What the product does
The selected compatible scanner, target count, credentials, policy and cadence are identified in the product schedule.
Guardian Infrastructure Assessment controls target authorisation, assessment policy, scheduling, dedicated execution, normalised findings, evidence and remediation.
Guardian for Australian customers is built, operated and hosted in Australia. All Guardian customer and platform data, including backups and recovery copies, is maintained and stored within Australia.
Guardian retains target authority, profile snapshot, job status, node and timing references, finding identity, severity, evidence, actions, reassessment and closure history. Credentials and raw scanner payloads remain restricted.
The proposal identifies target quantity, environment, profile, credentials, cadence, execution capacity, evidence, retention, reassessment, support and provider relationship.
Target ownership, credentials, profile, schedule, exclusions and permitted methods must be approved. Third-party targets remain excluded without authority.
The selected compatible scanner, target count, credentials, policy and cadence are identified in the product schedule.
Provider operations remain customer scoped and entitlement controlled.
Manual exploitation and engineering remain separate professional services.
Customers and providers need to know which systems are authorised, which profile was used, where the job ran, whether the scanner is healthy, what evidence supports the finding and how remediation is verified.
Guardian separates the customer and application workflow from dedicated execution. This keeps target attestation, entitlements, jobs, leases, cancellation, findings and evidence under controlled policy.
Require active customer ownership, scope and attestation before the target enters an assessment job.
Use approved profiles, dedicated scanner nodes, claims, leases, heartbeats, timeout and cancellation.
Normalise supported results and link material issues to risks, actions, evidence and verification.
The selected compatible scanner, target count, credentials, policy and cadence are identified in the product schedule.
Maintain active, customer-owned, attested target records with environment and business context.
Capture the approved assessment profile and retain it with the job for traceability.
Validate entitlement and create bounded jobs from the application workflow.
Use claims, leases, heartbeats, timeout, cancellation and node health around execution.
Convert supported results into customer-readable severity, status, evidence and affected scope.
Link material findings to owners, due dates, evidence, reassessment and reporting.
Provider operations remain customer scoped and entitlement controlled.
Authorised targets, environment, ownership, attestation and active assessment status.
Queued, claimed, running, completed, failed, timed-out and cancelled job state.
Normalised severity, target, lifecycle, source profile, observation and remediation owner.
Customer-readable issue, evidence, affected service and practical remediation guidance.
Evidence, reassessment, reopen and closure state according to the approved workflow.
Authorised customer targets, jobs, findings and actions with explicit tenant relationships.
Manual exploitation and engineering remain separate professional services.
Confirm ownership, attestation, credentials, exclusions, contacts and permitted assessment behaviour.
Maintain approved assessment profiles, policy snapshots and entitlement limits.
Operate dedicated scanner nodes, health, capacity, leases, cancellation and secure result return.
Review result completeness, duplicates, target mapping, evidence and customer-safe presentation.
Track owners, due dates, exceptions, evidence and reassessment readiness.
Report target coverage, job health, findings, actions, reassessments and unresolved limitations.
Scanner binaries remain isolated from public web request handlers and operate only on approved jobs.
Confirm target ownership, credentials, profile, contacts, exclusions and safe-testing restrictions.
Record the approved target and assessment policy for the job.
Validate entitlement and create the bounded assessment job.
A dedicated node claims and performs the job with health and lease supervision.
Import supported results and prepare customer-readable findings and evidence.
Assign required actions and use evidence or reassessment to review closure.
The product supports controlled recurring or on-demand assessment where exact targets and policy are required.
Assess authorised internal systems and services using the approved access and credential model.
Assess approved public-facing systems with a profile deeper than baseline monitoring where authorised.
Operate exact customer target scope, jobs and findings through provider entitlements.
Run approved recurring jobs against stable target groups and track remediation over time.
Assess a defined environment after migration, build, hardening or significant configuration change.
Run a controlled reassessment against previously identified issues and affected targets.
These details remain explicit before activation, but are grouped into one operating view so buyers can review the responsibilities without working through four separate page sections.
Onboarding confirms target authority, assessment profile and execution architecture. The customer provides target inventory, ownership, network paths, credentials, environment, business context, maintenance windows, exclusions, contacts and any prohibited activity. Targets without confirmed authority do not enter the active workflow. Damocles validates scanner-node reachability, target behaviour, credentials, profile, capacity, cancellation, evidence and result mapping before recurring schedules are enabled. Go-live records target and job entitlement, profile, cadence, support, result review, reporting and the boundary to manual penetration testing and remediation engineering.
Guardian controls the assessment lifecycle while compatible execution nodes perform the scanner-specific work. The application service creates validated jobs and never executes scanner binaries directly in public request handlers. Dedicated nodes claim approved jobs, report heartbeats, return supported results and honour cancellation and timeout. The selected scanner or assessment engine can change if target governance, policy, finding continuity, evidence quality and supportability remain controlled. The proposal identifies the supported implementation and profile. New execution connectors are reviewed for node isolation, credentials, target controls, job supervision, output quality, rate and capacity, cancellation, support and commercial effort.
Assessment records preserve the target, profile, job, finding and remediation chain. Guardian retains target authority, profile snapshot, job status, node and timing references, finding identity, severity, evidence, actions, reassessment and closure history. Credentials and raw scanner payloads remain restricted. Failed, timed-out and cancelled jobs are shown explicitly and never represented as completed clean assessments. Reports identify covered targets, successful and failed jobs, material findings, overdue actions, reassessments and known limitations.
Commercial scope follows targets, profiles, schedules and separately agreed assessment activity. The proposal identifies target quantity, environment, profile, credentials, cadence, execution capacity, evidence, retention, reassessment, support and provider relationship. Manual exploitation, custom scanner engineering, destructive methods, emergency work and remediation implementation remain separate unless included. The customer owns target authority and remediation decisions. Damocles owns the controlled assessment and review activities listed in the schedule.
The exact answer is confirmed in the proposal and package schedule, but these points should be understood before activation.
Yes where target and profile entitlement, node capacity and the approved cadence are configured.
Yes where authorised and handled through approved operational controls. Credentials are not exposed publicly.
No. Dedicated scanner nodes perform execution outside public request handlers.
Yes through explicit provider authority, customer target ownership and product entitlements.
No. It provides controlled infrastructure assessment, while manual attack-path testing remains a separate engagement.
Jobs use health, leases and timeout state so failure is visible and can be retried or reviewed safely.
We will map targets, policy, credentials, cadence, execution nodes, findings, remediation and verification.