Eleven coverage classes and one exclusion
Every class below has its own page, with its own defect classes, its own standards at their current versions, and its own worked example. That is deliberate: an unsupported class in a long list weakens every class beside it.
The classes
Each one, and what it is actually about
Not a list of things we say yes to. Each line is the argument that class's own page is built on, and no two of them are the same argument.
| Coverage class | What the assessment is actually about |
|---|---|
| Web applications | Access control and business logic, worked with a credential for each role — the classes a signature catalogue cannot reach because every response is well formed. |
| Mobile apps | The signed release build exactly as you publish it: obfuscated, certificate pinned and defended at runtime, decompiled and analysed without source. |
| APIs | An authorisation matrix written before anything is tested against it, then every route checked against it with a second credential in hand. |
| Thick client | The package you distribute, and the question underneath it — not whether a check inside the client can be removed, but whether the server relied on it. |
| External network | The perimeter worked out from what actually answers rather than from the asset list, and handed back as a scope proposal before anything is tested. |
| Internal network | How far a foothold travels, inside a movement boundary you wrote into the scope rather than one decided while the run was going. |
| Cloud | The identity and permission layer, where cloud findings concentrate — and a permission proved by making the call rather than by reading the policy. |
| Active Directory | Privilege paths walked rather than drawn, with the edges that failed reported alongside the ones that held. |
| Social engineering | A foothold, obtained under a written authorisation naming the population and the window. Judged on whether it got in, not on what proportion clicked. |
| Secure code review | A file, a line, the path that reaches that line, and the change that closes it — written against the idiom your repository already uses. |
| LLM applications | What the application does with the model rather than what the model says: what it retrieves and trusts, what it renders, and which tools it can be made to invoke. |
- What the assessment is actually about
- Access control and business logic, worked with a credential for each role — the classes a signature catalogue cannot reach because every response is well formed.
- What the assessment is actually about
- The signed release build exactly as you publish it: obfuscated, certificate pinned and defended at runtime, decompiled and analysed without source.
- What the assessment is actually about
- An authorisation matrix written before anything is tested against it, then every route checked against it with a second credential in hand.
- What the assessment is actually about
- The package you distribute, and the question underneath it — not whether a check inside the client can be removed, but whether the server relied on it.
- What the assessment is actually about
- The perimeter worked out from what actually answers rather than from the asset list, and handed back as a scope proposal before anything is tested.
- What the assessment is actually about
- How far a foothold travels, inside a movement boundary you wrote into the scope rather than one decided while the run was going.
- What the assessment is actually about
- The identity and permission layer, where cloud findings concentrate — and a permission proved by making the call rather than by reading the policy.
- What the assessment is actually about
- Privilege paths walked rather than drawn, with the edges that failed reported alongside the ones that held.
- What the assessment is actually about
- A foothold, obtained under a written authorisation naming the population and the window. Judged on whether it got in, not on what proportion clicked.
- What the assessment is actually about
- A file, a line, the path that reaches that line, and the change that closes it — written against the idiom your repository already uses.
- What the assessment is actually about
- What the application does with the model rather than what the model says: what it retrieves and trusts, what it renders, and which tools it can be made to invoke.
The exclusion
Physical, hardware and wireless
Out of scope for the platform entirely, in every class, and stated in the same words on every one of the pages above. It is worth saying once in a place a buyer can find it, because a coverage list with no boundary is a coverage list nobody should believe.
Everything else is a scoping question rather than a capability one. Where a class needs something from you before it can start — a credential for each role, a deployed position inside the network, a written authorisation naming a population — that requirement is on the class page, in the block that sets out what is fixed before a run begins.
Delivery
All three models cover all of them
The models differ by where the human sits, never by what is tested. So the model is a decision about assurance and about whose signature the report carries, and it is never a decision about coverage.
| Delivery model | Where the human is | Coverage |
|---|---|---|
| Fully autonomous | A person authorises scope and targets. Nothing after that. | All eleven classes. |
| Autonomous, expert verified | A senior auditor verifies every finding before anything reaches you. | All eleven classes. |
| Human led Terminal | A senior auditor runs the engagement with B-52 underneath. | All eleven classes. |
- No human action after scope sign-off
- An empanelled auditor is inside the engagement
- TerminalNo state follows this one
Where the report has to go into a regulated filing, the choice narrows: Security Brigade signs under its CERT-In empanelment, and the auditor who signs has to have been inside the engagement. The delivery models page sets out which one answers which need.
One scan is one application or target, from $500
Card payment works without a sales conversation. Where the estate is larger than one target, or the report has to carry a signature, a scoping call settles it faster than a form.