Authorized penetration testing with explicit scope and evidence
ASL Authorized Security Testing is the active-testing service associated with the Scan platform. It is never started from a URL alone. The engagement requires a signed scope, exact targets, approved techniques, a time window and an emergency contact before testing begins.
What the product helps an organization do
Capability descriptions are public and meaningful; private implementation details, credentials and customer topology remain protected.
Authorize exactly what may be tested
The rules of engagement are part of the control system, not paperwork added after the fact.
Included capability
- Named asset owner and tester
- Exact domains, addresses, applications or devices
- Allowed and prohibited techniques
- Stop conditions and real-time contact path
Collect reviewable evidence
Testing focuses on reproducible observations and protects customer data from unnecessary collection.
Included capability
- Timestamped test activity and findings
- Impact explained without sensational language
- Evidence sized to prove the issue
- No expansion beyond the signed boundary
Verify remediation
The engagement can continue through repair guidance and a focused retest so closure means more than a status change.
Included capability
- Prioritized remediation plan
- Fix verification against the original condition
- Residual-risk and limitation record
- Client-ready completion summary
Readiness is part of the product description
We distinguish an implemented capability from a provider, compliance or acceptance gate that remains open.
Explicit rules and emergency stop path
Evidence and remediation tracking
Active testing never implied by a business audit
A practical buying path
Start with a bounded assessment, prove the workflow with representative data, then expand only after acceptance evidence is clear.
- 01
Readiness assessment
Confirm users, workflow, data, integrations, risks and success measures.
- 02
Configured pilot
Use representative or synthetic data to test the highest-value journey and operating boundaries.
- 03
Supported deployment
Complete acceptance, training, recovery and support before expanding usage.
Common questions
Can you test a website I do not own?
No. Testing requires written authorization from the responsible asset owner or another legally authorized party.
Does a business audit authorize penetration testing?
No. Active testing requires a separate explicit approval and scope.
Will the report include sensitive exploit details publicly?
No. Detailed evidence is handled within the authorized customer engagement, not published as marketing content.
Product readiness varies. Security, financial, legal, health and public-service software assists authorized people and does not replace professional judgment, legal obligations or client-specific acceptance.