Every finding ships with reproducible PoC, CVSS, CWE/CVE, and SOC 2 / ISO / PCI mappings. White-label PDFs flow straight into customer security reviews.
Generated nightly. Hand to your auditor, your customer, or your board.
Every finding ships curl + HTTP scripts. Re-run them yourself. They pass on exploit, fail on patch.
Vector string included. Severity rationalised against business impact, not just CVSS class.
Every finding ties to a CWE class. Where a known CVE exists, we cite it and link the upstream advisory.
SOC 2 CC, ISO 27001 A-controls, PCI DSS, HIPAA, flagged automatically per finding.
Premium and Enterprise reports carry your brand, your typography, your customer disclaimer. Yours to ship.
Every report opens with what's new, what's fixed, what regressed. No diff-archaeology in your inbox.
SHA-256 hash chain across the report, evidence, and PoC artifacts. Tamper-evident by default.
PDF, JSON, SARIF, STIX. Findings flow into your SIEM, ticket queue, or auditor's portal.
Same data, no PDF. Findings render as live cards in the dashboard, with a one-click "open in CLI" replay.
The reset endpoint accepts a forged JWT signed with alg=none. Combined with email enumeration on /api/users/:id, an unauthenticated attacker takes over any account in two requests.
One target, daily continuous coverage. The first chain lands before tomorrow's standup.