PTaaS LiteUnderstand PTaaS Lite

Understand PTaaS Lite

Learn how PTaaS Lite gives you self-serve, AI-validated penetration testing for your web application, and how it differs from PTaaS Pro.

Who can use this feature

Available as an add-on. Contact your CSM to learn more.

PTaaS Lite is Scrut's self-serve penetration testing-as-a-service for web applications. You add your target, run scans yourself, and manage every finding end to end, while Scrut's AI agents confirm each vulnerability before you see it and check each fix you submit.

What Is PTaaS Lite?

PTaaS Lite gives you continuous, AI-validated penetration testing for one web application. In PTaaS Pro, Scrut's Security Experts (SEs) run your testing program, review findings, and verify fixes. In PTaaS Lite, you run the program yourself, and two AI agents take on the review work:

  • The AI Validation agent re-attempts to exploit every suspected vulnerability after a scan and tags each one as Likely TP (true positive) or Likely FP (false positive).
  • The AI Verification agent re-attacks a finding after you submit a fix and decides whether the fix held.

You stay the final decision maker. The agents label and verify findings, but you decide how to act on each one.

Who PTaaS Lite Is For

PTaaS Lite is built for two roles in your team:

  • Security and compliance owners, who review the findings queue and decide how to handle each finding.
  • Engineering owners, who fix vulnerabilities and submit findings for verification.

How PTaaS Lite Works

  1. Add your target. Add one web application and, optionally, share code, API specifications, and supporting documents so the scan better understands your application.
  2. Run a scan. Trigger a scan from your target. You can run one scan every 30 days.
  3. Let the AI validate findings. When discovery completes, the AI Validation agent tries to exploit each suspected vulnerability. Findings appear in your Findings list only after validation completes, each with a validation tag.
  4. Fix and submit for verification. Fix the vulnerability in your application, then submit the finding for verification.
  5. Let the AI verify your fix. The AI Verification agent re-attacks every open affected resource. If the fix holds on all of them, the finding is closed. If any resource is still exploitable, the finding is reopened.

Validation Tags

Every published finding carries one of two validation tags:

Validation tagWhat it means
Likely TP (True Positive)The agent successfully exploited the vulnerability, so it is very likely real.
Likely FP (False Positive)The agent could not exploit the vulnerability; it might be a false positive.

Heads Up! A Likely FP tag is the AI's assessment, not a final decision. Likely FP findings are published with Open status and stay fully actionable, so review them the same way you review Likely TP findings.

PTaaS Lite vs. PTaaS Pro

AreaPTaaS LitePTaaS Pro
Who runs the programYouScrut's Security Experts
Review before findings are publishedAI Validation agentSecurity Expert review
Fix verificationAI Verification agent, starts when you submitSecurity Expert, within the verification SLA
Who triggers scansYouScrut, according to your Program Calendar
Scan frequencyOne scan every 30 daysRelease Scans and Full Pentests per your Program Calendar
TargetsOne web applicationSet by your contract
Program CalendarNot includedIncluded
Manual expert pentestNot includedIncluded

Finding Statuses

PTaaS Lite uses the same finding statuses as PTaaS Pro:

StatusWhat it means
OpenThe finding is published and needs your action. All newly published findings start here, regardless of their validation tag.
Pending VerificationYou submitted the finding for verification, and the AI Verification agent is re-attacking it.
ClosedThe AI Verification agent confirmed the fix on every affected resource.
ReopenedAt least one affected resource is still exploitable after verification.
IgnoredYou chose not to act on the finding.
Risk AcceptedYou formally accepted the risk, and a linked risk was created in the Risk Register.

Important: You can't close a finding manually in PTaaS Lite. A finding is closed only when the AI Verification agent confirms the fix.

If Scanning Is Paused for Your Workspace

If your workspace is no longer enabled for PTaaS Lite, Scrut pauses new scans only. Your targets and findings stay in your account, and you can still act on findings, including submitting them for verification, ignoring them, adding risks, and exporting reports. Contact your CSM to resume scanning.

FAQs

Contact support@scrut.io or your CSM for further assistance.