The finding is the transcript
Nothing is recorded without the requests and identities that proved it.
Autonomous agents map every domain you own and prove what is exploitable, inside the scope, rate limits and permissions your team sets. Findings go to your engineers' coding agent over MCP with the exploit as the specification, and replay re-runs it to confirm the fix held.
An inventory tells you how many hosts you have. A graph tells you what happens when one of them falls: which hosts share an origin, which names point at providers that no longer claim them, and where a finding sits relative to everything around it.
Define exactly which hosts agents may reach, what they are allowed to do when they get there, and how hard they are allowed to push. The runtime enforces it and records every denial.
5 requests per second, per host
3 agents working in parallel
No traffic between 09:00 and 18:00
Granted agents may send POST, PUT and PATCH against this target. Every request it makes is written to the audit log.
A report tells you what was wrong in the week it was written. It cannot tell you whether the fix worked. Replay can.
Nothing is recorded without the requests and identities that proved it.
The exploit chain is the specification, so the patch is written against evidence rather than a description.
The original exploit runs again against the changed system and returns a dated verdict.
Who tightened a policy, who took a host out of scope, who accepted a risk, who exported evidence and who changed somebody's role. Not a login history with everything interesting missing from it.
Point agents at your surface with the scope, limits and permissions your team sets, and find out what is reachable before somebody else does.