How agents work

How our agents work

Agents cover ground no fixed-hour engagement could reach. People decide what any of it means. Here is exactly how that division works.

The division of labour

The distinction that matters is not what is automated — it is what is trusted without review.

What agents do unattended

  • Enumerate the attack surface and keep that map current as it changes
  • Fingerprint services, versions and configurations at full breadth
  • Probe for known weakness classes across every asset, not a sample
  • Re-run continuously so new exposure surfaces when it appears
  • Collect the evidence an engineer needs to judge a candidate finding

What a person does

  • Agree the scope and the boundaries before anything runs
  • Reproduce every candidate finding by hand
  • Chain individually minor issues into the paths that actually matter
  • Discard what cannot be exploited in your environment
  • Write the report, and stand behind every claim in it

An engagement, end to end

Five stages. You know at each point what is happening and what you get from it.

  1. Human · Step 1

    Scope

    We agree in writing what is in bounds, what is out, and what may never be touched. Nothing runs before this is settled.

  2. Agent · Step 2

    Enumerate

    Agents map every host, service and endpoint in scope, then keep that map current for the duration of the engagement.

  3. Agent · Step 3

    Exploit and chain

    Agents probe for known weakness classes across the whole surface and collect the evidence a person needs to judge each candidate.

  4. Human · Step 4

    Human verification

    An engineer reproduces every candidate by hand, chains individually minor issues into paths that matter, and discards what cannot be exploited here.

  5. Human · Step 5

    Report and retest

    You get the written findings, and once your fixes land we retest to confirm they hold.

Certifications held across the team

  • GXPN
  • CISSP
  • LPI
  • CEH

A run, as it happens

Agents surface candidates continuously. Each one waits for a person before it becomes a finding.

enumerating subdomains

fingerprinting services

auth bypass candidate — /api/v2/session

chained privilege escalation — admin to root

queued for human verification

verified and written up by an engineer

What we never do

Send you unverified findings

If a person has not reproduced it, it does not go in the report. Scanner output is an input to our work, never a deliverable.

Test outside written scope

Nothing runs against a system that is not in the agreed scope, and nothing destructive runs without explicit sign-off.

Lock you into our tooling

You are buying an outcome and a report, not a dependency. Everything we set up in your pipeline is yours and runs without us.

What you receive

  • A technical report with reproduction steps for every finding
  • An executive summary for the people approving the work
  • Remediation sequenced by exploitability, not by scanner severity
  • A retest once your fixes are in
  • Direct access to the engineer who did the work