diff --git a/README.md b/README.md index bca91782..0b2e6d29 100644 --- a/README.md +++ b/README.md @@ -244,7 +244,7 @@ See the [Shannon GitHub Action documentation](https://github.com/KeygraphHQ/shan See [keygraph.io/pricing](https://keygraph.io/pricing) for current prices and the full feature table. -**Pro**, **Enterprise**, and the **Community Program** run an enterprise-hardened fork of Shannon, and all three add: +**Pro**, **Enterprise**, and the **Community Program** are powered by an enhanced, enterprise-grade version of the Shannon engine, and all three add: - **Black-box pentesting**: tests the running application from the outside, with no source code needed. - **Dependency (SCA) and secret checks**: SCA with reachability, and secrets scanning that includes repository history. diff --git a/docs/keygraph-platform.md b/docs/keygraph-platform.md index a1b631a0..fccac953 100644 --- a/docs/keygraph-platform.md +++ b/docs/keygraph-platform.md @@ -2,7 +2,7 @@ Shannon 3.0 is an open-source pentester. It reads your source, maps routes and data flows, runs real attacks against a live target, and writes PDF and SARIF reports. It runs locally, in CI, or air-gapped with your own model. Shannon is a complete pentester, not a trial edition. -Pro and Enterprise are Keygraph's commercial editions. They run an enterprise-hardened fork of Shannon continuously across hundreds of repositories and add what a security team needs around it: black-box pentesting that needs no source code, audit-depth static analysis on a parsed code graph, SCA and secrets scanning, one deduplicated record per vulnerability across scans and scanners, fix pull requests, fix verification, two-way Jira sync, and SSO, RBAC, and audit logs. They are for security teams that own vulnerability management across many engineering teams and need one place to triage, assign, fix, and verify. +Pro and Enterprise are Keygraph's commercial editions. They are built on an enhanced, enterprise-grade version of the Shannon engine, run continuously across hundreds of repositories, and add what a security team needs around it: black-box pentesting that needs no source code, audit-depth static analysis on a parsed code graph, SCA and secrets scanning, one deduplicated record per vulnerability across scans and scanners, fix pull requests, fix verification, two-way Jira sync, and SSO, RBAC, and audit logs. They are for security teams that own vulnerability management across many engineering teams and need one place to triage, assign, fix, and verify. The Community Program is Pro at no cost for organizations that qualify. Every module is included in Pro, Enterprise, and the Community Program. They differ in price, eligibility, hosting, and support. Current prices and the full feature table are at [keygraph.io/pricing](https://keygraph.io/pricing). @@ -17,7 +17,7 @@ No source code? Use the [Blackbox Pentester](https://keygraph.io/agentic-blackbo | Price | Open source under AGPL-3.0. You pay only your own model costs | $0 in cloud service fees while you qualify. You pay only your own AI provider usage | $50 per active developer per month, every module included, no add-ons | Custom | | Best for | Developers and teams running repository-level pentests locally or in CI | U.S.-based 501(c)(3) nonprofits, and seed or pre-Series-A startups with 20 or fewer active developers | Teams that want every module, cloud-hosted and managed by Keygraph | Security organizations running continuous AppSec across many teams and repositories that need it inside their own environment | | Code analysis | Agent pass over architecture, entry points, and data flows to seed the pentest, plus optional multi-stage security code analysis, sized to finish inside a CI run | Same as Pro | Persistent code property graph plus a long-running analysis harness with interprocedural taint, sanitizer modeling, cross-repo context, exploit chains, and multi-pass review | Same as Pro | -| White-box pentesting | On-demand, source-aware white-box pentesting with optional authenticated testing, focused on injection, XSS, SSRF, broken authentication, and broken authorization, with proof by exploitation | Same as Pro | Enterprise-hardened Shannon fork run continuously against white-box and grey-box targets, with proof by exploitation | Same as Pro | +| White-box pentesting | On-demand, source-aware white-box pentesting with optional authenticated testing, focused on injection, XSS, SSRF, broken authentication, and broken authorization, with proof by exploitation | Same as Pro | The enterprise-grade Shannon engine, run continuously against white-box and grey-box targets, with proof by exploitation | Same as Pro | | Black-box pentesting (no source code) | Not included. Shannon needs the target's source code | Same as Pro | Agents attack the running application from the outside with no source access, with up to 4 login credentials for multi-role testing. Findings are validated with working exploits | Same as Pro | | SCA and secrets | Not included | Same as Pro | SCA with reachability and secrets scanning, including repository history | Same as Pro | | Findings management | Per-run PDF, Markdown, JSON, and SARIF 2.1.0, with SARIF upload to GitHub code scanning | Same as Pro | One record per vulnerability per repository across scans and scanners, with status history, auto-reopen, ownership, SLAs, dashboards, and audit evidence | Same as Pro | @@ -64,7 +64,7 @@ Shannon focuses on injection, XSS, SSRF, and broken authentication and authoriza ### Proof by exploitation -The pentesting engine is a hardened fork of Shannon with the same rule: a pentest finding requires a working exploit. No exploit, no finding. Pro and Enterprise store the exploit and replay