Optional active-testing product

Test websites and APIs more deeply, explain the weakness and verify the fix.

Katana coordinates authorised active website and API assessment, authenticated or custom profiles, customer-readable findings, evidence, actions and rescans through Guardian.

Synthetic Guardian Website Security and Katana workspace showing readiness, control results, evidence, remediation and rescans.
Synthetic Website Security and Katana demonstration data using the Guardian business-workspace style. No customer information.
Australian data residency

Guardian for Australian customers is built, operated and hosted in Australia. All Guardian customer and platform data, including backups and recovery copies, is maintained and stored within Australia.

Authorised active testingWebsite and API profilesCustomer-readable evidenceRescans and remediation review
Buyer decision summary

Know what Guardian Katana Website and API Security Testing does, what the customer sees and what Damocles is responsible for before activation.

Guardian retains target, profile, job, timestamps, finding identity, severity, affected function, approved evidence, action and rescan history. Credentials, raw requests, secrets and unrestricted scanner payloads remain restricted.

The proposal identifies websites and APIs, environments, profiles, authentication, automatic cadence, on-demand allowance, cooldown, rescan quantity, evidence, retention, customer users and support.

The product does not authorise arbitrary scanning, destructive testing, denial-of-service activity, unrestricted credential use or assessment of third-party systems.

01

What the product does

Target limits, cadence, profiles, manual-test cooldowns and rescan allowances are confirmed in the package schedule.

02

What the customer sees

The customer experience remains consistent even where the approved execution component changes.

03

What Damocles manages

Manual penetration testing and secure code review remain separate where deeper human-led validation is required.

The operational problem

Baseline checks cannot fully assess authenticated workflows, object ownership, API behaviour and application-specific attack paths.

Modern applications expose APIs, roles, multi-tenant data, business processes and authenticated functions that require a deeper and more controlled assessment profile. The customer also needs evidence a developer can use and a reliable way to review the fix.

Katana adds active assessment beyond Guardian Core monitoring. It manages targets, profiles, schedules, controlled execution, findings, evidence, action linkage and rescans while preserving explicit customer authority and entitlement.

01

Assess the relevant application paths

Use the approved website, API, authentication and profile rather than a generic public-only check.

02

Give developers usable evidence

Present affected scope, reproduction context, severity and remediation guidance without publishing unsafe raw payloads.

03

Verify the remediation

Use included or approved rescans and Guardian evidence to review whether the material issue is resolved.

Product capability

Active website and API assessment under controlled target and profile entitlement.

Target limits, cadence, profiles, manual-test cooldowns and rescan allowances are confirmed in the package schedule.

TG

Approved targets

Maintain explicit customer ownership, URLs, API endpoints, environment, contacts and safety boundaries.

AP

Assessment profiles

Use approved public, authenticated, API or custom profiles according to the application and test objective.

SC

Scheduled and on-demand execution

Run assessment jobs within entitlement, cadence, cooldown and safe-execution policy.

NF

Normalised findings

Convert supported results into consistent severity, status, affected scope and remediation context.

EV

Evidence

Retain approved customer and developer evidence while restricting credentials and unsafe raw detail.

RS

Rescans

Use included or approved rescans to review remediation and reopen findings where necessary.

What the customer sees

Application owners, developers and providers see different depth around one assessment record.

The customer experience remains consistent even where the approved execution component changes.

TS

Target and schedule status

Approved target, profile, latest assessment, next schedule, entitlement and execution state.

FS

Finding summary

Severity, affected website or API, lifecycle state, first and last observation and remediation owner.

FD

Finding detail

Customer-readable description, impact, evidence, affected function and practical remediation guidance.

AC

High-priority actions

Link material findings to Guardian risks and All Actions with owners and due dates.

RR

Rescan result

Record whether the issue is resolved, reduced, still present, reopened or requires manual review.

PV

Provider operations

Authorised customer target, assessment, finding, action and rescan views with explicit scope.

What Damocles manages

Damocles operates target governance, profiles, execution health and assessment follow-up.

Manual penetration testing and secure code review remain separate where deeper human-led validation is required.

TA

Target authorisation

Confirm customer ownership, environment, contacts, credentials, exclusions and permitted assessment behaviour.

PF

Profile preparation

Select or prepare the approved public, authenticated, API or custom assessment profile.

EH

Execution health

Monitor queued, running, completed, failed, timed-out and cancelled assessment jobs.

QR

Quality review

Review supported results, target scope, duplicates, evidence and customer-safe presentation.

RF

Remediation follow-up

Coordinate high-priority actions, developer questions, evidence and rescan readiness.

SR

Assessment reporting

Report target coverage, findings, action state, rescans and current entitlement through Guardian.

Operating lifecycle

From authorised target and profile to finding, remediation and rescan.

Credentials, targets and execution remain controlled by entitlement and approved assessment policy.

01

Authorise

Confirm target ownership, application scope, authentication, contacts, exclusions and safety boundaries.

02

Prepare profile

Select the assessment depth, credentials, schedule, target limits and approved custom behaviour.

