The map of security testing, and where Squall stands on it.

Squall is at phase 0. Here is what it covers today, how it compares with every other way of testing, what it runs on, and what each phase adds.

Eight things to test, four ways to test them.

Every security service on the market fills some of these cells. Green is Squall today. Dashed is a later Squall phase. Grey names who else does that work.

Squall todaySquall, partlyLater Squall phaseOther providers

Industry terms in small type, for readers who want to map each cell to the products they know.

The whole picture first.

Security is six jobs, as set out in the NIST Cybersecurity Framework 2.0, the most widely used map of the field. Squall does one of them well, checks part of another, and leaves the rest to you or other providers. Knowing which is which is the point.

Govern Identify Protect Detect Respond Recover Squall coverage today
IdentifyKnow what you have and where it is weak. Squall's core job: finding weaknesses in your app, code and site.
Core
ProtectPut the safeguards in. Squall checks some of them are set right: settings, stored keys, third-party parts. It does not install them.
Checks part
DetectNotice an attack while it happens. Testing whether your alarms fire is on the roadmap.
Roadmap
GovernDecide who owns the risk, set policy, report to the board.
Yours
RespondAct when something goes wrong: contain, investigate, tell people.
Not Squall
RecoverGet back to normal: backups, restore, lessons learned.
Not Squall

The other lenses on this page sit inside this map: the attacker's playbook and the testing types all belong to Identify, Protect and Detect.

Think of your app as a building.

Squall is the inspector who walks round before opening day. It checks the locks, the windows and the keys left under the mat, and hands you a written list with a photo of each problem it finds. It is not a hired burglar who tries to break in and walk out with the safe.

Checked today On the roadmap Not what Squall does
1 2 3 4 5 6 7 8 9 10
1
The front door lockHow your sign-in page and its security settings are set up.
Checked
2
Keys under the matPasswords and access keys left in your code, including old versions of it.
Checked
3
The windowsWhat your website gives away, and the protections it asks browsers to apply.
Checked
4
Who you post things toEvery outside service your app sends data to, and anything nobody can explain.
Checked
5
The building suppliesThird-party parts in your app with publicly known defects.
Checked
6
The view from the streetEverything the internet can see of your domain, not only the app.
Roadmap
7
The AI receptionistWhether your chatbot can be tricked into leaking data or misbehaving.
Roadmap
8
The alarm systemWhether anyone would notice an attack while it is happening.
Roadmap
9
The staffPhishing emails, phone calls, tricking people. Squall never does this.
Never
10
An actual break-inGetting inside and going further, as a criminal would. That is a red team's job.
Not Squall

Where Squall sits among the options.

Companies test security in six broad ways, from a cheap scan to a regulator-led exercise. They differ in two things: how far the test goes, and how often it happens. Squall sits deliberately in one corner: it looks often and proves what it finds, and it does not try to break in.

Looks for openings Proves they are real Breaks in Acts like a criminal gang How far the test goes → Every night A few times a year Once a year or less How often it runs → Exposure programme (whole company, consultancy-run) Automated scanner Squall Penetration test Red team exercise

Automated scanner

Software that checks for known problems. Fast and cheap. Produces long lists with false alarms, and rarely says what it missed.

Goes: looks for openingsRuns: whenever you like

Runs itself

Squall

Automated checks plus a person who confirms each problem, with proof, a fix list, and a written list of what was not checked. Nightly if you want.

Goes: looks, then provesRuns: every release, or nightly

Built for small teams

Penetration test

A skilled tester tries to break in over days or weeks, chaining small problems into a real one. A snapshot, usually once or twice a year.

Goes: breaks inRuns: once or twice a year

Specialist firm

Red team exercise

A team plays a real criminal group for weeks: technology, people and sometimes physical entry. Tests whether your defenders notice.

Goes: acts like a criminal gangRuns: once a year or less

Consultancy, large budgets

Exposure programme (CTEM)

An ongoing programme across the whole organisation: find everything exposed, rank it, prove it, get it fixed. Needs your security team to run with it.

Goes: looks, proves, some testingRuns: continuously

Consultancy-run, enterprise

Regulator-led red team

Intelligence-led red teaming under a regulator's scheme, such as HKMA iCAST in Hong Kong, CBEST in the UK or TIBER-EU. Required for some banks and insurers.

Goes: acts like a named real-world threat groupRuns: on the regulator's cycle

Accredited providers only. Squall is not this and does not replace it.

One more product category, breach and attack simulation, replays known attacks against your defences on a schedule. It is closest to the alarm testing on Squall's roadmap.

Side by side.

