P-01 · Web Application Penetration Testing

Every route. Every flow. Every run.

Hand Rift your source and it reasons from code to a real vulnerability, mapping every route and walking every auth flow the way a real attacker would. Authorize a running instance and it confirms each finding live, so what reaches you is evidence-backed, not a maybe.

// Capabilities

Built to think, not just scan

Four things a signature scanner can't do, and that a once-a-year pentest can't keep pace with.

White-box, from your source

Rift reads your code for taint-aware depth and reasons from source to a real vulnerability. Add credentials and a running instance and it confirms findings live. Source is required to run; black-box from a URL alone is on the roadmap.

Business logic, beyond signatures

Reasons about checkout, RBAC, tenancy, and multi-step flows to surface IDOR, auth bypass, privilege escalation, and abuse a pattern-matcher will never see.

SAST + DAST, fused

Code-level analysis finds the soft spot, then Rift fires real requests at a running instance you authorize to confirm it's actually reachable. Live confirmation is opt-in, seeded by the code analysis, not a separate blind scanner.

Every finding comes with evidence

The exact code path that proves it, plus a working request and payload where live confirmation is authorized, all captured and replayable. Evidence-gated, so triage time goes to fixing, not verifying.

214
Routes walked per run
9 min
Median time-to-first-finding
0%
False-positive target
100%
Findings backed by evidence

Target figures from internal testing, shown to illustrate the model. Verified customer benchmarks publish at launch.

// Coverage

Modern apps, fully walked

SPAs, REST and GraphQL APIs, server-rendered apps, and the messy auth in between: analyzed from source and, where you authorize a live instance, exercised the way a user (and an attacker) actually would. See how the agents work, or run it for compliance penetration testing.

  • Single-page apps & API-only backends
  • OAuth, SSO, and multi-step authentication flows
  • Role- and tenant-based access control testing
  • Staging or production, with safe-by-default exploitation
  • Re-run any time; each run diffs against the last
OWASP Top 10OWASP API Top 10Business logicAuth & sessionSSRF / XXEInjection
route coverage · acme-app214 mapped
GET/clean
POST/api/auth/loginhigh
GET/api/orders/{id}high
POST/api/checkoutclean
GET/admin/userscrit
PUT/api/profilemed
POST/trackcrit
GET/api/searchclean
2
critical
2
high
0
false pos.
// How it works

From connect to confirmed in three steps

01

Connect & scope

Connect a repo via our GitHub App or a GitLab token, set authorized scope and guardrails, and point live confirmation at a running instance you own. Nothing to install.

02

Agents go to work

Rift reasons from your code and proposes findings; an independent review confirms each before it reaches you. Where you authorize a live target, it fires a real request to confirm.

03

Route, fix, re-run

Verified findings flow to GitHub as draft remediation pull requests with reproduction steps. Re-run any time and Rift diffs against the last run.

// Pricing

Priced by application size

You're scoped by the surface being tested, sized by routes and auth complexity. Run it once, yearly for compliance, or as a re-run subscription. Indicative bands below; we confirm scope with you.

Brochure / marketing
~25 routes, single auth flow: the lightest band.
Standard SaaS app
~120 routes, a handful of auth flows: the typical product.
Complex platform
~400 routes, rich roles and tenancy.
Enterprise suite
1,000+ routes across multiple apps, with custom scoping.

Test your app like an attacker would.

Be first in line. Tell us about your app and we'll bring you on the moment Rift is ready.