Who are you?
Are login and session controls exposing weaknesses?
Authentication & session testingApplication security, made visible
Your application is more than what’s on screen. Aegis discovers the pages, APIs, and inputs behind it—and tests them for security vulnerabilities.
Discover the surface. Understand the risk. Know what to fix.
01 / The unseen application
Behind every screen are services exchanging data, users with different permissions, and inputs that change how things work. Together, these entry points form your attack surface.
What’s underneath
A page can look perfectly normal while the API behind it exposes something it shouldn’t.
You can’t test an entry point
you haven’t discovered.
02 / Security, without the jargon
Dynamic Application
Security Testing.
In plain English: testing an application while it’s running, from the outside. No source code required.
Aegis interacts with pages, APIs, and inputs to look for behavior that could let someone access data or functionality they shouldn’t.
How it differs from code scanningLike checking the doors and windows of a building—not just reviewing its blueprints.
An analogy, not a guarantee of complete coverage. Automated testing complements code review and expert assessment.
03 / First, discover
Start with an application you’re authorized to test. Aegis follows links, explores browser interactions, reads API definitions, and collects the inputs it discovers.
Because a test can only reach what discovery and configuration make available.
Aegis combines passive discovery, HTML and JavaScript extraction, browser crawling, and API imports. Actual coverage depends on scope, configuration, and application behavior.
Look beyond links.
Discover routes in HTML,
JavaScript, and browser traffic.
Bring your API definitions.
Import OpenAPI /
Swagger and Postman collections.
Keep the scope intentional.
Configure
boundaries, limits, and exclusions.
04 / Then, understand
Finding an endpoint tells you where to look. Its method, inputs, authentication context, and observed behavior help determine what to test. Select a node to look beneath the URL.
Illustrative application relationships—not a claim that Aegis automatically infers your business model.
Aegis records endpoint and parameter information, fingerprints technologies, and uses configured authentication and active access-control probes. Understanding is built from these signals—not assumed.
05 / Test in context
Security testing checks whether the application behaves as intended when requests change. Aegis combines dedicated testing engines with configurable detection templates.
Are login and session controls exposing weaknesses?
Authentication & session testingCan a request reach a resource without the required permission?
Authorization & object-level accessCan an input alter a query, execute a script, or change server behavior?
Input handling & injection testing06 / A small change. A real weakness.
Imagine a customer viewing their order. The application knows they’re signed in. But does it check that the order actually belongs to them?
Fictional example. A successful HTTP status alone does not prove an access-control vulnerability; ownership and response evidence need validation.
The technical issue
The application returns a resource without checking whether the user is allowed to access it.
The security consequence
A signed-in user may be able to see another customer’s information.
The business exposure
Depending on the data exposed, this could lead to incident costs, regulatory obligations, and lost trust.
07 / Follow the consequence
The question isn’t just “what’s vulnerable?”
A weakness matters in context. Follow this example from an ordinary customer session to a resource that should be out of reach.
An educational attack path, not a live exploit or a claim of automatic business-impact analysis.
A vulnerability is not just a technical issue.
The resource at the end of the path determines what’s at stake: customer information, account access, financial records, or operational continuity. Your team adds that business context when prioritizing a finding.
08 / The technical view
Plain-English capabilities first.
The engineering details,
one level deeper.
Coverage depends on enabled engines, templates, credentials, scope, and what the application exposes. No automated scanner finds every vulnerability.
HTML link and form extraction, JavaScript endpoint extraction, and headless Chromium crawling help discover server-rendered applications and client-side routes.
HTML · JavaScript · browser traffic · forms · route discovery
Import OpenAPI / Swagger definitions and Postman collections. Test discovered HTTP endpoints and their inputs. GraphQL support includes schema-driven input discovery and dedicated security checks where the schema is available.
REST · OpenAPI · Postman · GraphQL
Discovery of a protocol does not imply full security testing of it. This site does not claim active gRPC or WebSocket security coverage.
Configure form or JSON login, bearer tokens, cookies, headers, and API keys. When active authorization testing is enabled, Aegis checks anonymous access to discovered resources and selected header, method, and content-type bypass scenarios.
Login · sessions · JWT checks · anonymous replay · access-control probes
IDOR and BOLA describe object-level access-control weaknesses. General cross-user and cross-role comparison is not promised; those scenarios need additional manual assessment. Mutating probes require explicit opt-in.
Dedicated engines test SQL, NoSQL, command, and LDAP injection, along with cross-site scripting. Templates extend testing to additional weaknesses such as server-side request forgery and server-side template injection.
Query parameters · forms · headers · JSON bodies · path inputs
Evidence varies by check: response comparisons, timing behavior, browser execution, or out-of-band callbacks when configured.
Technology fingerprints, security-header checks, exposed-file templates, and sensitive-information checks help identify configuration issues and potentially exposed components.
A technology-to-CVE match is a lead for investigation—not proof that the application is exploitable.
09 / From discovery to action
A useful finding connects a weakness to an affected endpoint and the evidence behind it. Give security and development teams a shared starting point for investigation and remediation.
Discovered endpoints, inputs, and technology information.
Severity, affected requests, and check-specific evidence where captured.
Descriptions and guidance where available, alongside finding triage.
Run scans after changes and compare findings. Confirm results in the same authentication and scope context.
GET /api/orders/{id}
10 / A practice, not a one-time scan
Use Aegis against a running, authorized test environment. Review findings, make changes, and run testing again as your application evolves.
