01Black-box and white-box

Point it at a URL.Or hand it the code too.

Black-box needs nothing but a reachable target. White-box adds the repository, so every finding points at the exact lines that cause it.

  • New pentest: target https://shop.acme.test (reachable), mode black-box, nothing to install.

    Black-box

    • Give Trident a URL. It maps routes and APIs.
    • Auth, IDOR, injection and business logic get exercised across real flows.
    • Point it at a URL. Nothing to install.
  • Pentest selected assets from Inventory: shop.acme.test and acme/payments-api (read-only) together, white-box. Findings point to src/routes/invoices.ts:41.

    White-box

    • Connect a repo alongside the live target, from Inventory.
    • Findings point at the file and line, with a fix to commit.

02How it reads your app

Your app, taken apartthe attacker's way.

Routes come from the spec and the crawl, inputs from parameters and bodies, auth from how access is actually checked. Candidates that don't reproduce are dropped, not reported.

openapi.yamlGETPOSTGETGETPOSTmembers.ts 1 2 3 4 5 6 7 8 910111213141516shop.acme.testSmall-batch gin,made slowly.PARSING THE ATTACK SURFACE …spec + crawl04/account/orders/api/orgs/:id/members/login/checkoutROUTESparams + bodies04idorgIdcouponfileINPUTShow access is checked02session cookieorg membership checkAUTHwhere data lands03orders querymembers queryfile writeSINKScandidate 1/3candidate 1/3 · droppedcandidate 2/3candidate 2/3 · reproducedcandidate 3/3candidate 3/3 · droppedclean sessionreplaying candidate 2/3IDOR on /api/orgs/:id/membersHigh · CVSS 8.2 · app.example.comReproduced · proof attached

03Validated by doing

Every candidate is replayedbefore it counts.

  • 01

    Candidates queue at the gate

    Each idea the agents try becomes a candidate, not a finding.

  • 02

    Only what reproduces passes

    Replayed from a clean session with a second account. If it reproduces, it is filed with the steps.

  • 03

    The rest is dropped

    What doesn't reproduce is dropped, not reported. No maybes in your queue.

04Proof attached

Every finding arriveswith the steps to reproduce it.

05Why it is different

Real exploits,not a wall of maybes.

The usual way: Quarterly pentests catch one point-in-time snapshot.
With Trident: Continuous testing runs against every change you ship.
The usual way: Scanners flag maybes you cannot reproduce.
With Trident: Findings stay validating until an exploit reproduces end to end.
The usual way: Reports are PDFs that age out on arrival.
With Trident: Each finding ships the exact request to replay, plus a PR.
The usual way: Business logic and IDOR slip past automated tools.
With Trident: Auth, access control and logic are exercised across real flows.
The usual way: Triage burns engineering time on guesswork.
With Trident: Engineers receive validated, reachable issues with reproducible evidence.

06What it tests

The bugs a scannercan't reach.

IDOR, privilege escalation and auth bypass across your endpoints, tested safely with guardrails. REST and GraphQL endpoints are mapped and replayed.

  • Broken access control
  • IDOR
  • Tenant isolation
  • Privilege escalation
  • Auth bypass
  • Business logic
  • Injection
  • REST endpoints
  • GraphQL endpoints

07Questions

Questions,answered.

No. A vulnerability scanner primarily identifies known conditions or signatures. A penetration test attempts to determine whether weaknesses can be combined or exploited under defined rules of engagement. Trident only files what it can reproduce.

The affected target, the exact steps that reproduce it, the observed impact, a CVSS score, remediation guidance and a retest result.

Not automatically. An auditor or customer may still require an independent assessment with defined dates and scope. Continuous testing improves coverage between those assessments.

New public routes, authentication or authorization changes, material API changes, and the remediation of a confirmed finding.

[08]GET STARTED+

Find it beforethey do.

Start a free trial. Your first verified findings land within a day of connecting.

  • SOC 2 audited by Sensiba LLP
  • Read-only cloud access