AUTHORIZED SECURITY VALIDATION

Reaper validates security under written scope and Rules of Engagement.

Reaper is available for assets the customer owns or is authorized to test. Active work begins only after the engagement documents targets, permissions, methods, operating windows, stop conditions and evidence handling.

Public exposure

Passive DNS, TLS, headers, robots, sitemap and exposed-route review without bypassing access controls.

Backend and API

Authorization, tenant isolation, object access, rate limits and unsafe endpoint behavior within written scope.

Repository and configuration

Client-provided or explicitly scoped source, dependency, secret, environment and CI/CD exposure review.

Agentic systems

Prompt, tool, webhook, memory, source-leakage and approval-gate testing inside an authorized environment.

Infrastructure

Named cloud exposure, routing, services and public misconfiguration within the approved target set.

Evidence and retest

Finding evidence, severity, reproduction conditions, containment or fix path and a bounded retest decision.

Engagement requirements

  • Named domains, IP ranges, APIs, cloud resources or repositories.
  • Authority to test the target, including third-party permission where required.
  • Permitted methods, authentication contexts and production constraints.
  • Escalation contacts, stop conditions and incident procedure.
  • Evidence handling, retention, reporting and retest terms.

The engagement does not authorize credential theft, persistence, credential stuffing, out-of-scope extraction or testing beyond the written Rules of Engagement.

Discuss a security validation engagement