Understand PTaaS Lite
Learn how PTaaS Lite gives you self-serve, AI-validated penetration testing for your web application, and how it differs from PTaaS Pro.
Who can use this feature
Available as an add-on. Contact your CSM to learn more.
PTaaS Lite is Scrut's self-serve penetration testing-as-a-service for web applications. You add your target, run scans yourself, and manage every finding end to end, while Scrut's AI agents confirm each vulnerability before you see it and check each fix you submit.
What Is PTaaS Lite?
PTaaS Lite gives you continuous, AI-validated penetration testing for one web application. In PTaaS Pro, Scrut's Security Experts (SEs) run your testing program, review findings, and verify fixes. In PTaaS Lite, you run the program yourself, and two AI agents take on the review work:
- The AI Validation agent re-attempts to exploit every suspected vulnerability after a scan and tags each one as Likely TP (true positive) or Likely FP (false positive).
- The AI Verification agent re-attacks a finding after you submit a fix and decides whether the fix held.
You stay the final decision maker. The agents label and verify findings, but you decide how to act on each one.
Who PTaaS Lite Is For
PTaaS Lite is built for two roles in your team:
- Security and compliance owners, who review the findings queue and decide how to handle each finding.
- Engineering owners, who fix vulnerabilities and submit findings for verification.
How PTaaS Lite Works
- Add your target. Add one web application and, optionally, share code, API specifications, and supporting documents so the scan better understands your application.
- Run a scan. Trigger a scan from your target. You can run one scan every 30 days.
- Let the AI validate findings. When discovery completes, the AI Validation agent tries to exploit each suspected vulnerability. Findings appear in your Findings list only after validation completes, each with a validation tag.
- Fix and submit for verification. Fix the vulnerability in your application, then submit the finding for verification.
- Let the AI verify your fix. The AI Verification agent re-attacks every open affected resource. If the fix holds on all of them, the finding is closed. If any resource is still exploitable, the finding is reopened.
Validation Tags
Every published finding carries one of two validation tags:
| Validation tag | What it means |
|---|---|
| Likely TP (True Positive) | The agent successfully exploited the vulnerability, so it is very likely real. |
| Likely FP (False Positive) | The agent could not exploit the vulnerability; it might be a false positive. |
Heads Up! A Likely FP tag is the AI's assessment, not a final decision. Likely FP findings are published with Open status and stay fully actionable, so review them the same way you review Likely TP findings.
PTaaS Lite vs. PTaaS Pro
| Area | PTaaS Lite | PTaaS Pro |
|---|---|---|
| Who runs the program | You | Scrut's Security Experts |
| Review before findings are published | AI Validation agent | Security Expert review |
| Fix verification | AI Verification agent, starts when you submit | Security Expert, within the verification SLA |
| Who triggers scans | You | Scrut, according to your Program Calendar |
| Scan frequency | One scan every 30 days | Release Scans and Full Pentests per your Program Calendar |
| Targets | One web application | Set by your contract |
| Program Calendar | Not included | Included |
| Manual expert pentest | Not included | Included |
Finding Statuses
PTaaS Lite uses the same finding statuses as PTaaS Pro:
| Status | What it means |
|---|---|
| Open | The finding is published and needs your action. All newly published findings start here, regardless of their validation tag. |
| Pending Verification | You submitted the finding for verification, and the AI Verification agent is re-attacking it. |
| Closed | The AI Verification agent confirmed the fix on every affected resource. |
| Reopened | At least one affected resource is still exploitable after verification. |
| Ignored | You chose not to act on the finding. |
| Risk Accepted | You formally accepted the risk, and a linked risk was created in the Risk Register. |
Important: You can't close a finding manually in PTaaS Lite. A finding is closed only when the AI Verification agent confirms the fix.
If Scanning Is Paused for Your Workspace
If your workspace is no longer enabled for PTaaS Lite, Scrut pauses new scans only. Your targets and findings stay in your account, and you can still act on findings, including submitting them for verification, ignoring them, adding risks, and exporting reports. Contact your CSM to resume scanning.
FAQs
Contact support@scrut.io or your CSM for further assistance.