Inventory input
Known applications, domains, and endpoints enter the workflow.
OutScope validates whether known application endpoints are reachable externally or internally, determines their DAST analyzability, and helps AppSec teams govern what should happen next.
Built for AppSec, Product Security, DevSecOps, and security-testing teams.
Application inventory
Known apps & endpoints
Reachability
External + internal probes
DAST analyzability
Classification + evidence
Coverage decision
Onboard · Review · Exclude
DAST coverage
Measurable operating process
The coverage gap
CMDB records do not show whether endpoints work, where they are reachable, whether DAST can analyze them, or whether they have been handled consistently.
How OutScope works
Every stage produces the input for the next: probe execution, analysis, decision, orchestration, and measurable coverage.
Execution pipeline
Input → probe execution → analysis → decision → orchestration → coverage output
Known applications, domains, and endpoints enter the workflow.
External or internal workers collect reachability evidence.
OutScope evaluates endpoint type and DAST analyzability.
Candidates are marked for onboarding, review, or exclusion.
Pipelines preserve the decision and coordinate the next action.
History, analytics, runs, and reports make the process measurable.
External + internal visibility
External probes measure reachability from the Internet. Internal workers run from an organization-controlled environment. These observations are operational signals—not vulnerability conclusions.
Internet perspective
Corporate-network perspective
| External | Internal | Signal for AppSec |
|---|---|---|
| Reachable | Reachable | Internet-facing or broadly reachable |
| Not reachable | Reachable | Internal-only from measured perspectives |
| Reachable | Not reachable | External or environment-specific reachability |
| Not reachable | Not reachable | Inactive, restricted, or requiring review |
DAST analyzability
OutScope records a classification, confidence, and reason from the observed response: normal web application or API, authentication barrier, blocked response, unavailable service, placeholder content, or review required.
Analyzability is technical suitability for DAST—not a vulnerability or security verdict.
DAST orchestration
Connect coverage decisions with your DAST workflow through controlled pipelines and purpose-built integrations, with an auditable path from validation to action.
Onboard · Review · Exclude
Coverage governance
Create an evidence trail across assets, checks, reachability, analyzability, reviews, pipeline execution, and reports.
API keys and Python SDK.
HTML, JSON, and PDF evidence.
Status and analyzability views.
Companies, assets, and history.
A clearer DAST program starts with evidence
Bring a representative slice of your application inventory and evaluate the workflow with your AppSec team.