RUN.01 — Pentest

Authorized testing with a reviewable evidence trail.

This research mode organizes scope, validation evidence, remediation guidance, and reviewer decisions so technical teams can reproduce what was observed.

Evaluation boundary. These figures are project-reported results from controlled internal evaluations. They are not independent certifications, public vulnerability totals, or vendor-accepted findings.

What you get

  • Scope policy file checked into the run, gating every action.
  • Per-finding evidence chain: signed payload, runtime receipt, side-effect delta, source reference.
  • Reviewer disposition stamped with operator identity.
  • Deterministic replay.sh per finding.
  • Mode-aware report (executive + technical) with redaction manifest.
  • Artifact hashes and reviewer disposition for the report bundle.

Engagement shape

  • Discovery: SecHive loads the scope and inventories the surface.
  • Hypothesis: HypothesisGraph builds candidate weakness list.
  • Validation: Benign PoCs run under scope guard.
  • Operator review: findings triaged in mission control.
  • Reporting: deliverable rendered with proof pack attached.
  • Retest: rerun the same proof pack post-fix.