Cyber is in beta. Find it under Cyber in the navigation menu.
How it works
- Register an app. Give it a name and a target — a domain or an API base URL — then prove you own the domain with a DNS record.
- Set the boundaries. Fence off what Oliver may test, attach logins so he can test behind the sign-in page, and attach repositories so findings point at the exact line of code.
- Oliver scans. A run maps everything reachable, then tests inside your scope at the intensity you chose — from read-only to full.
- Findings arrive with proof. Each confirmed finding carries the attack path and a safe proof of concept you can replay yourself.
- The next scan re-checks. Fixed findings are verified automatically, retest requests are honored, and dismissed findings stay quiet.

What you can do
The Cyber page itself is your workspace posture view. It totals open findings by severity across every app, flags what needs attention — critical and high open, needs triage, awaiting retest — and lists recent findings above the app roster. Until an app’s first scan completes, Cyber shows “not scanned yet” rather than a clean bill of health, and while a scan runs the counts carry a live indicator because they can still change.
Key concepts
Get started
Run a pentest
Register your first app, set the boundaries, and launch a scan
Triage security findings
Read each finding’s proof and move it through your workflow
Oliver
Meet the Security Engineer agent that runs your pentests
Connections
Connect the Git provider that unlocks white-box testing