Controlled optional assurance product

Assess authorised infrastructure without turning scanner execution into an uncontrolled black box.

Guardian Infrastructure Assessment controls target authorisation, assessment policy, scheduling, dedicated execution, normalised findings, evidence and remediation.

Australian data residency

Guardian for Australian customers is built, operated and hosted in Australia. All Guardian customer and platform data, including backups and recovery copies, is maintained and stored within Australia.

Authorised targetsPolicy-controlled executionDedicated assessment jobsGuardian findings and remediation
Buyer decision summary

Know what Guardian Infrastructure Assessment does, what the customer sees and what Damocles is responsible for before activation.

Guardian retains target authority, profile snapshot, job status, node and timing references, finding identity, severity, evidence, actions, reassessment and closure history. Credentials and raw scanner payloads remain restricted.

The proposal identifies target quantity, environment, profile, credentials, cadence, execution capacity, evidence, retention, reassessment, support and provider relationship.

Target ownership, credentials, profile, schedule, exclusions and permitted methods must be approved. Third-party targets remain excluded without authority.

01

What the product does

The selected compatible scanner, target count, credentials, policy and cadence are identified in the product schedule.

02

What the customer sees

Provider operations remain customer scoped and entitlement controlled.

03

What Damocles manages

Manual exploitation and engineering remain separate professional services.

The operational problem

Repeatable infrastructure assessment must scale without weakening target ownership, execution safety or customer evidence.

Customers and providers need to know which systems are authorised, which profile was used, where the job ran, whether the scanner is healthy, what evidence supports the finding and how remediation is verified.

Guardian separates the customer and application workflow from dedicated execution. This keeps target attestation, entitlements, jobs, leases, cancellation, findings and evidence under controlled policy.

01

Authorise every target

Require active customer ownership, scope and attestation before the target enters an assessment job.

02

Supervise execution

Use approved profiles, dedicated scanner nodes, claims, leases, heartbeats, timeout and cancellation.

03

Move findings into remediation

Normalise supported results and link material issues to risks, actions, evidence and verification.

Product capability

The controls required for a production infrastructure-assessment service.

The selected compatible scanner, target count, credentials, policy and cadence are identified in the product schedule.

AT

Authorised target inventory

Maintain active, customer-owned, attested target records with environment and business context.

PS

Policy snapshots

Capture the approved assessment profile and retain it with the job for traceability.

QJ

Queued jobs

Validate entitlement and create bounded jobs from the application workflow.

HS

Health and supervision

Use claims, leases, heartbeats, timeout, cancellation and node health around execution.

NF

Normalised findings

Convert supported results into customer-readable severity, status, evidence and affected scope.

RA

Remediation and verification

Link material findings to owners, due dates, evidence, reassessment and reporting.

What the customer sees

Customers see assessment scope, status, findings and actions without access to unsafe execution internals.

Provider operations remain customer scoped and entitlement controlled.

TI

Target inventory

Authorised targets, environment, ownership, attestation and active assessment status.

JS

Job status

Queued, claimed, running, completed, failed, timed-out and cancelled job state.

FS

Finding summary

Normalised severity, target, lifecycle, source profile, observation and remediation owner.

FD

Finding detail

Customer-readable issue, evidence, affected service and practical remediation guidance.

VR

Verification state

Evidence, reassessment, reopen and closure state according to the approved workflow.

PV

Provider operations

Authorised customer targets, jobs, findings and actions with explicit tenant relationships.

What Damocles manages

Damocles manages target governance, execution infrastructure and result quality according to scope.

Manual exploitation and engineering remain separate professional services.

TA

Target governance

Confirm ownership, attestation, credentials, exclusions, contacts and permitted assessment behaviour.

PM

Profile management

Maintain approved assessment profiles, policy snapshots and entitlement limits.

NO

Node operation

Operate dedicated scanner nodes, health, capacity, leases, cancellation and secure result return.

QR

Quality review

Review result completeness, duplicates, target mapping, evidence and customer-safe presentation.

RF

Remediation follow-up

Track owners, due dates, exceptions, evidence and reassessment readiness.

SR

Assessment reporting

Report target coverage, job health, findings, actions, reassessments and unresolved limitations.

Operating lifecycle

From target attestation to controlled execution and reviewed remediation.

Scanner binaries remain isolated from public web request handlers and operate only on approved jobs.

01

Authorise

Confirm target ownership, credentials, profile, contacts, exclusions and safe-testing restrictions.

02

Snapshot

Record the approved target and assessment policy for the job.

03

Queue

Validate entitlement and create the bounded assessment job.

