
Updated
Introducing 0cloud
Managed security testing starts with a clear scope, a real target, and evidence an engineer can check.
A product keeps changing after its penetration test ends. New endpoints appear, permissions change, and an integration gives an old feature access to new data. The report still describes the version that was tested.
0cloud is our managed service for testing that changing attack surface. It uses the public 0sec engine, with the scope and engagement agreed directly with our team.
Start with the question the test should answer
A useful engagement starts with a concrete concern. Can one customer read another customer’s records? Can an integration perform an action its owner wasn’t allowed to authorize? Does a file upload reach a parser with more privileges than it needs?
Those questions determine the accounts, environments, source access, and boundaries the test requires. They also define what a successful demonstration would look like. A generic list of suspicious endpoints isn’t an answer.
The service is available by arrangement. We agree on the target, permitted actions, timing, and evidence needed before testing begins. For systems with sensitive data or availability constraints, those details belong in the scope from the start.
A finding should be usable
An engineer receiving a report needs to know where the behavior occurs, what an attacker must already control, and how to reproduce it. The report should distinguish an observed failure from a plausible consequence that hasn’t been demonstrated.
A crash, for example, establishes different things from a successful cross-account read. A source review can identify a missing check without establishing that an unauthenticated user can reach it. Keeping those distinctions visible makes remediation easier to prioritize.
Verification is part of our research workflow. Its strength depends on what ran and what it observed. A second agent agreeing with the first is useful review, but execution evidence and a clear security boundary carry the claim.
The engine and the managed service
The public 0sec engine provides the research tooling. 0cloud adds the managed engagement around it: agreeing on scope, operating the work, and discussing the results with the team responsible for the target.
A benchmark can help us evaluate the engine. It doesn’t establish the coverage of a particular customer application, and it doesn’t replace a scoped test of that application.
If there’s a part of your product you want tested, tell us what it is. A useful first message includes the system, the concern, and the environment available for testing. We can use that to decide what a meaningful engagement would require.
Updated September 2026 to reflect the current product structure and remove service guarantees that this introduction did not substantiate.