Account

Overview

Sample data
Everything on this page is sample data. There is no Acme Corp customer: the company, the engagement name, the dates and the SOW reference are made up. The decisions, findings and chain head are real output, from connector image 0.3.0 run on 2026-09-14 against two lab listeners at these addresses (10.0.5.0/24 is a private range; 203.0.113.0/24 is an IANA documentation range). No customer data appears here.
Every finding mapped to ATT&CKNIST 800-53 the control language SOC 2, PCI DSS and HIPAA programs map to. A NIST CSF 2.0 crosswalk is planned and is not built, so nothing here emits one
Assessment plan runs on demand from your connector

Every finding below is severity Informational, with no CVSS score. That is the ceiling this product reaches, not the floor. The shipped executor is a TCP-connect probe: it records that a port answered on a host inside the approved scope. It does not authenticate, fingerprint versions, test inputs or assign CVSS, and no plan changes that. This is a reachability and discovery instrument, not a penetration test, and it must not be represented as one.

Scope integrity
2 out-of-scope attempts, denied
Denied at the policy decision point, before execution. Every decision in this engagement is written to the signed chain and is independently re-verifiable.
Actions evaluated
4
2 allowed · 2 denied · 0 held
Audit chain
verifies OK
head cfed4198 · 4 entries · signed
the guardrails your assessment runs under

Constrained by policy. Recorded by default.

all enforced
enforced
PEP
Deny by default
Every action is checked against the approved scope before it runs. No model sits in the decision path.
enforced
SCOPE
Reviewed scope envelope
Scope is validated, versioned policy bound to minted capability material - not a config flag that can drift.
enforced
LOG
Hash-chained audit
Every decision is recorded, signed, and tamper-evident. One edit breaks the chain.
enforced
DEPTH
Gated depth ceiling
recon / active / exploit are gated; nothing exceeds the depth you approved.
armed
STOP
Stop reporting
Revoke the enrollment and the connector can no longer report. A run in progress is stopped on the connector host, by stopping its container. You hold both switches.
enforced
PROOF
Re-verifiable
The decision chain re-verifies against your connector's own key, by hash, without us.

“Don't trust the AI. Read the policy it has to pass, and the signed record it cannot alter.”

Every decision on the record

Governed decision ledger

tamper-evident

Every action was checked against the approved scope before it ran, then written to a hash-chained audit signed by your connector's key. This is your record, and an auditor can replay it without us.

ALLOW
ASSESS /recon/10.0.5.10
in scope, class granted, depth ok · nmap: 443/tcp 3389/tcp open of 5 probed
signed
ALLOW
ASSESS /recon/10.0.5.25
in scope, class granted, depth ok · nmap: 8080/tcp open of 5 probed
signed
DENY
ASSESS /recon/10.0.5.99
10.0.5.99 OUT OF SCOPE - no packet sent · excluded from the estate
signed
DENY
ASSESS /recon/203.0.113.10
203.0.113.10 OUT OF SCOPE - no packet sent · outside the estate
signed
chain verifies OK head cfed4198521dc2f8·signed by the connector key
Status
Connectorenrolled · online
Latest reportready
Scope tokenapproved
Depth ceilingrecon

Findings
2 Informational
Open the report →
the loop
01
Scope
Authored → proposed → human review → capability re-minted
02
Assess
Deny-by-default PDP under the agent, every action
03
Prove
Hash-chained, signed, tamper-evident record
04
Report
Auditor-ready, standards-mapped, cited by hash

Category: governed security assessment - scope checked per action, every decision signed. No model sits in the decision path.

active

Acme Corp - External Perimeter (sample)

sample engagement acme-2026-07 · window 2026-07-27 → 2026-07-29
depth ceiling: recon
Rules of engagement
Approved scope
acme-2026-07
Estate (in-bounds)
10.0.5.0/24
Targets
10.0.5.10, 10.0.5.25, 10.0.5.99, 203.0.113.10
Exclusions
10.0.5.99/32
Ports
22, 80, 443, 3389, 8080
Depth ceiling
recon
Prohibited
dos
Token TTL
3600s
SOW reference
SOW-acme-2026-07.pdf
Scope of record

