Secori secori.io
BuildingAdaptive security testing · research phase

Protection atevery stage.

Adaptive security testing for code, applications and live systems. Specialist agents map what you expose, test how an attacker would use it, challenge their own findings and tell you what to fix, with evidence.

01Test a live app · authorized URL, no code needed↗ 02Connect a repository · pinned commit, minimum permissions↗ 03Upload files · snapshot hashed at intake↗
live consoleapp.nimbus-pay.test · authenticated run · syntheticscan-2291
00:00:00judgereproduced F-0417 from pin; negative control passed
0entry points · live app, repository, files
0evidence tiers · suspected to fix-verified
0specialists · independent review built in
0green “secure” badges, ever
01 / 06

Coverage across the lifecycle.

current vs planned, labeled

Built for what you are building, what is live, and what changes next. Each stage says what is available today and what is still planned.

01BuildSource review on a pinned commit: access control, privileged paths, exposed secrets, unsafe rendering in supported stacks.
source reviewmore stacks
02LaunchBlack-box and authenticated live testing from the outside in. Browser, exposed APIs, client bundle, roles and sessions.
live testingweb3 frontends, qualified separately
03OperateThreads the fleet follows for you: advisories, dependency changes, repository diffs. A new endpoint in your bundle becomes a hypothesis.
threadsscheduled retesting
04EvolveBounded retests on a new pin: the original failure before, the fix after, nearby variants and a benign control. Nothing merges or deploys by itself.
retestchange-review plan
02 / 06

How the swarm investigates.

map · test · challenge · explain · recheck

Adaptive means the investigation changes with what it observes. Here one observation changes the next test.

01CartographerDiffs the client bundle and finds an export endpoint that was not there last week.
02DispatcherRoutes the observation. Export touches records, so Tenant gets it at high effort under the job's ceiling.
03TenantCompares what each role can reach through the new endpoint and raises a candidate.
04JudgeReproduces from the pin alone, without the author's notes, then runs the benign control.
05ScribeWrites the private report: where, prerequisites, impact, evidence tier, fix, and what was not tested.
06JudgeOn your new pin: original fails to reproduce, variants checked, control still passes. Fix-verified.
bundle diff
dispatch
role comparison
reproduce + control
private report
03 / 06

What a useful result looks like.

synthetic example · not a customer report

Every report says how sure we are, what it took, what it means, what to change and what was not covered. There is no green safety score.

syntheticF-0417criticalreviewed
Order records readable across workspaces.
Where
Orders API, record lookup by identifier
Prerequisites
Any signed-in user of any workspace
Impact
Order history of other customers can be read. No write path observed.
Evidence
Reproduced on the authorized runtime by an independent specialist from the pin alone. Benign control passed.
Fix
Scope the lookup to the caller's workspace in the data layer; add a tenant-boundary test for every record type.
Not covered
Export endpoint not yet tested. Admin role out of scope.
01Evidence ladder
suspected✓
source-supported✓
sandbox-reproduced✓
runtime-reproduced✓
reviewednow
fix-verified
02Rule

Many agreeing agents are not independent evidence. A finding moves up only when a different specialist reproduces it without the author's notes and the control behaves as expected.

04 / 06

The swarm.

ten specialists · one evidence system

Each specialist owns one method and one toolset, runs in an ephemeral sandbox with a network allowlist, and never inherits a personal credential. The fleet hunts continuously and can be pointed at one target as a service.

05 / 06

Proof, limits, funding.

benchmarks when they exist · token route unselected
Matched-scope benchmark
— / —

Not an achieved score. The placeholder stays until a frozen cohort, a baseline, held-out cases, negative controls, measured cost and independent grading exist.

cohort: proposedgrading: independentcost cap: required
What exists today
  • Offline evidence fixture: vulnerable and corrected twin, four tests, sixteen observations, pinned hashes.verified
  • Engineering foundation for source review and authorized live testing.reviewed
  • This design system: site and console on one visual language, synthetic data throughout.you are here
  • Shared contract prototype: intake, durable job, private report, retest.next
  • Paired mode trials and a qualified pilot lane with measured cost.after
01
Token fees
Collected into a liquid treasury. Venue, rate and chain undecided.
02
Budgets
Bounded compute and verification after liabilities and reserve.
03
Useful work
Accepted findings and reports under measured cost.
04
Capability
Reusable tests and stronger specialists.
05
Participation
More service and, later, community direction. An adoption hypothesis.

Project-token fees are intended to fund compute, specialist testing and verification. Collected funds, obligations and reserve stay separately visible. Buying a token is never in the scan path. Treasury view →

06 / 06

Roadmap.

from the plan, not from the pitch
F0SpecificationBoth modes, boundaries, frontend flows, primary evidence, staged acceptance.complete
F1Shared contract prototypeIntake → durable job → private report → retest, with duplicate, denial, cancel and failure states.next
F2Paired mode trialsInert source import and a scoped local-app run compared with one report rubric.queued
F3Choose and qualify a pilot laneFrozen cohort, independent grading, provider, privacy and capacity evidence, bounded cost.queued
F4Customer pilot readinessTenant isolation, deletion and retention, scope enforcement, recovery, one accepted full journey.queued
Next step

Security that learns. Protection that evolves.

Bring your app or code. Get a clearer view of its security, with the evidence to act on it.