SSofTest
Internal security testing

See a system from every angle — in one pass.

SofTest points eight scanning engines at the systems you're authorized to test — surface, runtime, code, dependencies, git history and capacity — and has Claude turn what they find into a single report your team can act on.

Your own organization in a minute · by Teknoniaga · softest.teknoniaga.com

How deeply have we looked?

A blind spot is not a clean result.

Each engine answers a question the others can't. Together they read a system top to bottom — so "nothing found" means examined, not skipped.

Surface
nmap
What is even exposed? Open ports and the services listening behind them.
sends traffic
Surface
nuclei
Does anything exposed have a known flaw? Community templates for known CVEs and misconfiguration.
sends traffic
Runtime
strix
Can it be broken into while it's running? An AI agent actively probes the live system.
actively attacks
Code
semgrep
Is the code we wrote unsafe? Injection, unsafe APIs and risky patterns across languages.
reads source
Code
bandit
Any Python-specific security bugs? AST-aware checks: shell=True, unsafe yaml, weak crypto, secrets.
reads source
Supply
trivy
Are the parts we pulled in vulnerable? Known CVEs, leaked secrets and misconfig in dependencies and images.
reads deps
History
gitleaks
Did we ever commit a credential? Secrets committed once and later deleted — invisible to a working-tree scan.
reads history
Capacity
loadtest · k6
Does it hold up under traffic? Latency and error-rate under load, stress, spike or soak.
sends traffic
Your team

Three roles, one console

Everyone reads the findings. Who can point an engine at a system is gated.

admin

Runs the platform. Approves targets, manages the team, resets passwords, sets report branding.

pentester

Runs the work. Registers targets and starts scans, on top of everything a viewer sees.

viewer

Reads the results. Every finding and every report — but can't start a scan.

Reports

Written to hand over

After each scan, findings become one report — grouped by severity, with fixes proposed, never applied.

Claude

Triaged automatically. The summary, severity grouping and fix diffs are generated after every scan.

PDF · DOCX

Either format, on demand. Choose the sections and a severity floor — a one-page summary or the full detail.

Branding

Per-client identity. Your logo, colour, footer and classification banner on the cover.

Team-wide

Everyone can read. A viewer exists precisely to read results they didn't run.

Plans

Start free. Pay when it earns its keep.

A 14-day trial with no card, then a plan sized to how much you test. Every plan includes the report Claude writes from what the engines find.

!

Only test what you're authorized to test.

nmap, nuclei, Strix and load testing send real traffic at a real system. Scanning something you don't own — or don't have written permission to test — is not a grey area. Every target is registered with an authorization reference and approved by an admin before a single engine can touch it, and load is capped server-side. The gate is the platform's whole reason to exist.

Ready when you are

Create your organization and run your first scan.

Register a target, prove it's yours, pick how deep to look, and read the report. Already have a sign-in? Use it — everyone your admin adds joins the same organization.