supply approved credentials or headers when needed, and start the run.
Progress, tool output, findings, and terminal events stream into the scan record.
Issue workflow
Triage the issue, assign an owner, apply the remediation, and mark it ready for a retest.
Evidence, status history, audit events, and retest outcome stay attached to the issue.
Automation where repetition is expensive. Control where judgment matters.
Your team
- 01Owns authorization, scope, credentials, and maintenance windows.
- 02Reviews impact in business context and decides priority.
- 03Implements the fix and controls release timing.
- 04Approves integrations, roles, and outbound actions.
AISEC
- 01Continuously maps the authorized public attack surface.
- 02Drives security tools and follows evidence-backed hypotheses.
- 03Deduplicates findings into issues with proof and remediation context.
- 04Replays tests after fixes and watches for perimeter change.
Start with one verified project.
Add an authorized target, confirm the perimeter, and run the first bounded assessment from the dashboard.