Overview
SecOpent is a catalog-driven, agent-native pentest workbench.
17 adapters across asset/web/network/cloud/identity.
Pain → Solution → Value
Authorized pentests used to take weeks of scoping before the first test ran — and a single drift past the rules of engagement could invalidate everything that followed. SecOpent compresses the loop into three stages: the unsafe default, what the catalog gates, and what changes for the team.
Pain
Agents run unsafely
LLMs probe production systems on their own.
Solution
Catalog gates scope + tools
Deterministic layer + human decides.
↓100%" data-i18n-zh="↓100%">↓100%
Off-scope incidents
Pain
Scope drift mid-engagement
Scope creep invalidates findings.
Solution
Catalog diffs scope, re-gates
Every change re-issues approvals.
0
Scope-creep events
Pain
Findings unsigned, unauditable
Reports auditors cannot trust.
Solution
Signed findings + audit trail
Immutable log of every action.
↑100%" data-i18n-zh="↑100%">↑100%
Signed output
Pain
Pentest cost = one-shot weeks
Weeks of scoping per engagement.
Solution
17 cross-domain adapters
Asset / web / network / cloud / identity.
17
Adapter coverage
What changes for the team
A wider view of the same loop. Each card zooms into the corresponding column above.
Pain
AI in pentesting defaults to unsafe
- LLM-driven tools make dangerous decisions autonomously — probing production without consent.
- Scope drift, unsigned findings, and unauditable results become the default, not the exception.
- Manual scoping eats days before a single test even runs.
17 days
Avg. scoping time per engagement
Solution
Catalog gates every dangerous decision
- The LLM only proposes — a deterministic layer + human operator decides every step.
- Scope, approval, signing, and publish are all gated by the catalog.
- Findings are cryptographically signed; every action lands in an immutable audit trail.
17
Cross-domain adapters ready
Value
Pentest cycles shrink from weeks to days
- Scope and approval are pre-encoded in the catalog — scoping goes from days to minutes.
- AI is used safely inside a defined boundary, not bolted onto the perimeter.
- Reports ship with cryptographic evidence that satisfies MLPS 2.0 / 等保 2.0 — no rebuild required.
100%
Signed, audit-ready output
Product architecture
Every authorized engagement moves through the same five participants.
Capabilities
Catalog-driven
17 adapters · YAML case DSL · CoverageMatrix.
Agent-native
LLM proposes; deterministic layer + humans decide.
Oracle N/N validation
Independent re-runs to catch flaky tests.
Hardened sandbox
seccomp · process-isolated · timeout + resource caps.
By the numbers
- 17 cross-domain adapters
- YAML case DSL
- Oracle N/N validation
- seccomp sandbox
- 3-layer evidence + redaction