Skip to content
AUDIT ENGINE · ARCHITECTURE

How the audit engine actually works.

For the buyer who has read the marketing pages and now has one remaining question. This page covers the pipeline, the isolation guarantees, the retention policy, and what leaves your control at each step. Written for the CISO office and for the security engineer who will spot hand-wave in the answer.

THE PIPELINE · FIVE STAGES
01
INTAKE

A signed brief becomes a workspace.

The engagement brief you submit at /engagement/nda is countersigned, and a per-engagement workspace is created inside our infrastructure. The workspace is namespaced by a UUID, gated on your account, and never shares filesystem, database, or blob storage with any other engagement. The NDA is written to that same workspace so the artefact and the contract can never drift.

Prisma workspace recordSigned NDA (PDF)GCS bucket · KMS-encrypted at rest
02
ISOLATION

Your material sits in its own compartment.

Everything you upload — a codebase ZIP, a Postman collection, an OpenAPI spec, a set of URLs — is decrypted only inside a per-engagement runner. Runners are ephemeral Docker containers with no ambient credentials, no outbound egress except to the tools they need, and a hard 4-hour TTL. When a runner exits, its filesystem is wiped and its container image is discarded.

Docker · rootless containersScaleway ephemeral runnersNo cross-workspace mountsZero-egress except allowlist
03
ANALYSIS

The tools run against your material.

Static analysis runs Semgrep with our OWASP ASVS L2 rulepacks, TruffleHog and gitleaks over the full git history, and CVE lookup against the OSV and GitHub Security Advisories databases. External-recon runs Nuclei, Naabu, Subfinder, and sslyze. Grey-box adds Burp Suite Professional, sqlmap, and a bespoke race-condition harness driven by the tester. Each finding is logged with a stable identifier, a payload, and the tool + version that produced it.

Semgrep · TruffleHog · gitleaks · OSV · GHSANuclei · Naabu · Subfinder · sslyzeBurp Pro · sqlmap · custom Go harness
04
GRADING

Findings are scored, tagged, and tied to a control.

Every finding is scored with CVSS 4.0 and its Base + Threat + Environmental vector, tagged with a CWE identifier, and mapped to the ATT&CK v14 technique it exercises. For engagements with a compliance dimension, findings are also mapped to SOC 2 CC7.1, ISO 27001 A.5.30, NIS2 Article 21, DORA Article 26, PCI DSS v4.0, or NIST SP 800-53 controls — whichever your brief called for.

CVSS 4.0 · CWE taggingMITRE ATT&CK v14 mappingFramework overlay per brief
05
REPORT

A signed report lands, and the workspace is closed.

The report is written in a single template — executive summary, engagement scope, findings, methodology + compliance mapping, remediation roadmap, appendices — and rendered into a PDF signed by an X.509 certificate held on our KMS. The signed PDF, a JSON export of the findings for your ticket system, and any reproducible payloads are delivered to you. The workspace enters a retention window and is wiped at the end of it.

X.509 report signing (KMS-held)JSON export for Jira / LinearRetention-triggered deletion
ISOLATION GUARANTEES

One engagement can never see another.

  1. 01Per-engagement workspace — no shared filesystem, no shared database, no shared blob storage across engagements.
  2. 02Runners are ephemeral. No engagement runner survives longer than four hours; every runner is a fresh container with no persistent state.
  3. 03No ambient credentials in runners. Tools that need an API key (GHSA lookup, OSV) receive short-lived credentials scoped to the engagement and revoked on exit.
  4. 04Zero-egress default. Outbound network access from a runner is denied except for a per-engagement allowlist you approve in the brief.
  5. 05Tester actions are logged with a stable identifier, timestamp, and payload. The audit trail is retained regardless of workspace lifecycle so post-hoc verification is always possible.
RETENTION POLICY

What we keep, for how long, and why.

ArtefactKeptWhy
Source material (repo ZIPs, uploaded traces)30 daysLong enough to re-open and re-run against remediated changes; short enough that a stale copy is never our problem.
Findings and grading (JSON + PDF)7 yearsMatches the longest audit-evidence retention obligation we see from our SOC 2, ISO 27001, and DORA clients.
Runner filesystem + tool caches4 hoursRunner TTL. Nothing survives.
Signed report (X.509)10 yearsA signed report needs to be verifiable long after the engagement — the signature is only useful if the artefact is still around.
PII deliberately included by youOn requestGDPR erasure requests are honoured within 30 days. Findings that referenced the erased PII are redacted, not deleted; the finding stays, the identifier is removed.

GDPR Article 17 erasure requests are honoured within 30 days. Findings that referenced the erased PII are redacted, not deleted — the finding record stays for audit-trail integrity; the personal identifier is removed. On request we produce a written attestation of erasure.

WHAT LEAVES YOUR CONTROL

A short honest inventory.

SubjectWhat we holdWhat leaves you
Public URLs in your automated tier scanCached with hashesNothing sensitive by definition
Uploaded source codeAnalysed and deleted per retentionNever egresses outside our infrastructure
Detected secrets (verified live)Logged as finding · never fetched againYou are told; rotation is your call
CVE lookupsPackage name + version onlyNo file contents ever sent to OSV / GHSA
ATT&CK / OWASP mappingsReference data pulled at build timeNo engagement telemetry leaves the runner
SECURITY OF THE SECURITY VENDOR

Because you are entitled to ask.

DEV PIPELINE

Every change on our own codebase runs the same Semgrep + TruffleHog + OSV pipeline our clients pay for. Findings block merge on high severity. Two humans sign off every production change and CI enforces required reviewers. Deploy telemetry is retained 90 days.

ACCESS & SECRETS

All production access is short-lived and JIT-issued through our IdP with WebAuthn. Long-lived secrets live in KMS-backed stores; runners receive scoped, time-bounded credentials on start. Zero standing production access for anyone, including the CEO.

DISCLOSURE

Our own responsible-disclosure policy lives at /legal/disclosure and mirrors what we ask our clients to publish. Reports acknowledged within one business day; 90-day default disclosure window on high-severity issues.

DPA & SUBPROCESSORS

Our DPA is at /legal/dpa with the current subprocessor list and their regions. Any change is announced 30 days before it takes effect so you can object.

QUESTIONS THIS PAGE DIDN’T ANSWER?

Ask them before you sign, not after.

A 30-minute call with a lead tester and a member of the operations team. We walk any procurement or security-review reviewer through the pipeline in real time.