Skip to content
REDMAW

Security & Trust

Offensive security should be controlled as rigorously as the systems it tests.

RedMaw is designed to validate real exposure without treating authorization, isolation or evidence integrity as secondary concerns.

A platform that attacks production has to be governable, or it should not run.

Authorization

Explicit authorization

RedMaw requires explicit authorization and ownership verification before active testing. The product distinguishes discoverable systems from systems that are approved for adversarial validation.

Scope is enforced through target controls and operating modes, so testing stays within the boundary the customer has defined.

Execution

Controlled execution

The platform supports allowlists, test modes and approval gates for higher-impact actions.

The purpose is to make adversarial validation useful in production without removing the controls a security team needs around sensitive activity.

Evidence

Evidence integrity

Validated findings can include reproducible evidence, session recording and replay, and signed tamper-evident artifacts where supported.

Evidence is tied to the finding state, so remediation and retest remain connected to the original validation rather than drifting into a separate report.

Access

Enterprise access controls

RedMaw supports SSO, SCIM, RBAC and audit logging.

Administrative and testing actions can be traced, so customers can see who changed scope, who approved activity and what the platform executed.

Isolation

Tenant isolation and connectivity

Customer data and evidence are isolated by tenant. Managed dedicated hosting and regional hosting options support organizations with stronger separation requirements.

A secure outbound connector can provide controlled connectivity into customer environments without requiring inbound ports.

Data

Data handling

RedMaw stores the operational data required to maintain assets, findings, engagements and evidence.

Sensitive evidence is handled as security data, and retained according to the customer's configured or contracted retention requirements.

Certification status

Not stated here yet

We are not stating RedMaw's own certification status yet. We would rather leave it blank than publish something we would have to revise.

If your evaluation depends on our certification position, ask us directly and you will get a straight answer rather than a badge.

Everything above describes controls in the product. Those are separate from any attestation about RedMaw as a company, and they do not change when that position changes.

Ask the hard questions before you authorize anything.

Bring your scope, authorization and governance requirements to the conversation.