How long does a scan take?
Initial triage arrives in under 60 seconds. A deeper automated scan typically takes 3–8 minutes, depending on scope and authentication flows. Human verification follows; its timing depends on the finding.
Who verifies the findings?
The agent captures evidence, then a security engineer reproduces the finding and checks its impact before delivery. Initial triage is not the same as a human-verified report.
What is included in the free trial?
14 days of the Pro feature set, with no card required. This includes unlimited projects, full scan depth, and daily re-runs.
Will testing disrupt my app?
Production-safe mode uses read-only probes by default. Destructive testing requires explicit opt-in. Set your testing scope before starting a scan.
Do I need security expertise?
Each finding includes impact, captured evidence, and fix guidance you can use in Claude Code or Cursor. Review and test any suggested change before deploying it.
Is a smoke test the same as a pentest?
No. A smoke test checks your deployed app for security gaps. A scoped pentest adds an agreed engagement scope, authenticated multi-role testing, and a signed report. The two services have different scope and pricing.
Can I share the results?
You can export PDF reports with scan timestamps. For a customer or auditor requiring a signed assessment, use a scoped pentest engagement.