Skip to content
REDMAW

Platform

Enterprise governance and controls

Run controlled offensive security with explicit authorization, scope enforcement, approval gates, enterprise identity controls, audit logging and deployment options built for sensitive environments.

The governance layer needs to be as deliberate as the attack engine.

Authorization

Authorization before execution

Controlled offensive security starts with permission. RedMaw requires explicit scope and ownership verification before active testing can run, and distinguishes customer-owned targets from systems that are merely visible from the internet or connected through a third party.

Authorization is treated as a technical control, not a note in a project plan. The testing engine operates inside boundaries the customer has deliberately defined.

  • Ownership verification for active targets
  • Explicit authorized scope
  • Clear customer responsibility for permitted testing
  • Evidence of what was approved and tested

Scope

Scope is an enforcement boundary

RedMaw separates what the platform can discover from what it is allowed to attack. Allowlists, target scope and test mode define where active techniques may run, so a system can be observed for posture without becoming an exploitation target.

That distinction matters in production, where nearby third-party infrastructure, shared SaaS services or sensitive systems may be visible but are not part of the authorized engagement.

  • Allowlists and target boundaries
  • Active versus posture modes
  • Controlled test behavior
  • Auditability of scope changes

Approval

Higher-impact actions require more control

Some adversarial actions carry more operational consequence than others. RedMaw supports approval gates so higher-impact steps require deliberate authorization before execution.

The purpose is to preserve the value of real validation without treating production systems as a playground. Approval history stays part of the audit trail, giving security teams a record of which actions were automated, which required human approval, and what was executed.

  • Approval gates
  • Explicit authorization for sensitive actions
  • Recorded approval history
  • Reproducible session evidence

Identity and audit

Enterprise identity and audit controls

RedMaw integrates with enterprise identity and access-management practice through SSO, SCIM and RBAC. Audit logging records administrative and testing activity, so customers can see who changed scope, who approved an action and how the platform was used.

These controls matter precisely because the product has offensive capability.

  • SSO
  • SCIM
  • RBAC
  • Audit logging
  • Administrative traceability

Isolation

Isolation, hosting and data control

RedMaw supports tenant isolation and managed dedicated hosting for organizations that need stronger separation. Regional hosting and customer-controlled key options support more demanding governance requirements, while the secure outbound connector provides controlled reach into customer environments without requiring inbound firewall exposure.

  • Tenant isolation
  • Dedicated hosted environments
  • Regional hosting options
  • Customer-controlled key options
  • Secure outbound connectivity

Not generally available

In-tenant sovereign deployment is not generally available today. It remains a future option under discussion and should not be planned around as a current capability.

Why governance comes first

A platform that attacks production systems has to be governable, and a buyer evaluating one is right to ask how. These are the controls that make controlled exploitation defensible rather than merely impressive.

Stop assuming you are secure. Prove it.

Continuously test what an attacker can actually reach across your applications, SaaS identities, internal infrastructure and AI systems.