One harness for the whole engagement. Nothing is called proven until an independent check reproduces it.
Describe the objective in a sentence and choose the scope. Only your approval can extend either.
Short-lived agents run real commands in a disposable container or microVM, pivoting on what they find.
Candidates go to an independent validator, as many as the run’s validation budget allows. The report separates what it proved from what it could not, and what it never got to.
Nothing is confirmed until a separate validator reproduces it from its own evidence.
Example output. Identifiers are illustrative.
Every action passes the same check. It can ask for less. It can never grant itself more.
Scope and budgets are set when you create the run, and only you can widen either. Credentials it finds are reused inside that boundary, never past it.
Work happens in a disposable container or microVM with no host access, reaching only what the scope you chose allows. It is destroyed afterwards.
Privilege escalation, lateral movement and anything destructive stay off until approved — one at a time, or up front if you choose automatic mode.
Every outside call is opt-in — a hosted model, a remote sandbox, OSINT and search lookups. Run it all yourself and the only traffic leaving is the assessment, to the target you authorized.
OrcaCyber is in private testing. Tell us a little and we’ll be in touch.
Teams with a company email are reviewed first.
One email when your invite is ready. Nothing else.
We’ve saved .