Before any request is sent
The operator must confirm control of the target or documented authority to test it. Scope includes hosts, paths, identities, exclusions, rate constraints, test windows, and emergency contacts.
- No third-party targets
- No discovery beyond approved boundaries
- No credentials submitted through the marketing form
Assessment workflow
The proposed workflow maps reachable functionality, models trust boundaries, prioritizes abuse paths, performs bounded validation, and records reproducible evidence.
- Web applications and REST APIs
- Authenticated flows when safely provisioned
- Stop conditions for instability or unexpected data
What it cannot show
A black-box view cannot inspect unreachable branches, internal data flows, or undeployed code. It is a point-in-time assessment and cannot guarantee that every vulnerability is found.