03

Execute

Run the assessment through the controlled job and execution workflow.

04

Review findings

Normalise material results, validate scope and prepare customer-readable evidence.

05

Remediate

Assign the required code, configuration, dependency, authentication or control change.

06

Rescan and close

Run the approved rescan and review the result before closing or reopening the finding.

Common use cases

Common Katana assessment use cases.

Katana is selected when the customer needs more depth or frequency than the Guardian Core baseline.

PW

Public website assessment

Assess approved internet-facing application behaviour beyond the baseline monitoring profile.

AU

Authenticated application

Use approved test accounts and roles to assess protected functions and customer workflows.

AP

API assessment

Assess supported endpoints, authentication, object access, input handling and workflow behaviour.

CR

Continuous release cadence

Schedule approved assessments around regular application change and remediation cycles.

MS

MSP customer service

Operate authorised customer targets, profiles, findings and rescans within provider entitlements.

PR

Pentest preparation or follow-up

Use Katana to identify areas requiring deeper manual testing or to maintain awareness after an engagement.

Operating model

How Guardian Katana Website and API Security Testing is onboarded, integrated, evidenced and scoped commercially.

These details remain explicit before activation, but are grouped into one operating view so buyers can review the responsibilities without working through four separate page sections.

ON

Onboarding and implementation

Onboarding requires target authority, application context and safe credential handling. The customer provides target ownership, environment, application contacts, technology context, expected functions, test accounts, roles, API documentation where available, exclusions, maintenance windows and incident contacts. Credentials are handled through approved operational controls and are not exposed publicly. A profile-validation run confirms authentication, target behaviour, test depth, rate and safety controls, expected coverage, false-positive handling and evidence quality before recurring schedules are enabled. Go-live records target and profile entitlement, cadence, on-demand cooldown, rescan allowance, notification, finding review, developer handover, support and the boundary to manual penetration testing.

IN

Connector and integration model

Katana is the Damocles product; controlled assessment components remain behind the execution boundary. The execution component must accept only authorised target and profile jobs, preserve customer scope, report job health, return supported findings and evidence, support cancellation and avoid direct exposure through public web request handlers. Guardian provides the customer and provider workflow. The execution technology can evolve without changing the public Katana product, provided target governance, evidence quality, finding continuity and entitlement remain intact. Custom integrations and profiles are assessed for authentication, target behaviour, safety, secrets handling, supportability, expected coverage and commercial effort before activation.

EV

Data, evidence and reporting

Assessment evidence supports developer action without exposing credentials or unsafe execution detail. Guardian retains target, profile, job, timestamps, finding identity, severity, affected function, approved evidence, action and rescan history. Credentials, raw requests, secrets and unrestricted scanner payloads remain restricted. A rescan result records what the approved assessment could observe after remediation. Complex business-logic, design or environmental questions may still require manual validation. Reports distinguish scheduled coverage, execution failures, findings, rescans and unresolved actions so a failed job is not represented as a clean assessment.

CM

Commercial unit and responsibilities

Commercial scope is based on approved targets, profiles, cadence and rescan entitlement. The proposal identifies websites and APIs, environments, profiles, authentication, automatic cadence, on-demand allowance, cooldown, rescan quantity, evidence, retention, customer users and support. Katana is not included merely because Guardian Core monitors a website. It is a separately entitled active-testing product. Manual penetration testing, code review and engineering remain separate unless expressly included. The customer provides target authority, representative access and remediation ownership. Damocles provides the controlled assessment and follow-up activities listed in the product schedule.

Frequently asked questions

Questions buyers ask about Guardian Katana Website and API Security Testing.

The exact answer is confirmed in the proposal and package schedule, but these points should be understood before activation.

Q1

How is Katana different from Core website monitoring?

Katana adds deeper active profiles, authenticated and API testing, additional cadence, evidence and rescan entitlement.

Q2

Does Katana replace penetration testing?

No. It provides repeatable active assessment, while manual testing remains necessary for deeper attack paths, business logic and expert validation.

Q3

Can it use test accounts?

Yes where authenticated profiles, credential handling and target authority are approved.

Q4

Can an MSP operate customer assessments?

Yes through explicit provider relationships, customer target ownership and product entitlements.

Q5

What happens when a job fails?

Guardian shows the failed, timed-out or cancelled state and does not represent it as a zero-finding assessment.

Q6

How many rescans are included?

The package schedule defines included and rolling rescan allowances, expiry and any additional commercial unit.

Scope and boundaries

Katana executes only against explicitly authorised targets and approved profiles.

The product does not authorise arbitrary scanning, destructive testing, denial-of-service activity, unrestricted credential use or assessment of third-party systems.

Katana does not guarantee discovery of every application or API weakness and does not replace secure development, manual testing or remediation engineering.

Target limits, cadence, credentials, profiles, exclusions, cooldowns, evidence and rescans remain entitlement controlled.

Take the next practical step

Identify the websites, APIs and authenticated workflows that need deeper repeatable testing.

We will define target authority, profiles, credentials, cadence, rescans, finding review and the Guardian remediation workflow.