Platform
Enterprise governance and controls
Run controlled offensive security with explicit authorization, scope enforcement, approval gates, enterprise identity controls, audit logging and deployment options built for sensitive environments.
The governance layer needs to be as deliberate as the attack engine.
Authorization
Authorization before execution
Controlled offensive security starts with permission. RedMaw requires explicit scope and ownership verification before active testing can run, and distinguishes customer-owned targets from systems that are merely visible from the internet or connected through a third party.
Authorization is treated as a technical control, not a note in a project plan. The testing engine operates inside boundaries the customer has deliberately defined.
- Ownership verification for active targets
- Explicit authorized scope
- Clear customer responsibility for permitted testing
- Evidence of what was approved and tested
Scope
Scope is an enforcement boundary
RedMaw separates what the platform can discover from what it is allowed to attack. Allowlists, target scope and test mode define where active techniques may run, so a system can be observed for posture without becoming an exploitation target.
That distinction matters in production, where nearby third-party infrastructure, shared SaaS services or sensitive systems may be visible but are not part of the authorized engagement.
- Allowlists and target boundaries
- Active versus posture modes
- Controlled test behavior
- Auditability of scope changes
Approval
Higher-impact actions require more control
Some adversarial actions carry more operational consequence than others. RedMaw supports approval gates so higher-impact steps require deliberate authorization before execution.
The purpose is to preserve the value of real validation without treating production systems as a playground. Approval history stays part of the audit trail, giving security teams a record of which actions were automated, which required human approval, and what was executed.
- Approval gates
- Explicit authorization for sensitive actions
- Recorded approval history
- Reproducible session evidence
Identity and audit
Enterprise identity and audit controls
RedMaw integrates with enterprise identity and access-management practice through SSO, SCIM and RBAC. Audit logging records administrative and testing activity, so customers can see who changed scope, who approved an action and how the platform was used.
These controls matter precisely because the product has offensive capability.
- SSO
- SCIM
- RBAC
- Audit logging
- Administrative traceability
Isolation
Isolation, hosting and data control
RedMaw supports tenant isolation and managed dedicated hosting for organizations that need stronger separation. Regional hosting and customer-controlled key options support more demanding governance requirements, while the secure outbound connector provides controlled reach into customer environments without requiring inbound firewall exposure.
- Tenant isolation
- Dedicated hosted environments
- Regional hosting options
- Customer-controlled key options
- Secure outbound connectivity
Not generally available
In-tenant sovereign deployment is not generally available today. It remains a future option under discussion and should not be planned around as a current capability.
Why governance comes first
A platform that attacks production systems has to be governable, and a buyer evaluating one is right to ask how. These are the controls that make controlled exploitation defensible rather than merely impressive.
Stop assuming you are secure. Prove it.
Continuously test what an attacker can actually reach across your applications, SaaS identities, internal infrastructure and AI systems.