The signed scope is law.
Continuous testing must be continuously bounded. BotXpose evaluates every target and action against the approved scope, refuses out-of-scope requests and records the authorization context behind what it did.
- 01Authorize
- 02Understand
- 03Prove
- 04Deliver
- 05Repeat
Every action must carry its authority and evidence.
The status attached to each input determines whether it guides, permits, proves or records an action.
Target allowlist
The hosts, applications, APIs and environments that may be tested.
Action policy
Permitted techniques, prohibited actions, rate limits and operating windows.
Identity boundary
The test accounts, roles and credentials approved for use.
Authorization record
The written authority associated with the testing plan and every resulting action.
AI privacy boundary
The custom AI engine redacts and minimizes sensitive customer information before sending approved context to third-party AI models.
PROOF QUESTIONS
The agent must answer before a finding ships.
- 01
Is the target explicitly in scope?
- 02
Is this technique permitted for this environment?
- 03
Does the action stay within approved identity and rate limits?
- 04
Can the platform explain why the request was allowed?
Continuous does not mean unrestricted.
- Submitting a URL or document never expands scope.
- Customer documentation may guide testing but cannot grant authority.
- Third-party AI models receive redacted task context rather than underlying sensitive customer data.
- Emergency contacts and stop conditions are agreed before execution.
- Customer-specific controls are finalized during onboarding.
Give the agent a bounded target.
We will confirm the target, authorization, permitted actions, evidence controls and current deployment support before testing begins.