Every scan runs against an explicit allow-list of approved targets, so the only systems ever touched are ones somebody deliberately put in scope.
Scope is what separates security testing from something nobody authorised. A scanning tool pointed at the wrong host is a serious incident, so Argus Pentest does not accept an arbitrary address at scan time: a target has to be added to an allow-list first, as a deliberate act, and a scan can only reference something already on that list.
A target must be added to the allow-list before it can be scanned.
Scans reference approved targets rather than arbitrary addresses.
Scope is a configured, reviewable list rather than a runtime argument.
The role a target is scanned as is part of its configuration.
Discovery widens coverage of an approved target, never the target set.
No. A scan can only reference a target already on the approved allow-list, so putting a system in scope is always a separate, deliberate step.
The tool is built for testing your own applications. Adding a target is an assertion that you are authorised to test it.
A scripted login hands the scanner real session cookies and a bearer token.
Endpoints found while logging in and crawling become the spec the scanner works from.
The model generates payloads and triages results — text in, text out, never vision.
Credentials, scan traffic and reports all stay on your own infrastructure.
See the complete product: problem, features, how it works and deployment.
Request a demo to watch a scan log in to an approved target and work the surface behind the sign-in form.