What's covered/01 · Pentesting

We attack your stack like the people who would.

Real offensive operators - not a scanner on a subscription - break into your systems within tightly-bounded scope, prove what's exploitable, and hand you fixes instead of a 60-page PDF. The latest models do the heavy lifting; a human signs every move.

[ 01 ] What makes us different

Not a scanner with a subscription.

Most "pentests" are an automated scan, a templated report, and an invoice. Ours is a team of people who break into things for a living, working under hard constraints, handing you outcomes you can act on.

Operators, not a scan queue

Ex-offensive-security engineers from Amazon, StockX, BofA and government - 60+ confirmed vulnerabilities between them. They chain bugs and abuse logic a scanner will never see.

- manual exploitation · real compromise

Fixes, not a PDF

Every finding ships with a reproduction, a severity, and code-level remediation guidance. We help you close it - and the retest is included, not a line item.

- remediation + retest, every time

Findings land live, in the platform

No quarterly drop. Findings appear as we confirm them - triaged, prioritized, and mapped to the compliance controls they touch. Your team watches the test happen.

- continuous · mapped to SCF controls

Latest models, human in the loop

As Anthropic partners we run on frontier models - but they never act alone. Every action is bounded by signed rules of engagement and approved by a named operator.

- scope-bound · human-signed
[ 02 ] The process

Six phases. One bounded engagement.

Every engagement runs the same disciplined path - from a signed scope to a verified fix. The two gated phases (scope and retest) are enforced by the platform, not left to anyone's good intentions.

Phase 01 · gated

Scope & rules of engagement

We define targets, boundaries, and blast radius with your team, then sign a rules-of-engagement document. It is enforced in code - a hard allowlist, not a handshake.

Signed RoE · enforced allowlist
Phase 02

Recon & surface mapping

We enumerate the real attack surface in scope: hosts, endpoints, identities, dependencies, and the seams between them. The map that no architecture diagram admits to.

Attack-surface inventory
Phase 03

Exploitation

Operators attempt genuine compromise - manual, chained, creative - strictly inside the agreed scope. Models accelerate the grind; a human drives and decides every action.

Confirmed exploit paths
Phase 04

Proof & evidence

Nothing theoretical reaches you. Every finding is reproduced, captured, and assigned a severity. If we can't prove it, it doesn't ship as a finding.

Reproducible evidence per finding
Phase 05

Remediation & guidance

Each finding comes with code-level fix guidance, ranked by what actually matters. We work the fix with your engineers instead of lobbing a report over the wall.

Prioritized, code-level fixes
Phase 06 · gated

Retest & verify

When you ship the fix, we re-run the test, mark the finding fixed, and verify the result. Logged in the Sythe Labs platform - evidence you can hand an auditor.

Verified fix · logged in-platform
[ 03 ] AI, on a leash

The latest models. A human in the loop. Always.

We are not an autonomous bot loosed on your infrastructure. As Anthropic partners we get the newest frontier models the day they land - and we use them to move faster, not to take a person out of the chair. Every agent action runs under signed rules of engagement and a hard allowlist, with a named operator approving the move. It is not possible for a test to touch a system outside the agreed scope.

A human signs every finding

No exploit is run and no finding reaches you without a named operator reviewing and approving it. The model proposes; a person decides.

Bounded by rules of engagement

Scope, targets, and blast radius are defined and signed before a single packet leaves. The boundary is enforced in code - not by trust.

Frontier models, on a tight leash

As Anthropic partners we run the newest models to accelerate recon and triage - but only within signed scope, and never with authority to act on their own.

rules_of_engagement.lock✓ authorized
In scope · allow
+app.acme-prod.com
+api.acme-prod.com/v2/*
+10.4.0.0/22 · staging-vpc
Out of scope · deny
*.acme-corp.internal
prod database · billing
everything not listed above
Enforced by the platform. Out-of-scope targets are denied before a request is ever made - every time.
[ 04 ] What you get back

An evidence-grade finding. Not a screenshot dump.

This is a real finding from our platform - the exact shape your team sees the moment we confirm something. Severity, reproduction, a human author, the container it lives in, and the compliance control it maps to.

High

Server-side request forgery in webhook validator

id f7c1a9e2-b04dsource pentestworkspace acme-prod
Triaged

The outbound webhook validator follows attacker-controlled redirects without re-checking the destination, letting a crafted callback URL reach the internal metadata service. Confirmed: retrieved an IAM credential from the staging instance role. Reproduction, request captures, and a scoped PoC are attached in the platform.

Container
api-gateway
Status
triaged
Severity
high
Authored by Jarred Parr · operatorcreated 2026-05-21 · 14:02 UTChuman-verified
Status lifecycle
opentriagedfixedverified
Severity scale
criticalhighmediumlowinfo
[ → ] Get started

Find out what's actually exploitable.

A 30-minute scoping call. We'll tell you where we'd start, what we'd test first, and what a bounded engagement looks like for your stack - whether or not you hire us.