What the product does
Target limits, cadence, profiles, manual-test cooldowns and rescan allowances are confirmed in the package schedule.
Katana coordinates authorised active website and API assessment, authenticated or custom profiles, customer-readable findings, evidence, actions and rescans through Guardian.
Guardian for Australian customers is built, operated and hosted in Australia. All Guardian customer and platform data, including backups and recovery copies, is maintained and stored within Australia.
Guardian retains target, profile, job, timestamps, finding identity, severity, affected function, approved evidence, action and rescan history. Credentials, raw requests, secrets and unrestricted scanner payloads remain restricted.
The proposal identifies websites and APIs, environments, profiles, authentication, automatic cadence, on-demand allowance, cooldown, rescan quantity, evidence, retention, customer users and support.
The product does not authorise arbitrary scanning, destructive testing, denial-of-service activity, unrestricted credential use or assessment of third-party systems.
Target limits, cadence, profiles, manual-test cooldowns and rescan allowances are confirmed in the package schedule.
The customer experience remains consistent even where the approved execution component changes.
Manual penetration testing and secure code review remain separate where deeper human-led validation is required.
Modern applications expose APIs, roles, multi-tenant data, business processes and authenticated functions that require a deeper and more controlled assessment profile. The customer also needs evidence a developer can use and a reliable way to review the fix.
Katana adds active assessment beyond Guardian Core monitoring. It manages targets, profiles, schedules, controlled execution, findings, evidence, action linkage and rescans while preserving explicit customer authority and entitlement.
Use the approved website, API, authentication and profile rather than a generic public-only check.
Present affected scope, reproduction context, severity and remediation guidance without publishing unsafe raw payloads.
Use included or approved rescans and Guardian evidence to review whether the material issue is resolved.
Target limits, cadence, profiles, manual-test cooldowns and rescan allowances are confirmed in the package schedule.
Maintain explicit customer ownership, URLs, API endpoints, environment, contacts and safety boundaries.
Use approved public, authenticated, API or custom profiles according to the application and test objective.
Run assessment jobs within entitlement, cadence, cooldown and safe-execution policy.
Convert supported results into consistent severity, status, affected scope and remediation context.
Retain approved customer and developer evidence while restricting credentials and unsafe raw detail.
Use included or approved rescans to review remediation and reopen findings where necessary.
The customer experience remains consistent even where the approved execution component changes.
Approved target, profile, latest assessment, next schedule, entitlement and execution state.
Severity, affected website or API, lifecycle state, first and last observation and remediation owner.
Customer-readable description, impact, evidence, affected function and practical remediation guidance.
Link material findings to Guardian risks and All Actions with owners and due dates.
Record whether the issue is resolved, reduced, still present, reopened or requires manual review.
Authorised customer target, assessment, finding, action and rescan views with explicit scope.
Manual penetration testing and secure code review remain separate where deeper human-led validation is required.
Confirm customer ownership, environment, contacts, credentials, exclusions and permitted assessment behaviour.
Select or prepare the approved public, authenticated, API or custom assessment profile.
Monitor queued, running, completed, failed, timed-out and cancelled assessment jobs.
Review supported results, target scope, duplicates, evidence and customer-safe presentation.
Coordinate high-priority actions, developer questions, evidence and rescan readiness.
Report target coverage, findings, action state, rescans and current entitlement through Guardian.
Katana is selected when the customer needs more depth or frequency than the Guardian Core baseline.
Assess approved internet-facing application behaviour beyond the baseline monitoring profile.
Use approved test accounts and roles to assess protected functions and customer workflows.
Assess supported endpoints, authentication, object access, input handling and workflow behaviour.
Schedule approved assessments around regular application change and remediation cycles.
Operate authorised customer targets, profiles, findings and rescans within provider entitlements.
Use Katana to identify areas requiring deeper manual testing or to maintain awareness after an engagement.
These details remain explicit before activation, but are grouped into one operating view so buyers can review the responsibilities without working through four separate page sections.
Onboarding requires target authority, application context and safe credential handling. The customer provides target ownership, environment, application contacts, technology context, expected functions, test accounts, roles, API documentation where available, exclusions, maintenance windows and incident contacts. Credentials are handled through approved operational controls and are not exposed publicly. A profile-validation run confirms authentication, target behaviour, test depth, rate and safety controls, expected coverage, false-positive handling and evidence quality before recurring schedules are enabled. Go-live records target and profile entitlement, cadence, on-demand cooldown, rescan allowance, notification, finding review, developer handover, support and the boundary to manual penetration testing.
Katana is the Damocles product; controlled assessment components remain behind the execution boundary. The execution component must accept only authorised target and profile jobs, preserve customer scope, report job health, return supported findings and evidence, support cancellation and avoid direct exposure through public web request handlers. Guardian provides the customer and provider workflow. The execution technology can evolve without changing the public Katana product, provided target governance, evidence quality, finding continuity and entitlement remain intact. Custom integrations and profiles are assessed for authentication, target behaviour, safety, secrets handling, supportability, expected coverage and commercial effort before activation.
Assessment evidence supports developer action without exposing credentials or unsafe execution detail. Guardian retains target, profile, job, timestamps, finding identity, severity, affected function, approved evidence, action and rescan history. Credentials, raw requests, secrets and unrestricted scanner payloads remain restricted. A rescan result records what the approved assessment could observe after remediation. Complex business-logic, design or environmental questions may still require manual validation. Reports distinguish scheduled coverage, execution failures, findings, rescans and unresolved actions so a failed job is not represented as a clean assessment.
Commercial scope is based on approved targets, profiles, cadence and rescan entitlement. The proposal identifies websites and APIs, environments, profiles, authentication, automatic cadence, on-demand allowance, cooldown, rescan quantity, evidence, retention, customer users and support. Katana is not included merely because Guardian Core monitors a website. It is a separately entitled active-testing product. Manual penetration testing, code review and engineering remain separate unless expressly included. The customer provides target authority, representative access and remediation ownership. Damocles provides the controlled assessment and follow-up activities listed in the product schedule.
The exact answer is confirmed in the proposal and package schedule, but these points should be understood before activation.
Katana adds deeper active profiles, authenticated and API testing, additional cadence, evidence and rescan entitlement.
No. It provides repeatable active assessment, while manual testing remains necessary for deeper attack paths, business logic and expert validation.
Yes where authenticated profiles, credential handling and target authority are approved.
Yes through explicit provider relationships, customer target ownership and product entitlements.
Guardian shows the failed, timed-out or cancelled state and does not represent it as a zero-finding assessment.
The package schedule defines included and rolling rescan allowances, expiry and any additional commercial unit.
We will define target authority, profiles, credentials, cadence, rescans, finding review and the Guardian remediation workflow.