FAQ / The questions we actually get

Answers, including the unflattering ones.

How is this different from the scanner we already run?

A scanner reports pattern matches and leaves verification to you. GhostTrace confirms exploitability with non-destructive techniques and attaches the evidence, so a reported finding has already been demonstrated. Keep your scanner if you want checkbox breadth; the difference is what reaches your queue.

What happens to findings you cannot prove?

They stay in the artifacts rather than your queue. They are not reported as proven, and we do not pad a report with candidates to make the number look impressive. If we cannot demonstrate it, you do not get billed attention for it.

Can I reproduce a finding myself?

That is the point. Every proven finding ships a self-contained bundle: raw request, raw response, per-gate decisions and the authenticity verdict. Replay it and you should get the same result. If it does not reproduce on your side, you should not trust it, and we would want to know.

Is it safe to let this run against production?

Execution is bounded in code rather than policy: fail-closed scope enforcement, signed rules of engagement, dry-run preview, entitlement limits, capped spend and a complete audit ledger. Exploitability is confirmed non-destructively. See the trust center for the full list.

Do you test behind the login?

Yes, when credentials are provided for the engagement. SSO and a credential vault are rolling out.

Are you SOC 2 certified?

No. It is in progress and we will not claim otherwise. The engagement-level controls listed in the trust center are in effect today, and a DPA is available on request.

How much does it cost?

Pricing is not published yet. We are at design-partner stage and scoping engagements individually. The intent is an annual subscription priced by attack surface and cadence, positioned to replace both the scanner line and the periodic pentest line.

Who is actually building this?

Two founders: engineering and detection architecture led by a 30-year enterprise security engineer, and the AI reasoning layer architected by our CEO. Development is substantially AI-assisted under their direction, with a verification-heavy process. See about.