PTaaS LitePTaaS Lite Scope & Coverage

Know PTaaS Lite Scope & Coverage

See what PTaaS Lite covers, including target and scan limits, scan context uploads, and what's included only in PTaaS Pro.

Who can use this feature

Available as an add-on. Contact your CSM to learn more.

PTaaS Lite covers one web application with AI-driven scanning, validation, and fix verification. Knowing what's included, and what isn't, helps you plan your testing and set the right expectations with your team.

What's Included

AreaPTaaS Lite coverage
Target typeWeb App only
Number of targetsOne web application
ScansOne scan every 30 days, triggered by you
Finding validationEvery suspected finding is re-exploited by the AI Validation agent before it is published
Fix verificationThe AI Verification agent re-attacks your fix each time you submit a finding for verification
Scan contextOptional code archive, API specification, and supporting document uploads
Finding actionsSubmit For Verification, Ignore, Undo Ignore, Add Risk, comments, filters, and export

What's Not Included

  • Manual penetration testing by Scrut's Security Experts.
  • Security Expert review of findings or fixes.
  • The PTaaS Program Calendar, Release Scans, and scheduled Full Pentests.
  • Scans triggered or managed by Scrut on your behalf.

Target Limit

One web app for each tenant.

Scan Allowance

You can run one scan per target every 30 days. A scan counts toward your allowance only when it completes. If a scan fails, it doesn't use your allowance, and you can run it again.

Note: Verification runs that start when you submit a finding for verification don't count toward your scan allowance.

Scan Context

When you add or edit your target, you can share three types of context with the scan. Each is optional, and each field accepts up to 10 items.

  • Code repository: Upload a code archive (ZIP file) of your application.
  • API specification: Upload an OpenAPI or Swagger file, or add its URL, so the scan tests every documented endpoint.
  • Supporting documents: Upload documents that explain how your application is built, deployed, or accessed.

Pro Tip!The more context the scan has, the deeper and more targeted the testing. Uploading an API specification is the quickest way to improve endpoint coverage.

How Findings Are Scoped

Each finding can include one or more affected resources, such as a specific URL, endpoint, or parameter. The AI agents validate and verify each resource separately, and the finding shows the worst state across its resources. For example, if one resource is still exploitable after verification, the whole finding is reopened.

Findings Carried Over from PTaaS

If your workspace moves from PTaaS Pro to PTaaS Lite, findings you already acted on keep their status and history. This includes findings that are Risk Accepted, Ignored, Reopened, Pending Verification, or have a ticket created. Findings that are still Open start a new SLA.

FAQs

Contact support@scrut.io or your CSM for further assistance.