Method / Six steps

From authorized scope to evidence.

RedDepth is a human-supervised, multi-agent testing workflow. The sequence is intentionally ordered: authorization and mapping come before testing, independent validation comes before confirmation, and a fresh coverage audit challenges the meaning of “done.”

A controlled path, in order.

  1. Authorize the scopeThe human supervisor defines assets, identities, methods, exclusions, rate limits, and stability constraints. Ambiguous ownership stops the work.
  2. Map the surfaceSpecialized agents turn the written scope into an inventory of endpoints, parameters, roles, identities, workflows, and state transitions.
  3. Test systematicallyTesting agents vary method, identity, encoding, and state across the surfaces the scope allows, recording raw requests, responses, and tool output.
  4. Independently validate candidatesA separate agent receives the evidence and attempts a blind reproduction before a candidate can be treated as confirmed.
  5. Audit coverageA fresh pass challenges what remains untested. It may propose more work, but it cannot mark the work complete.
  6. Deliver evidence-linked resultsThe supervisor receives a draft report whose claims link back to the affected asset, reproduction path, evidence, impact, remediation direction, and limitations.

Where the workflow fits.

Web and API

Endpoints and parameters

Map and test web applications and APIs across the authorized request surface, including the state carried between workflow steps.

Identity

Roles and boundaries

Challenge cross-identity and cross-role behavior where the written scope and available credentials allow it.

Business logic

Workflows and state

Look beyond signatures at the conditions that emerge when a method, identity, value, or workflow state changes.

Network and host

Authorized infrastructure

Include network- or host-level surfaces when they are explicitly part of the scope and the engagement is authorized for them.

A methodology is stronger when its limits are visible.

RedDepth requires an engaged human supervisor and does not run unattended today. It currently covers web, API, network, identity and authorization, and business-logic surfaces. Mobile applications and cloud-configuration review are not currently included.

The workflow does not promise zero false positives, complete coverage, or a finished deliverable without human review. It provides a way to make the work, the evidence, and the remaining uncertainty easier to inspect.

Every Pilot starts with one authorized target and a scope agreed up front. Sensitive access details move through a private channel, never the public application form.