The wedge
AI pentest: audit your app without sending the code away.
What an AI pentest is, what it is not, and which kit mode to open for a site, a SaaS, or MCP agents.
Read the guide →Security audit kit
You do not pick an internal mode. You name the project — site, SaaS, MCP — and the depth. Each guide says what the squad does, what it refuses, and how to launch.
The wedge
What an AI pentest is, what it is not, and which kit mode to open for a site, a SaaS, or MCP agents.
Read the guide →01-express · 30–45 min
When to open Express, what it covers, and why an Express at confidence 5 is a fault.
Read the guide →02-complet-web · 1 day
Pipeline of a full web audit: what runs, what stays Untested without an account, and when to switch to SaaS.
Read the guide →03-complet-saas · 1–2 days
Two-tenant rule, pipeline 00–11, multi-tenant specialist. This is not SSPM (locking down Slack): it is auditing the SaaS YOU build.
Read the guide →04-agents-mcp · 4–8 h
Who may call which tool, a tool + another tenant’s id, exposed prompts and .env, third-party marketplace.
Read the guide →05-delta · 2–6 h
Snapshot before any new collection, re-check of open findings, no classes outside the baseline.
Read the guide →06-continuous · 30–90 min / run
Without a baseline, this is the wrong mode. OpenRouter key on every run. Short QA only if a Confirmed is born.
Read the guide →07-redteam-leger · 1–3 days
Four mandate clauses, what “light” allows, and why “it’s my site” in chat is not enough.
Read the guide →08-rapport-board · 1–3 h
Hard gate: qa.passed=true, sign-off present, no finding newer than QA. Otherwise stop.
Read the guide →