Step-by-step guides for configuring runs, reading evidence, and checking whether a defensive change worked in the tested scope.
From account setup to a first controlled run
Pick a target, scan profile, and review findings
Calibrate attack_depth and compliance_tags
Connect the supported GitHub Action and learn what makes a pull request pass or fail
Copy-paste a Shields-style security badge into any README or doc site
Interpret the five verdicts and the score-vs-finding delta distinction
Send an invitation, verify acceptance, and understand when a seat is counted.
Templatize an attack you already ran and add it to your tenant catalogue. Pro plan and above.
Store SAML or OIDC IdP metadata for your tenant. Enterprise plan only.
Review the planned tenant delivery boundary; webhook subscribers do not send production events in this release.
Turn a saved RunRequest into hourly / daily / weekly defense validation.
Diff decision-grade scores and finding lifecycle between two scope-compatible runs, with explicit evidence coverage.
Install once at the org level and every PR runs the PR Diff Red-Team Gate.
Download auto-emitted detection rules, import to Splunk or Elastic, and track from starter to verified.
From webhook payload to Sigma rule shipped — the exact sequence for a SOC analyst.
Turn a RunScore + compliance mapping + run comparison into a boardroom presentation.
See a controlled security run before configuring your own target.