Squall is at phase 0. Here is what it covers today, how it compares with every other way of testing, what it runs on, and what each phase adds.
Every security service on the market fills some of these cells. Green is Squall today. Dashed is a later Squall phase. Grey names who else does that work.
Industry terms in small type, for readers who want to map each cell to the products they know.
Security is six jobs, as set out in the NIST Cybersecurity Framework 2.0, the most widely used map of the field. Squall does one of them well, checks part of another, and leaves the rest to you or other providers. Knowing which is which is the point.
The other lenses on this page sit inside this map: the attacker's playbook and the testing types all belong to Identify, Protect and Detect.
Squall is the inspector who walks round before opening day. It checks the locks, the windows and the keys left under the mat, and hands you a written list with a photo of each problem it finds. It is not a hired burglar who tries to break in and walk out with the safe.
Companies test security in six broad ways, from a cheap scan to a regulator-led exercise. They differ in two things: how far the test goes, and how often it happens. Squall sits deliberately in one corner: it looks often and proves what it finds, and it does not try to break in.
Software that checks for known problems. Fast and cheap. Produces long lists with false alarms, and rarely says what it missed.
Goes: looks for openingsRuns: whenever you like
Runs itself
Automated checks plus a person who confirms each problem, with proof, a fix list, and a written list of what was not checked. Nightly if you want.
Goes: looks, then provesRuns: every release, or nightly
Built for small teams
A skilled tester tries to break in over days or weeks, chaining small problems into a real one. A snapshot, usually once or twice a year.
Goes: breaks inRuns: once or twice a year
Specialist firm
A team plays a real criminal group for weeks: technology, people and sometimes physical entry. Tests whether your defenders notice.
Goes: acts like a criminal gangRuns: once a year or less
Consultancy, large budgets
An ongoing programme across the whole organisation: find everything exposed, rank it, prove it, get it fixed. Needs your security team to run with it.
Goes: looks, proves, some testingRuns: continuously
Consultancy-run, enterprise
Intelligence-led red teaming under a regulator's scheme, such as HKMA iCAST in Hong Kong, CBEST in the UK or TIBER-EU. Required for some banks and insurers.
Goes: acts like a named real-world threat groupRuns: on the regulator's cycle
Accredited providers only. Squall is not this and does not replace it.
One more product category, breach and attack simulation, replays known attacks against your defences on a schedule. It is closest to the alarm testing on Squall's roadmap.
Twelve plain questions, five approaches. The Squall column is today's reality; anything not yet built is marked as roadmap.
Typical of each approach; individual providers vary. Squall answers reflect what runs today.
MITRE ATT&CK is the public catalogue of how real attackers operate, in fourteen stages from scouting a target to causing damage. Squall looks for the openings that make the early stages possible. It does not act out any stage itself; that is what a red team does.
Continuous Threat Exposure Management, or CTEM, is the five-step cycle large firms and consultancies use to run security as an ongoing programme. Here is how much of each step Squall covers for a single app.
What matters, and what are we allowed to test?
Covered. A signed scope names every site and repository before anything runs.
What is exposed?
Partly. Your app, its code and its live site. The wider internet view is on the roadmap.
Which problems matter most?
Mostly. A person reviews the findings and ranks them into a fix list.
Could an attacker really use it?
Partly. Proof is shown for each finding. Squall does not attempt the attack.
Does it actually get fixed?
Partly. Nightly watch tells you when things change. A fixed, new, still-open view is being built.
A full programme covers the whole organisation and needs your team to run it. Squall covers these steps for one app at a time.
Squall does not invent its own scanners. It curates proven open-source tools, runs them the right way inside a signed scope, and puts a person between the raw output and you. Here is every part, including the parts we built and the commercial services we rely on.
Installed and run on our own machine. Your code is never uploaded to a scanning service.
Selected, not yet in service.
Our own code. Not open source today.
Named so you know where your data goes.
The idea: take capabilities that already exist in the open, organise them so anyone shipping an app can use them without a security team, and be exact about what they cover. We run Squall on our own apps every night before we run it on anyone else's.
Each phase lights up more of the map. A capability joins Squall only after it has run on our own apps. No dates are promised.
Now
AI and the internet edge
Accounts and cloud
Your defences
Never part of Squall: testing your staff, break-ins, anything that could take your service down, regulator-required certification.
Tell us what you are shipping and when. We reply with the ownership step and a draft scope.
See how an attack unfolds. Technical reader? See the technical detail and the published method.