Keep the WAF on
Test through Azure Front Door, AWS WAF, Cloudflare, Akamai, and custom edge policies using customer-approved access rules.
Enterprise agentic pentesting
Your applications do not live in a lab. Casco works through the firewalls, WAFs, SSO, MFA, tenant boundaries, and conditional access policies your teams already enforce.
EDGEApproved traffic profile recognized
PASSAUTHMFA challenge satisfied
PASSAGENTCross-tenant risk under validation
RUNNINGSecurity controls stay on
A pentest that requires you to turn off the controls protecting production is not testing production. Casco adapts to the access pattern your security team approves and keeps every request attributable.
Test through Azure Front Door, AWS WAF, Cloudflare, Akamai, and custom edge policies using customer-approved access rules.
Use stable source IPs, scoped allowlists, and request IDs so your team can identify every Casco request without opening the perimeter.
Lock targets, accounts, roles, and prohibited actions before execution. Sensitive flows can stay in staging or require review.
Authenticated application testing
Casco supports CAPTCHA, MFA, SSO, and Microsoft Entra ID. Agents have dedicated identities with their own email inboxes, phone numbers, and TOTP devices. They complete login flows, preserve session state, switch between approved identities, and test the authorization boundaries behind them. This includes magic links, SMS one-time passwords, and TOTP challenges.
Dedicated inboxes and phone numbers also let agents exercise email workflows beyond login, including email-abuse scenarios within the approved testing scope.
Company-managed access
Connect your organization's identity provider so employees can access Casco using their existing company-managed accounts. We support Okta, Microsoft Entra ID, Google Workspace, Auth0, and other SAML or OpenID Connect providers.
Context when you want it
Start with the outside view, add internal context, or place a Casco security engineer in the review loop. The execution engine stays agentic in every mode.
Start with a target and approved test identities. Casco discovers routes, APIs, roles, and attack paths from the outside in.
TARGET + TEST IDENTITIESProvide API documentation, architecture context, source access, or additional roles. The agents still reason and adapt autonomously.
TARGET + CONTEXT + IDENTITIESCasco security engineers can review scope and findings before they reach your team. This is useful for sensitive systems and formal reporting.
AGENTS + SECURITY ENGINEERAutonomy with hard boundaries
Casco gives agents room to reason inside an explicit operating envelope. Scope, traffic identity, and prohibited actions are enforced as controls, not left to a prompt.
See network observabilityOut-of-scope targets are blocked by network policy before a request can reach them, outside the agent reasoning loop.
ENFORCED AT PROXYKnown source IPs and x-casco-request-id let your SOC verify origin, follow a finding through internal logs, and separate tests from real attacks.
EVERY REQUEST IDENTIFIEDDDoS, resource-exhaustion, and destructive actions stay excluded. Additional restrictions are recorded in the rules of engagement.
DESTRUCTIVE ACTIONS BLOCKEDPut a Casco security engineer on sensitive scope and finding review before results reach your team or formal reports are issued.
OPTIONAL REVIEW GATEAutonomous means autonomous
Casco was built by security and infrastructure leaders from AWS to scale adaptive testing without turning your engineers into the integration layer.