Skip to main content
Delivery model · Fully autonomous

Scope sign-off, then nothing

The last human action in this model is an authorisation. After it, B-52 discovers, plans, tests, exploits, reports and puts its own report through a QA gate that can send it back.

Security teams take this model to cover the estate in the months between deep engagements. They already run manual penetration tests, and the gap between them is what they are buying.

After the authorisation

Five things happen, and you are in exactly one of them

The sequence below is the whole engagement. Read step four carefully: it is the gate this model puts where a person would otherwise be reading.

Why the cross-check is a second gate and not the first

Every finding on every B-52 engagement arrives with a working exploit attached — the request that triggered it, what came back, and how to run it again. That is what makes a finding checkable by your own engineers, and it does not depend on the delivery model.

The cross-check is what this model adds because there is no auditor reading the output before you do. It runs after the exploit has already been produced, against the finding the exploit proved.

How the one-to-three-day figure was arrived at
  • It is a median observed across runs delivered in this model, not a target set in advance.
  • The measure runs from the moment scope is signed off to the moment the report is delivered.
  • A median describes the middle of those runs, so individual engagements land on either side of it.

Deliberately excluded

  • Everything before sign-off. Time spent agreeing what is in scope sits outside the measure, because the clock starts at the authorisation.

Where the run stops

Three actions wait for your written approval

Autonomy in this model means nobody at Security Brigade acts after sign-off. Three classes of action still stop and wait on you, in this model exactly as in the other two, and the run picks up again from where it paused.

Authorisation

The three gates, in the order they tend to come up

Production impact
Destructive or state-changing actions against a production system.
Beyond the entry host
Persistence, implants and lateral movement past the host B-52 first landed on.
Live data
Anything that touches live credentials or real customer data.

Persistence is the platform’s own work

Once persistence has been approved for a scope, B-52 establishes it. There is no handover to a human operator for that step, because the step is in the platform as well.

Everything above those three gates runs without asking. What sits at them waits until you have said yes in writing.

Before you scope one

The five questions this model gets asked

Common questions about the fully autonomous model, answered
What buyers ask about this modelThe answer
How long does it take? The observed median from scope sign-off to report delivery is one to three business days.
Who confirms a finding is real? The platform does. Every finding carries a reproducible exploit artefact, and in this model each one also passes an independent automated cross-check before it is reported.
Is anything left out of scope compared with the other models? No. All eleven coverage classes run here exactly as they run elsewhere. The delivery model changes where the human sits and nothing about what is looked at.
Can Security Brigade sign this for a regulated filing? No — there is no empanelled auditor in the engagement, and that involvement is what produces the signature. Take the expert-verified or human-led model where a filing is the destination.
Does anything still stop the run? Three actions do, and each of them waits on your written approval. They are set out in the band above.

Common questions about the fully autonomous model, answered

How long does it take?

The answer
The observed median from scope sign-off to report delivery is one to three business days.

Who confirms a finding is real?

The answer
The platform does. Every finding carries a reproducible exploit artefact, and in this model each one also passes an independent automated cross-check before it is reported.

Is anything left out of scope compared with the other models?

The answer
No. All eleven coverage classes run here exactly as they run elsewhere. The delivery model changes where the human sits and nothing about what is looked at.

Can Security Brigade sign this for a regulated filing?

The answer
No — there is no empanelled auditor in the engagement, and that involvement is what produces the signature. Take the expert-verified or human-led model where a filing is the destination.

Does anything still stop the run?

The answer
Three actions do, and each of them waits on your written approval. They are set out in the band above.

If an auditor has to be in it

Coverage is the same in all three. Move only if the destination of the report requires somebody at Security Brigade to have been in the engagement.

Compare all three models