Public exposure
Passive DNS, TLS, headers, robots, sitemap and exposed-route review without bypassing access controls.
ContactAUTHORIZED SECURITY VALIDATION
Reaper is available for assets the customer owns or is authorized to test. Active work begins only after the engagement documents targets, permissions, methods, operating windows, stop conditions and evidence handling.
Passive DNS, TLS, headers, robots, sitemap and exposed-route review without bypassing access controls.
Authorization, tenant isolation, object access, rate limits and unsafe endpoint behavior within written scope.
Client-provided or explicitly scoped source, dependency, secret, environment and CI/CD exposure review.
Prompt, tool, webhook, memory, source-leakage and approval-gate testing inside an authorized environment.
Named cloud exposure, routing, services and public misconfiguration within the approved target set.
Finding evidence, severity, reproduction conditions, containment or fix path and a bounded retest decision.
The engagement does not authorize credential theft, persistence, credential stuffing, out-of-scope extraction or testing beyond the written Rules of Engagement.
Discuss a security validation engagement