Reachability of the approved TCP ports on 10.0.5.10 and 10.0.5.25, inside estate 10.0.5.0/24. Out of scope: 10.0.5.99, excluded from the estate, and every address outside it, including 203.0.113.10. Both were denied before a packet was sent, and both denials are signed entries in the chain.

how this scope was authorized
1
Scope authored
Estate, targets, exclusions, depth - entered here
2
Change proposed
Validated, then staged as a proposal
3
Human review
Opens a review ticket; approved by account owner ✓
4
Capability re-minted
New scope bound to fresh credentials

The approval gate is part of the product, not friction: a scope change is staged as a proposal and no capability is re-minted until a human approves it. Your SOW reference is recorded alongside the scope for traceability - the scope itself is authored here, not extracted from the document.

The proof it stayed in bounds

Scope-integrity record

tamper-evident
Actions evaluated
4
2 allowed · 2 denied · 0 held
Out-of-scope attempts
2
all denied at the decision point, before execution
Entries in chain
4
head cfed4198521dc2f8

Decision ledger

signed by the connector key
ALLOW
ASSESS /recon/10.0.5.10
in scope, class granted, depth ok · nmap: 443/tcp 3389/tcp open of 5 probed
signed
ALLOW
ASSESS /recon/10.0.5.25
in scope, class granted, depth ok · nmap: 8080/tcp open of 5 probed
signed
DENY
ASSESS /recon/10.0.5.99
10.0.5.99 OUT OF SCOPE - no packet sent · excluded from the estate
signed
DENY
ASSESS /recon/203.0.113.10
203.0.113.10 OUT OF SCOPE - no packet sent · outside the estate
signed
chain verifies OK re-verify independently: recompute the SHA-256 chain - each hash must match and each sig verifies against the connector's published key. One altered entry breaks the chain.

“A claim you cannot trace is a claim we did not make.”

Auditor-ready · standards-mapped

Security Assessment - Acme Corp External Perimeter (sample)

generated 2026-07-30 · governed assessment · sample data
2 Informational scope integrity: verified

This assessment recorded 2 findings, both Informational with no CVSS score: TCP ports that accepted a connection on an approved target. Each finding cites, by hash, the signed audit entry that authorized the probe which produced it.

Reachable network services on 10.0.5.10

10.0.5.10 · RECON-001
443/tcp 3389/tcp
Informational

An open port was observed on 10.0.5.10. 2 of 5 scoped TCP ports accepted a connection: 443/tcp (HTTPS), 3389/tcp (RDP). This includes a remote-access / management service exposed to the assessing host: 3389/tcp (RDP). The probe established a TCP connection and nothing further: no service was interrogated, no credential was tried and no vulnerability was tested. This finding records reachability, which is why no CVSS score is asserted.

Evidence: nmap probed 5 port(s) [22, 80, 443, 3389, 8080] on 10.0.5.10; authorized by signed audit entry idx 0 (hash 8d85da3f00ee4634). No CVSS score.

ATT&CK T1133 ATT&CK T1190 NIST SC-7 NIST CM-7 NIST AC-17 audit idx 0 8d85da3f

Reachable network services on 10.0.5.25

10.0.5.25 · RECON-002
8080/tcp
Informational

An open port was observed on 10.0.5.25. 1 of 5 scoped TCP ports accepted a connection: 8080/tcp (HTTP-alt). The probe established a TCP connection and nothing further: no service was interrogated, no credential was tried and no vulnerability was tested. This finding records reachability, which is why no CVSS score is asserted.

Evidence: nmap probed 5 port(s) [22, 80, 443, 3389, 8080] on 10.0.5.25; authorized by signed audit entry idx 1 (hash 1c2601c0667b115a). No CVSS score.