Find routes, APIs, and inputs within scope.
Collect endpoint, technology, and identity context.
Run configured security checks.
Validate and prioritize findings with your team.
Rescan after remediation and compare results.
Automate with the CLI and REST API, use schedules for recurring scans, and receive configured webhook events. A rescan is not by itself proof that a weakness is fixed.
11 / One picture. A shared purpose.
Security becomes more useful when everyone can connect the technical finding to the decision they need to make.
For leadership
Turn an abstract security concern into a concrete conversation: what is reachable, what could be exposed, and what your team should investigate next.
Discuss your applicationWhy Aegis
Route→Input→Context→Test→Evidence
Aegis brings discovery, technology signals, configured identities, and security testing into one workflow. The point isn’t to send more requests. It’s to make testing—and the findings it produces—more useful.
12 / The practical questions
How testing runs, where data lives, and how results reach your team are part of the decision. Here’s what the implementation supports—and what needs a conversation.
The repository supports a Go binary with an embedded web interface, Docker deployment, and Kubernetes manifests. The web platform uses PostgreSQL.
Confirm with product: commercially available hosting models, managed regions, and support terms.
Provide test identities through form or JSON login, or configure tokens, cookies, headers, and API keys. Agree on the accounts, roles, and flows for your application.
Target login support is not a claim of platform SSO or universal identity-provider compatibility.
The CLI, REST API, recurring schedules, and signed webhooks provide automation points. The CLI’s severity-based failure threshold can be used in a CI job.
Schedules and webhooks are plan-dependent. No native Jira, Slack, or CI-provider connector is promised here.
Review and triage findings, compare scans, and export JSON, SARIF, CSV, HTML, or PDF from the platform. Command-line reports also support Markdown and text.
HTML/PDF platform reports are plan-dependent. Evidence varies by check; PDF rendering requires Chromium. Confirm your required artifact in a demo.
Security & privacy
Scan evidence can include request and response content—and sensitive data returned by the target. Use dedicated test accounts and agree on scope, storage, access, retention, and any external testing callbacks before scanning.
Read the Privacy Policy for what we collect, why, and your rights over it.
Two items in that policy are still open, not finalized: which region hosts your data, and a published subprocessor list. Both will be filled in once decided. No certification or compliance claim (SOC 2, ISO 27001, PCI DSS, HIPAA) is made on this site.
A complementary perspective
Different approaches answer different questions. Aegis adds a view of application behavior to your existing security practice—it doesn’t replace every other tool or expert.
SAST
Static Application Security Testing examines source code for potential weaknesses without needing the application to run.
DAST / Aegis
Discover and test a running application from the outside. Observe how it responds to requests, inputs, and configured identities.
Expert assessment
Penetration testers bring human judgment, business-logic analysis, and deeper investigation that automated testing cannot replace.
A few good questions
New to application security?
You’re in the right place.
Dynamic Application Security Testing checks a running application from the outside. It sends requests and examines responses to look for security weaknesses in pages, APIs, and inputs. Aegis combines discovery with this testing.
Code scanning and running-application testing see different things. DAST can observe deployed configuration, request handling, and behavior under a particular identity. Use it alongside SAST, code review, and expert testing—not instead of them.
Yes. Aegis discovers HTTP API endpoints and supports OpenAPI / Swagger and Postman imports. It also has GraphQL discovery and testing. Coverage depends on available definitions, reachable endpoints, configured authentication, and enabled checks.
Yes. Target authentication supports form and JSON login, tokens, cookies, headers, and API keys. Supply a dedicated test account and verify the session works for your application. Active authorization probes include authenticated-versus-anonymous comparisons; general multi-account or cross-role testing is not promised.
Implemented checks include injection weaknesses, cross-site scripting, authentication and authorization issues, GraphQL security checks, and exposed information or configuration. Some use dedicated engines and others use templates. Explore the capability details for context and limitations.
No. Automated discovery and testing help with repeatable coverage, but expert assessment is still important for business-logic abuse, complex workflows, and validating impact. A finding is a starting point for judgment—not a substitute for it.
The codebase includes binary, Docker, and Kubernetes deployment options. The web platform requires PostgreSQL. Commercial deployment availability, managed hosting regions, and service commitments need product confirmation.
Active tests send requests that may change data, trigger workflows, or affect performance. Start in a representative non-production environment. Agree on authorization, scope, exclusions, accounts, request limits, and monitoring before considering production. Safety controls reduce risk; they do not make scanning risk-free.
Duration depends on application size, response times, authentication, enabled checks, browser exploration, and scan limits. We do not publish a universal scan-time promise. Evaluate a representative application with the configuration you intend to use.
Use the CLI or API to initiate testing, schedules for recurring scans, and configured webhooks for events. Review and triage findings, make changes, then rescan and compare. Dedicated connectors should be confirmed rather than assumed.
Security engineers and DevSecOps teams use it to discover and test applications. Developers use findings to investigate fixes. Technology and business leaders use the resulting visibility to ask better questions about exposure and priorities.
Your application. A clearer picture.
Discover your attack surface. Understand your exposure.
Give
your team a clearer path from finding to fix.
Start with a 14-day free trial. Full product access, no payment method required. Explore discovery, authenticated testing, and evidence on your own application before you commit to a plan.
Visit the existing Aegis access portal