How the audit engine actually works.
For the buyer who has read the marketing pages and now has one remaining question. This page covers the pipeline, the isolation guarantees, the retention policy, and what leaves your control at each step. Written for the CISO office and for the security engineer who will spot hand-wave in the answer.
A signed brief becomes a workspace.
The engagement brief you submit at /engagement/nda is countersigned, and a per-engagement workspace is created inside our infrastructure. The workspace is namespaced by a UUID, gated on your account, and never shares filesystem, database, or blob storage with any other engagement. The NDA is written to that same workspace so the artefact and the contract can never drift.
Your material sits in its own compartment.
Everything you upload — a codebase ZIP, a Postman collection, an OpenAPI spec, a set of URLs — is decrypted only inside a per-engagement runner. Runners are ephemeral Docker containers with no ambient credentials, no outbound egress except to the tools they need, and a hard 4-hour TTL. When a runner exits, its filesystem is wiped and its container image is discarded.
The tools run against your material.
Static analysis runs Semgrep with our OWASP ASVS L2 rulepacks, TruffleHog and gitleaks over the full git history, and CVE lookup against the OSV and GitHub Security Advisories databases. External-recon runs Nuclei, Naabu, Subfinder, and sslyze. Grey-box adds Burp Suite Professional, sqlmap, and a bespoke race-condition harness driven by the tester. Each finding is logged with a stable identifier, a payload, and the tool + version that produced it.
Findings are scored, tagged, and tied to a control.
Every finding is scored with CVSS 4.0 and its Base + Threat + Environmental vector, tagged with a CWE identifier, and mapped to the ATT&CK v14 technique it exercises. For engagements with a compliance dimension, findings are also mapped to SOC 2 CC7.1, ISO 27001 A.5.30, NIS2 Article 21, DORA Article 26, PCI DSS v4.0, or NIST SP 800-53 controls — whichever your brief called for.
A signed report lands, and the workspace is closed.
The report is written in a single template — executive summary, engagement scope, findings, methodology + compliance mapping, remediation roadmap, appendices — and rendered into a PDF signed by an X.509 certificate held on our KMS. The signed PDF, a JSON export of the findings for your ticket system, and any reproducible payloads are delivered to you. The workspace enters a retention window and is wiped at the end of it.
One engagement can never see another.
- 01Per-engagement workspace — no shared filesystem, no shared database, no shared blob storage across engagements.
- 02Runners are ephemeral. No engagement runner survives longer than four hours; every runner is a fresh container with no persistent state.
- 03No ambient credentials in runners. Tools that need an API key (GHSA lookup, OSV) receive short-lived credentials scoped to the engagement and revoked on exit.
- 04Zero-egress default. Outbound network access from a runner is denied except for a per-engagement allowlist you approve in the brief.
- 05Tester actions are logged with a stable identifier, timestamp, and payload. The audit trail is retained regardless of workspace lifecycle so post-hoc verification is always possible.
What we keep, for how long, and why.
| Artefact | Kept | Why |
|---|---|---|
| Source material (repo ZIPs, uploaded traces) | 30 days | Long enough to re-open and re-run against remediated changes; short enough that a stale copy is never our problem. |
| Findings and grading (JSON + PDF) | 7 years | Matches the longest audit-evidence retention obligation we see from our SOC 2, ISO 27001, and DORA clients. |
| Runner filesystem + tool caches | 4 hours | Runner TTL. Nothing survives. |
| Signed report (X.509) | 10 years | A signed report needs to be verifiable long after the engagement — the signature is only useful if the artefact is still around. |
| PII deliberately included by you | On request | GDPR erasure requests are honoured within 30 days. Findings that referenced the erased PII are redacted, not deleted; the finding stays, the identifier is removed. |
GDPR Article 17 erasure requests are honoured within 30 days. Findings that referenced the erased PII are redacted, not deleted — the finding record stays for audit-trail integrity; the personal identifier is removed. On request we produce a written attestation of erasure.
A short honest inventory.
| Subject | What we hold | What leaves you |
|---|---|---|
| Public URLs in your automated tier scan | Cached with hashes | Nothing sensitive by definition |
| Uploaded source code | Analysed and deleted per retention | Never egresses outside our infrastructure |
| Detected secrets (verified live) | Logged as finding · never fetched again | You are told; rotation is your call |
| CVE lookups | Package name + version only | No file contents ever sent to OSV / GHSA |
| ATT&CK / OWASP mappings | Reference data pulled at build time | No engagement telemetry leaves the runner |
Because you are entitled to ask.
Every change on our own codebase runs the same Semgrep + TruffleHog + OSV pipeline our clients pay for. Findings block merge on high severity. Two humans sign off every production change and CI enforces required reviewers. Deploy telemetry is retained 90 days.
All production access is short-lived and JIT-issued through our IdP with WebAuthn. Long-lived secrets live in KMS-backed stores; runners receive scoped, time-bounded credentials on start. Zero standing production access for anyone, including the CEO.
Our own responsible-disclosure policy lives at /legal/disclosure and mirrors what we ask our clients to publish. Reports acknowledged within one business day; 90-day default disclosure window on high-severity issues.
Our DPA is at /legal/dpa with the current subprocessor list and their regions. Any change is announced 30 days before it takes effect so you can object.
Ask them before you sign, not after.
A 30-minute call with a lead tester and a member of the operations team. We walk any procurement or security-review reviewer through the pipeline in real time.