Twelve plain questions, five approaches. The Squall column is today's reality; anything not yet built is marked as roadmap.

Yes Partly, or depends on the provider Squall roadmap No

Typical of each approach; individual providers vary. Squall answers reflect what runs today.

Against the attacker's playbook.

MITRE ATT&CK is the public catalogue of how real attackers operate, in fourteen stages from scouting a target to causing damage. Squall looks for the openings that make the early stages possible. It does not act out any stage itself; that is what a red team does.

Squall looks for the openings here Partly Roadmap Not covered
2 of 14stages where Squall looks for the openings today: getting in, and stolen keys.
3 of 14partly covered or on the roadmap: scouting, running code, and data leaving.
8 of 14stages a red team acts out that Squall does not, by design. One more, preparing tools, happens on the attacker's side.

Against an exposure-management programme.

Continuous Threat Exposure Management, or CTEM, is the five-step cycle large firms and consultancies use to run security as an ongoing programme. Here is how much of each step Squall covers for a single app.

Step 1

Scope

What matters, and what are we allowed to test?

Covered. A signed scope names every site and repository before anything runs.

Step 2

Discover

What is exposed?

Partly. Your app, its code and its live site. The wider internet view is on the roadmap.

Step 3

Prioritise

Which problems matter most?

Mostly. A person reviews the findings and ranks them into a fix list.

Step 4

Validate

Could an attacker really use it?

Partly. Proof is shown for each finding. Squall does not attempt the attack.

Step 5

Mobilise

Does it actually get fixed?

Partly. Nightly watch tells you when things change. A fixed, new, still-open view is being built.

A full programme covers the whole organisation and needs your team to run it. Squall covers these steps for one app at a time.

What is inside, openly.

Squall does not invent its own scanners. It curates proven open-source tools, runs them the right way inside a signed scope, and puts a person between the raw output and you. Here is every part, including the parts we built and the commercial services we rely on.

Open-source tools Squall runs today

Installed and run on our own machine. Your code is never uploaded to a scanning service.

Finds passwords and keys in your code historyTruffleHog, GitleaksAGPL-3.0, MIT
Finds third-party parts with known defectsOSV-ScannerApache-2.0
Reads your code for risky patternsSemgrep Community EditionLGPL-2.1
Uses your app like a person and records what it sends wherePlaywright (Chromium)Apache-2.0
Proves what a live session sends, when neededmitmproxyMIT
Checks your site's settings and the accounts that publish itcurl, GitHub CLI, provider APIsopen / read-only

Lined up for the roadmap

Selected, not yet in service.

The internet's view of your domainsubfinder, Nuclei, NmapMIT, MIT, NPSL
Testing AI chatbotsgarak, PyRITApache-2.0, MIT
Cloud account settingsProwlerApache-2.0
Alarm testingAtomic Red Team, CalderaMIT, Apache-2.0

What we built

Our own code. Not open source today.

  • The scope gateRefuses to run against anything not in your signed scope
  • The runnerRuns each tool the same way every time and keeps its raw output
  • The reportProof per finding, what passed, what was not checked
  • Change watchCompares each nightly run with the last and stays quiet when nothing changed
  • The run logOne record per run: who asked, under which scope, what happened

Commercial services we use

Named so you know where your data goes.

  • Anthropic ClaudeHelps the human reviewer read findings. The scanning itself uses no AI. You can opt out.
  • OktaSign-in to the results page
  • CloudflareSecure connection to the results page, and email
  • GitHubHosts our code and this site

The idea: take capabilities that already exist in the open, organise them so anyone shipping an app can use them without a security team, and be exact about what they cover. We run Squall on our own apps every night before we run it on anyone else's.

From phase 0 to phase 3.

Each phase lights up more of the map. A capability joins Squall only after it has run on our own apps. No dates are promised.

Phase 0

Now

  • Your app and its codeWeak spots, keys left in code, outside services, parts with known defects
  • A person reviews the findings
  • Ranked fixes with proof
  • Nightly re-checks, reports only on change

Phase 1

AI and the internet edge

  • AI chatbots and featuresCan it be tricked, can it leak
  • What your domain shows the internet
  • A one-page verdict and retest view
  • Newly exploited weaknesses matched to your app

Phase 2

Accounts and cloud

  • Cloud and publishing account settings
  • Findings matched to regulations

Phase 3

Your defences

  • Would your alarms fireTesting your monitoring against known attacks

Never part of Squall: testing your staff, break-ins, anything that could take your service down, regulator-required certification.

Want to see it on your app?

Tell us what you are shipping and when. We reply with the ownership step and a draft scope.

See how an attack unfolds. Technical reader? See the technical detail and the published method.