Security & authorization

Offense you can put in writing.

This is an offensive-security tool, so authorization is the product, not a footnote. Here is how the engine stays inside the scope you give it — and what a security or procurement team can expect before it runs.

A hard authorization gate

The engine refuses every device-touching or offensive stage until a valid engagement is present with consent set to confirmed. It is a precondition, not a flag to hand-wave past — autonomous means autonomous within a written authorization.

An audit manifest, every run

The engagement block — owner, authorization reference, and the target APK's sha256 — is recorded verbatim into each run's manifest. Every run is traceable back to the scope that permitted it.

Defensive by construction

Deliverables are prove-then-fix: a demonstrated bypass, a synthesized disarm, and a hardening recommendation. When it cannot fully resolve, it says so — “assisted, not resolved” — rather than fabricating a result.

Your perimeter, your data

On-prem and self-hosted licensing keep the binary inside your own network — it never leaves. For teams under strict data-handling rules, nothing about the app under test has to cross our boundary.

Scope

What we do, and what we don't

The engine goes deep on one part of the OWASP MASVS surface — resilience and anti-tamper (MASVS-RESILIENCE). It augments the attested human penetration test; it does not replace it. The value is continuous evidence between the annual snapshot, mapped to a framework your assessors already use.

Intended targets

  • Your own builds
  • Vendor-supplied test builds
  • Client work under written scope
  • Piracy or DRM-stripping
  • Data exfiltration or malware evasion
  • Anything you are not authorized to test

Where we are

Straight about maturity

We are early, and we would rather tell you that than imply otherwise. We do not hold SOC 2 or ISO certification yet, and we will not claim it before it is real. What we can show you today is the authorization model above, the audit manifest a run produces, and an on-prem option that keeps your binary in your own network. If your procurement process needs more, tell us what — we will meet it in writing rather than in marketing.

Ask us anything