- What is tested
- Eleven coverage classes, from web and mobile applications through to Active Directory, source code and AI applications. Physical security, hardware and wireless testing sit outside all three models.
- How it is tested
- Six phases — discovery, planning, scanning, exploitation, reporting, and a QA gate that sits after reporting and can send the finished report back to the phase that produced it.
- What a finding carries
- A reproducible exploit artefact: the request, the response and the steps to reproduce it. That holds in every model, including the one with nobody in the loop.