Know PTaaS Lite Scope & Coverage
See what PTaaS Lite covers, including target and scan limits, scan context uploads, and what's included only in PTaaS Pro.
Who can use this feature
Available as an add-on. Contact your CSM to learn more.
PTaaS Lite covers one web application with AI-driven scanning, validation, and fix verification. Knowing what's included, and what isn't, helps you plan your testing and set the right expectations with your team.
What's Included
| Area | PTaaS Lite coverage |
|---|---|
| Target type | Web App only |
| Number of targets | One web application |
| Scans | One scan every 30 days, triggered by you |
| Finding validation | Every suspected finding is re-exploited by the AI Validation agent before it is published |
| Fix verification | The AI Verification agent re-attacks your fix each time you submit a finding for verification |
| Scan context | Optional code archive, API specification, and supporting document uploads |
| Finding actions | Submit For Verification, Ignore, Undo Ignore, Add Risk, comments, filters, and export |
What's Not Included
- Manual penetration testing by Scrut's Security Experts.
- Security Expert review of findings or fixes.
- The PTaaS Program Calendar, Release Scans, and scheduled Full Pentests.
- Scans triggered or managed by Scrut on your behalf.
Target Limit
One web app for each tenant.
Scan Allowance
You can run one scan per target every 30 days. A scan counts toward your allowance only when it completes. If a scan fails, it doesn't use your allowance, and you can run it again.
Note: Verification runs that start when you submit a finding for verification don't count toward your scan allowance.
Scan Context
When you add or edit your target, you can share three types of context with the scan. Each is optional, and each field accepts up to 10 items.
- Code repository: Upload a code archive (ZIP file) of your application.
- API specification: Upload an OpenAPI or Swagger file, or add its URL, so the scan tests every documented endpoint.
- Supporting documents: Upload documents that explain how your application is built, deployed, or accessed.
Pro Tip!The more context the scan has, the deeper and more targeted the testing. Uploading an API specification is the quickest way to improve endpoint coverage.
How Findings Are Scoped
Each finding can include one or more affected resources, such as a specific URL, endpoint, or parameter. The AI agents validate and verify each resource separately, and the finding shows the worst state across its resources. For example, if one resource is still exploitable after verification, the whole finding is reopened.
Findings Carried Over from PTaaS
If your workspace moves from PTaaS Pro to PTaaS Lite, findings you already acted on keep their status and history. This includes findings that are Risk Accepted, Ignored, Reopened, Pending Verification, or have a ticket created. Findings that are still Open start a new SLA.
FAQs
Contact support@scrut.io or your CSM for further assistance.