Optional Guardian add-on

Go beyond baseline website monitoring with Katana.

Katana provides deeper active website and API security testing for approved targets, with scheduled or on-demand assessments, customer-safe findings, evidence, rescans and remediation workflows through Guardian.

Clear package boundary

Guardian Core monitors website vulnerability; Katana adds deeper active testing.

Customers do not need Katana to receive the approved baseline website vulnerability monitoring included in Guardian Core.

Katana is selected when the organisation needs active assessment orchestration, authenticated or custom assessment profiles, more frequent testing, included rescans or deeper website and API evidence.

01

Authorise

Confirm the approved website or API targets, assessment intent, credentials and safety boundaries.

02

Assess

Run scheduled or on-demand Katana assessments subject to entitlement, cadence and cooldown controls.

03

Remediate

Connect findings, evidence, rescans and high-priority actions to the Guardian remediation workflow.

Katana add-on capabilities

Active website and API security testing with governed evidence.

AT

Approved targets

Website and API targets remain explicitly authorised and tenant scoped.

SP

Assessment profiles

Approved standard, authenticated or custom assessment profiles define how testing is performed.

SC

Scheduled and on-demand testing

Assessment cadence, manual-scan cooldowns and target limits are entitlement controlled.

NF

Normalised findings

Customers receive customer-safe findings and evidence rather than raw scanner output.

RS

Rescans

Included rescans and rolling rescan allowances support remediation verification.

AC

High-priority action linkage

High and critical findings can be connected to Guardian risks, owners and All Actions.

Commercial basis

Katana is separately entitled and scoped.

Commercial terms are based on approved websites and APIs, assessment cadence, assessment profiles, manual-scan cooldowns, included rescans and rolling rescan allowances.

Credentials, raw requests and raw scanner payloads are not exposed publicly. Availability depends on the approved deployment and service configuration.

Manual penetration testing is a separately scoped professional engagement unless it is expressly included in the applicable proposal.

Deeper active testing

Define the approved targets, cadence and assessment depth.

We will distinguish the baseline website vulnerability monitoring included in Guardian Core from the additional active testing delivered through Katana.