ATT&CK T1190 NIST SC-7 NIST CM-7 audit idx 1 1c2601c0

ATT&CK techniques listed are those whose precondition the exposure satisfies, not techniques observed to succeed. These findings are as the connector records them in its signed engagement document. Known defect in connector 0.3.0. In every connector image from 0.3.0 through 0.4.1, ship-report relabelled them Unrated, dropped the ATT&CK and NIST mapping, and claimed knowledge-store citations while listing every store ABSENT. Fixed in 0.4.2: the shipped report keeps Informational and the mapping, and says in its body that no knowledge-store citations were resolved.


Appendix A · source integrity

Knowledge stores. The connector image carries none, so the report it ships lists each as ABSENT; the findings above are cited by the hash of a signed audit entry instead, which anyone can re-verify.

threat_intel ABSENT nist ABSENT pentest_method ABSENT dfir ABSENT
Outbound-only, in your infrastructure

Assessment connector

enrolled · online
PEP identity
pep-01 · SoulKey (Ed25519)
Deployment
container in infrastructure you operate · outbound-only to your control plane
Standup
approval-gated (scope + targets) before any run
Enforcement
deny-by-default action-PEP · no LLM in path
Audit
SoulKey-signed, hash-chained, shipped to the control plane you run
Last seen
2 min ago

The connector is itself governed: it enforces the same signed policy in your network that the control plane issued, and it only speaks outbound. Nothing runs until you approve the standup.

body of knowledge

The agent draws on a curated, hash-chained corpus - the GPEN + GCFA body of knowledge as method and judgment, never exploit code. Every finding traces to one of these by store @ hash.

📚 pentest_method
Assessment structure, RoE, and severity per NIST SP 800-115. The GPEN discipline.
NIST SP 800-11537 · ok
🔎 dfir
Evidence handling & chain-of-custody per NIST SP 800-86. The GCFA discipline that makes findings defensible.
NIST SP 800-8635 · ok
🎯 threat_intel
Adversary technique taxonomy - the MITRE ATT&CK mapping for every finding.
MITRE ATT&CK829 · ok
📑 nist
Finding-to-control mapping - NIST 800-53 control identifiers. No CSF 2.0 crosswalk is emitted.
800-531402 · ok
🔄 normalize
Weakness-to-technique translation for tighter ATT&CK precision across the corpus.
semantic bridgeok

We ship methodology and governance, not weapons: the corpus grounds judgment. Any cited hash re-verifies with tkhr_store verify <slug>.

multi-home management

Accounts you manage

-

Customer accounts that have delegated secondary admin to you. Act as one to run its engagements, scope, and connectors. The customer stays sovereign and can revoke at any time.

loading…
delegated access to your account

Who can act on your behalf

Grant an MSSP secondary admin over your account by their handle. They can run engagements, scope, and connectors - but never re-delegate, bill, or change your settings. Revoke instantly.

loading…
act as an MSSP

Your MSSP handle

-

If you run assessments for other accounts, enable MSSP mode and share your handle. A customer pastes it above on their side to delegate access to you.

loading…
people in this account

Members

Invite colleagues by email and assign a role. Owner = full control; Admin = manage the account; Operator = author scope only; Auditor = read-only.

loading…
directory group to role

AD / IdP group mapping

Map your directory groups to roles. When a user signs in through your AD, their group memberships grant these roles automatically.

connect your directory

AD / LDAP sign-in

-

Point at your Active Directory so your people sign in with their existing credentials. The bind password is stored write-only and never shown.

connecting to your control plane…
tiresias.report

No account here yet

You are signed in, but this control plane has no account for you. Accounts are provisioned by whoever operates this control plane: ask them to provision your organisation and grant you a role, then sign in again.

Signed in as

tiresias.report

Sign in

Sign in to reach your account on this control plane. Accounts are provisioned by its operator; there is nothing to buy here.

Continue with Google
or your organization