FAQ
Understand the OutScope coverage workflow.
Is OutScope an EASM or vulnerability scanner?
No. OutScope is focused on DAST Coverage Management. It validates known application endpoints from external and internal perspectives, determines DAST analyzability, and helps orchestrate the decisions and workflows required to improve DAST coverage.
What does DAST analyzability mean?
It means the observed endpoint appears technically suitable—or unsuitable—for a DAST workflow, with a recorded reason. It is not a vulnerability or a security verdict.
Why use both external and internal probes?
They provide different network perspectives. An internal worker can validate endpoints that are not reachable from an Internet-based probe.
How does OutScope connect with DAST workflows?
Controlled pipelines turn reachability and analyzability evidence into coverage decisions such as onboard, review, or exclude. Purpose-built integrations can connect those decisions with the appropriate downstream DAST workflow.
What evidence is collected?
DNS A/AAAA, TCP on configured ports, HTTP/HTTPS responses, redirects, selected headers and response metadata, TLS certificate data, and analyzability classification.
Can I try it without a sales process?
The current commercial motion is demo and pilot led. Existing users can sign in; new teams can request a focused evaluation.