Squall, technical detail

A review that shows its evidence and states what it could not check.

Who it is for

Small teams and solo builders shipping a web app, a bot or an AI feature without a security team of their own. You want an independent check before real users arrive, and you want to know exactly what that check covered.

Squall only reviews targets you own. Before anything runs, you prove control of the domain or repository and sign a written scope that names every target and what may be done to it.

How an engagement works

01

Prove ownership

Add a DNS TXT record we give you to the domain, or grant read access to the repository. Nothing runs until one of these is in place.

02

Sign the scope

A short written scope lists every hostname and repository, the checks permitted, and the dates. Anything outside it is refused before a tool starts.

03

Automated review

Squall runs the checks inside the scope, read-only and at human pace. Every step keeps its raw output so each finding can point at the line, header or host that proves it.

04

Human read

A person reads everything flagged and decides: confirmed, or cleared with a written reason. Scanner output never goes to you unread.

05

Report

The report is delivered to you privately. It is never published, and findings are never shared with anyone outside the engagement.

06

Nightly watch (optional)

The review re-runs each night on new commits. You hear from us only when the findings change.

What you receive from a run

Technical report

Every finding with its evidence, why it matters and how to fix it. A finding without proof is labelled unverified and says what proof is missing.

Available now

What passed, what was not covered

Each check that passed, stated. Each thing the review could not reach, named, with the reason.

Available now

Ranked fix list

Findings in severity order, each with the specific change that closes it.

Available now

One-page verdict

Ship, ship with fixes, or hold, with the three findings that decided it. Written for the person who signs off.

Partial: a short summary opens the report today; the standalone page is being built.

Retest comparison

On the next run: what was fixed, what is new, what is still open.

Partial: each run records whether findings changed since the last; the item-by-item comparison is being built.

What Squall can check today

Live means it runs on real targets now. Partial means part of it runs; the gap is stated. Planned means designed and not yet in service. Planned checks are not sold as part of a review.

CapabilityStatusWhat that meansAligns to
Application security reviewLiveSecrets in git history, dependency CVEs, static analysis, response headers and content security policy, the hosts your shipped bundle can talk to, what the app leaves in the browser. Runs per release and nightly.OWASP ASVS, OWASP Top 10
Vulnerability intelligencePartialA daily feed of new CVEs, known exploited vulnerabilities and exploit likelihood is live. Matching that feed against your own dependency list is planned; today dependency CVEs come from the application review.OWASP Top 10
Account and cloud posturePartialRead-only checks on the accounts that can publish your app: deploy-token expiry, repository visibility, branch protection. A full cloud account and host configuration review is planned.NIST SP 800-115
Reporting and evidencePartialTechnical report with evidence per finding and the passed and not-covered lists are live. The one-page verdict and a downloadable evidence bundle are planned.NIST SP 800-115
External attack surfacePlannedWhat the internet can see of your domain: subdomains, open ports, exposed services. Method written, not yet run on any target.NIST SP 800-115
AI and LLM testingPlannedWhether a bot or AI feature can be steered by planted instructions, made to leak data or pushed past its limits. Method written, tools not yet in service.OWASP Top 10 for LLM Applications
Standards and regulatory mappingPlannedFindings carry CWE and OWASP identifiers today. Mapping each finding to the regulatory clauses it touches is planned.OWASP ASVS
Detection validationPlannedWhether your monitoring would notice an attack in progress. Not built.NIST SP 800-115

Read how the application review runs, step by step, in the published method.

What it does not do

Squall is read-only. It recommends; it changes nothing in your code, your deployment or your accounts. Findings stay private to you and are never published.

Request a review

Tell us what you are shipping, the domain or repository, and when you plan to release. We reply with the ownership step and a draft scope.