04

Execute

A dedicated node claims and performs the job with health and lease supervision.

05

Normalise

Import supported results and prepare customer-readable findings and evidence.

06

Remediate and verify

Assign required actions and use evidence or reassessment to review closure.

Common use cases

Common infrastructure-assessment use cases.

The product supports controlled recurring or on-demand assessment where exact targets and policy are required.

IN

Internal infrastructure

Assess authorised internal systems and services using the approved access and credential model.

EX

External infrastructure

Assess approved public-facing systems with a profile deeper than baseline monitoring where authorised.

MS

MSP assessment service

Operate exact customer target scope, jobs and findings through provider entitlements.

SC

Scheduled assurance

Run approved recurring jobs against stable target groups and track remediation over time.

CH

Post-change assessment

Assess a defined environment after migration, build, hardening or significant configuration change.

RV

Remediation verification

Run a controlled reassessment against previously identified issues and affected targets.

Operating model

How Guardian Infrastructure Assessment is onboarded, integrated, evidenced and scoped commercially.

These details remain explicit before activation, but are grouped into one operating view so buyers can review the responsibilities without working through four separate page sections.

ON

Onboarding and implementation

Onboarding confirms target authority, assessment profile and execution architecture. The customer provides target inventory, ownership, network paths, credentials, environment, business context, maintenance windows, exclusions, contacts and any prohibited activity. Targets without confirmed authority do not enter the active workflow. Damocles validates scanner-node reachability, target behaviour, credentials, profile, capacity, cancellation, evidence and result mapping before recurring schedules are enabled. Go-live records target and job entitlement, profile, cadence, support, result review, reporting and the boundary to manual penetration testing and remediation engineering.

IN

Connector and integration model

Guardian controls the assessment lifecycle while compatible execution nodes perform the scanner-specific work. The application service creates validated jobs and never executes scanner binaries directly in public request handlers. Dedicated nodes claim approved jobs, report heartbeats, return supported results and honour cancellation and timeout. The selected scanner or assessment engine can change if target governance, policy, finding continuity, evidence quality and supportability remain controlled. The proposal identifies the supported implementation and profile. New execution connectors are reviewed for node isolation, credentials, target controls, job supervision, output quality, rate and capacity, cancellation, support and commercial effort.

EV

Data, evidence and reporting

Assessment records preserve the target, profile, job, finding and remediation chain. Guardian retains target authority, profile snapshot, job status, node and timing references, finding identity, severity, evidence, actions, reassessment and closure history. Credentials and raw scanner payloads remain restricted. Failed, timed-out and cancelled jobs are shown explicitly and never represented as completed clean assessments. Reports identify covered targets, successful and failed jobs, material findings, overdue actions, reassessments and known limitations.

CM

Commercial unit and responsibilities

Commercial scope follows targets, profiles, schedules and separately agreed assessment activity. The proposal identifies target quantity, environment, profile, credentials, cadence, execution capacity, evidence, retention, reassessment, support and provider relationship. Manual exploitation, custom scanner engineering, destructive methods, emergency work and remediation implementation remain separate unless included. The customer owns target authority and remediation decisions. Damocles owns the controlled assessment and review activities listed in the schedule.

Frequently asked questions

Questions buyers ask about Guardian Infrastructure Assessment.

The exact answer is confirmed in the proposal and package schedule, but these points should be understood before activation.

Q1

Can assessments run on a schedule?

Yes where target and profile entitlement, node capacity and the approved cadence are configured.

Q2

Can credentials be used?

Yes where authorised and handled through approved operational controls. Credentials are not exposed publicly.

Q3

Does Guardian run scanners in the web application?

No. Dedicated scanner nodes perform execution outside public request handlers.

Q4

Can an MSP operate customer assessments?

Yes through explicit provider authority, customer target ownership and product entitlements.

Q5

Does this replace penetration testing?

No. It provides controlled infrastructure assessment, while manual attack-path testing remains a separate engagement.

Q6

What happens when a node fails?

Jobs use health, leases and timeout state so failure is visible and can be retried or reviewed safely.

Scope and boundaries

Infrastructure Assessment never authorises arbitrary scanning or destructive activity.

Target ownership, credentials, profile, schedule, exclusions and permitted methods must be approved. Third-party targets remain excluded without authority.

The product does not imply exploitation, denial-of-service testing, unrestricted discovery or complete vulnerability identification.

Manual penetration testing, remediation engineering and specialist validation remain separate unless expressly included.

Take the next practical step

Define the authorised infrastructure scope and evidence the customer needs from each assessment.

We will map targets, policy, credentials, cadence, execution nodes, findings, remediation and verification.