xRiskSby NullVector
Secure control plane

Sign in

Authenticate to an authorized organization workspace.

Control plane ready

Operations Dashboard

Monitor authorized engagements, execution, evidence, and worker health.

Start an engagement

Follow these steps in order. Each test runs from a worker that matches the engagement location.

  1. 1Create the engagementClick New Engagement, select test type, external or internal execution, and the authorization dates.
  2. 2Add scope and authorizeIn the engagement table, click the shield button. Add each exact host, scheme, and port, then click Authorize.
  3. 3Connect the matching workerExternal engagement: use an external worker. Internal engagement: install a worker inside that network.
  4. 4Run the testOpen AI Execution, choose a provider and authorized engagement, enter the objective, then review the proposed actions.
Active Engagements
0

No active engagements

Running Sessions
0

No active execution

Findings
0

No validated findings

Critical Findings
0

No critical exposure

Authorized operations

Engagement Workspace

Graph-derived priorities

Top Threat Exposures

    No validated exposuresEvidence-backed attack paths will appear here.
    Live audit stream

    Recent Activity

      No recorded activityWorkspace actions will be recorded here.
      Execution fleet

      Worker Status

      A worker is required for every target-facing test. Use an external worker on an internet-connected node for public assets, or an internal worker inside the customer network for private assets. The control plane never scans a target directly.

      No workers enrolledVerified worker identities will appear here.

      Plan a test with an LLM

      Checking integrations

      Choose an authorized engagement, provider, approval method, and objective. Planning uses the engagement attack graph, tenant semantic memory, and—when enabled—current public web research with retained clickable sources.

      No execution runsCreate a constrained plan from authorized targets and typed operations.
      Configurable specialist coordination

      Agent Team

      Configure the coordinator and specialist roles used for evidence-aware planning. Each run snapshots this configuration. Autonomous runs require fresh administrator verification and remain bounded by the selected engagement scope, approved adapter classes, action cap, and replan cap.

      No specialist team configuredCreate the coordination, research, recon, validation, assessment, and reporting team.
      Isolated tool runtime

      Disposable Workspaces

      No disposable workspacesLaunch a time-bounded xRiskS-owned Kali workspace for an authorized engagement.
      Tenant-isolated asset relationships

      Attack Graph

      0 nodes0 relationships

      CPE, CVE, CWE, CAPEC, and ATT&CK correlation will appear as evidence-backed paths.

      No graph evidenceSigned worker evidence will project assets and relationships here.
      xRiskS capability catalog

      Tool Catalog

      0 tools
      Signed worker protocol v5

      Immutable Automation Adapters

      0 adapters

      These schema-specific adapters produce domain-separated worker signatures, normalized evidence, and graph projector receipts. The broader catalog remains available through audited, no-shell argument-vector workspaces.

      Centralized secret management

      Integrations & API Keys

      Configure every external API dependency here. Credentials are sealed by the root-owned xRiskS vault, are never returned to the control plane or browser, and require a fresh authenticator code to create, verify, or disable.

      No organization integrationsAdd an LLM or intelligence connector. The deployment-managed system provider remains available when configured.
      Verified and organization-authored content

      Knowledge Library

      Search the integrity-verified built-in library and your tenant-isolated articles. Organization articles are hashed and every change is audited.

      Signed worker learning

      Proposals awaiting review

      Workers can propose reusable knowledge only from evidence they produced. Reviewers must approve a proposal before it becomes an organization article.

      Tenant access

      Organization Team

      Membership unavailableOrganization administrators can manage tenant access.
      New engagement

      Create engagement

      Create a server-backed engagement. Scope and authorization remain separate enforced gates.

      Authorization boundary

      Manage scope

      Add an exact HTTP endpoint while the engagement is draft, then explicitly authorize it.

      Assessment plan

      Curated from the integrity-verified NullVector knowledge pack for this testing type.

      Outbound execution node

      Enroll worker

      Every target-facing test requires a worker. Choose external for public internet targets or internal for targets reachable only inside the customer network. Enrollment tokens expire after 15 minutes.

      Policy-enforced sandbox

      Create disposable workspace

      Choose offline analysis or a live full-tool workspace. Live workspaces remain non-root, read-only, capability-free, time-bounded, and can reach only the engagement's resolved authorized host and port entries.

      Audited sandbox execution

      Run a catalog tool

      Select any standalone executable from the signed 255-item catalog. xRiskS resolves the executable server-side, accepts arguments only, records the artifact, and enforces the workspace's engagement-bound network policy.

      No command has been executed.
      Tenant membership

      Invite team member

      Create a 24-hour single-use invitation bound to an exact email and role.

      Existing account

      Accept invitation

      The invitation email must match your authenticated account.

      Platform administration

      Create organization

      Create an isolated tenant and your initial organization administrator membership.

      Signed execution receipt

      Evidence

      
                
                
                
                
                
                
      Current public intelligence

      Run web research

      
      	          
      Live shared agent state

      Execution activity timeline

      Connecting to the tenant-isolated durable event stream…

      connecting
      xRiskS knowledge pack v1

      Testing knowledge

      Search integrity-verified components, guides, operations, tools, and validation methods. Knowledge never bypasses authorization or typed worker policy.

      Select an item

      Search and select a knowledge item to review its controlled procedure.
      Vault-sealed organization credential

      Add integration

      Select a reviewed connector with a fixed provider endpoint. The API key is sent once to the local vault and is never returned.

      Organization agent configuration

      Create specialist team

      Start from the tenant default and tune each specialist without changing its governed role or capability boundary.

      VersionNew
      SourceTenant default seed
      Config SHA-256Created on save
      Manifest SHA-256Inherited from seed

      Roles, capability profiles, participation modes, and delegation paths are policy-locked. Names, instructions, prompt templates, enablement, and iteration limits remain editable.

      Governed specialist roster

      Role configuration

      0 roles
      Destructive configuration change

      Reset this team?

      This creates a new version from the seeded default. Existing execution snapshots and version history remain unchanged.

      Fresh verification required

      Confirm with your authenticator

      Enter the current six-digit authenticator code to continue this credential administration action. Recovery codes are not accepted.

      Tenant-isolated knowledge

      New knowledge article

      Articles are stored only in the selected organization, hashed for integrity, and covered by the audit trail. They never expand execution scope or bypass approval.