- Your position
- Your engineers pull the cloud trail and application logs for the window in question and find traffic they cannot attribute. Nobody should accept a security finding on trust, least of all one produced by automation.
- The identifier
- Every validation request we send carries an identifier that lands in your own logs. You do not have to take our word for what we did — you can search for it, in your systems, without asking us for anything.
- The reconstruction
- Matched against the per-probe history, a challenged finding reconstructs exactly: which request, at what time, against which asset, under which authorisation. Handing you the means to audit the tester is the point — a validation programme you cannot audit is one you are obliged to trust.