The Sythe Explorer / A closer look

Start with the question
on your desk.

A buyer asks for proof. Your product changes. A security finding needs attention. Start with your situation to decide what work is appropriate, then use the walkthroughs to see who's involved and what happens in Sythe Labs.

Illustrative situations and supported workflows, using no customer data.

7 illustrated stories

Compliance

Explore compliance

Start with your situation

01 / Four chapters

Your customer asked for SOC 2. What do you actually need?

A buyer asks for a SOC 2 report before approving your service. Find out what they'll accept before you commit to an examination or promise a delivery date.

Explore situation

02 / Four chapters

A security questionnaire is holding up your deal

Sales has a spreadsheet full of security questions. Give the buyer answers your team can support, and separate missing evidence from missing controls.

Explore situation

03 / Four chapters

Your next customer has a security review team

The product team wants to buy. Procurement needs to know how you handle their data. Prepare for the larger customer's review without claiming controls you haven't put in place.

Explore situation

04 / Four chapters

You inherited a security program nobody owns

The policies are in a folder and the person who ran the reviews has left. Work out what still happens, what stopped, and who is responsible now.

Explore situation

See how the work gets done

01 / Four chapters

Get compliance evidence reviewed and approved

An auditor asks who reviewed production access this quarter. Use an evidence record to collect the supporting files and get an approver's decision on what they prove.

View walkthrough

02 / Four chapters

Get a policy approved, published, and acknowledged

Your access policy needs to reflect a change in how the team works. Review the revised wording, publish the approved version, and assign employees their acknowledgement tasks.

View walkthrough

03 / Four chapters

Share security documents through your Trust Portal

A prospective customer asks for your pentest report. Send them to your Trust Portal, where they can read your public security information and request protected documents.

View walkthrough

9 illustrated stories

Security

Explore security

Start with your situation

01 / Four chapters

A customer needs a pentest report before they can buy

The buyer asks for an independent test of your application. Agree what needs testing and what report they'll accept before commissioning the work.

Explore situation

02 / Four chapters

You're about to put customer data into a new application

The demo is becoming a live service. Decide which security questions need answers before real customer records reach the application.

Explore situation

03 / Four chapters

New payments, new roles, or a new API change the risk

An old assessment covered the old product. Check whether a new feature changes who can move money or reach customer data, then scope testing around that change.

Explore situation

04 / Four chapters

The scanner found problems. Which ones need action?

A list of severe findings isn't a plan. Check what ran, whether the affected system is exposed, and what still needs investigation before choosing the next action.

Explore situation

05 / Four chapters

You ship every week. Your last pentest is getting old.

A report describes the product that was tested. Compare its scope with today's service before deciding whether to retest fixes, assess new features, or keep scanning known targets.

Explore situation

06 / Four chapters

Do you need EDR for your team's laptops?

Who would notice suspicious activity on a laptop with access to company systems? Decide whether endpoint detection and response fits that risk, and who will act on the information it produces.

Explore situation

07 / Four chapters

You shipped the fix. Did it resolve the pentest finding?

The report is in, and an engineer has shipped a fix. A closed ticket doesn't establish that the reported behavior is gone. Follow the finding into a scoped retest to check whether the issue is resolved.

Explore situation

See how the work gets done

01 / Four chapters

Schedule vulnerability scans and check what actually ran

A scan was scheduled for this month. Did it finish, and which targets did it cover? See how Sythe Labs schedules approved scans and records the outcome of each run.

View walkthrough

02 / Four chapters

Send a repository security finding to your issue tracker

An engineer picks up a security ticket and asks, 'Where is this coming from?' Investigate the finding first, then file an issue with the code references and a link saved on the original finding.

View walkthrough