it later to verify the fix. +The pentesting engine is an enhanced, enterprise-grade version of the Shannon engine, built on the same methodology and the same rule: a pentest finding requires a working exploit. No exploit, no finding. Pro and Enterprise store the exploit and replay it later to verify the fix. The Blackbox Pentester applies the same rule without source access. It attacks the running application from the outside with a real browser and terminal, and it can take up to 4 login credentials (Google OAuth, GitHub, or custom auth) to test privilege escalation and IDOR across roles. diff --git a/llms-full.txt b/llms-full.txt index deb5d316..a869a98c 100644 --- a/llms-full.txt +++ b/llms-full.txt @@ -254,7 +254,7 @@ See the [Shannon GitHub Action documentation](https://github.com/KeygraphHQ/shan See [keygraph.io/pricing](https://keygraph.io/pricing) for current prices and the full feature table. -**Pro**, **Enterprise**, and the **Community Program** run an enterprise-hardened fork of Shannon, and all three add: +**Pro**, **Enterprise**, and the **Community Program** are powered by an enhanced, enterprise-grade version of the Shannon engine, and all three add: - **Black-box pentesting**: tests the running application from the outside, with no source code needed. - **Dependency (SCA) and secret checks**: SCA with reachability, and secrets scanning that includes repository history. @@ -1377,7 +1377,7 @@ For organizations that need broader static and organizational coverage now, see Shannon 3.0 is an open-source pentester. It reads your source, maps routes and data flows, runs real attacks against a live target, and writes PDF and SARIF reports. It runs locally, in CI, or air-gapped with your own model. Shannon is a complete pentester, not a trial edition. -Pro and Enterprise are Keygraph's commercial editions. They run an enterprise-hardened fork of Shannon continuously across hundreds of repositories and add what a security team needs around it: black-box pentesting that needs no source code, audit-depth static analysis on a parsed code graph, SCA and secrets scanning, one deduplicated record per vulnerability across scans and scanners, fix pull requests, fix verification, two-way Jira sync, and SSO, RBAC, and audit logs. They are for security teams that own vulnerability management across many engineering teams and need one place to triage, assign, fix, and verify. +Pro and Enterprise are Keygraph's commercial editions. They are built on an enhanced, enterprise-grade version of the Shannon engine, run continuously across hundreds of repositories, and add what a security team needs around it: black-box pentesting that needs no source code, audit-depth static analysis on a parsed code graph, SCA and secrets scanning, one deduplicated record per vulnerability across scans and scanners, fix pull requests, fix verification, two-way Jira sync, and SSO, RBAC, and audit logs. They are for security teams that own vulnerability management across many engineering teams and need one place to triage, assign, fix, and verify. The Community Program is Pro at no cost for organizations that qualify. Every module is included in Pro, Enterprise, and the Community Program. They differ in price, eligibility, hosting, and support. Current prices and the full feature table are at [keygraph.io/pricing](https://keygraph.io/pricing). @@ -1392,7 +1392,7 @@ No source code? Use the [Blackbox Pentester](https://keygraph.io/agentic-blackbo | Price | Open source under AGPL-3.0. You pay only your own model costs | $0 in cloud service fees while you qualify. You pay only your own AI provider usage | $50 per active developer per month, every module included, no add-ons | Custom | | Best for | Developers and teams running repository-level pentests locally or in CI | U.S.-based 501(c)(3) nonprofits, and seed or pre-Series-A startups with 20 or fewer active developers | Teams that want every module, cloud-hosted and managed by Keygraph | Security organizations running continuous AppSec across many teams and repositories that need it inside their own environment | | Code analysis | Agent pass over architecture, entry points, and data flows to seed the pentest, plus optional multi-stage security code analysis, sized to finish inside a CI run | Same as Pro | Persistent code property graph plus a long-running analysis harness with interprocedural taint, sanitizer modeling, cross-repo context, exploit chains, and multi-pass review | Same as Pro | -| White-box pentesting | On-demand, source-aware white-box pentesting with optional authenticated testing, focused on injection, XSS, SSRF, broken authentication, and broken authorization, with proof by exploitation | Same as Pro | Enterprise-hardened Shannon fork run continuously against white-box and grey-box targets, with proof by exploitation | Same as Pro | +| White-box pentesting | On-demand, source-aware white-box pentesting with optional authenticated testing, focused on injection, XSS, SSRF, broken authentication, and broken authorization, with proof by exploitation | Same as Pro | The enterprise-grade Shannon engine, run continuously against white-box and grey-box targets, with proof by exploitation | Same as Pro | | Black-box pentesting (no source code) | Not included. Shannon needs the target's source code | Same as Pro | Agents attack the running application from the outside with no source access, with up to 4 login credentials for multi-role testing. Findings are validated with working exploits | Same as Pro | | SCA and secrets | Not included | Same as Pro | SCA with reachability and secrets scanning, including repository history | Same as Pro | | Findings management | Per-run PDF, Markdown, JSON, and SARIF 2.1.0, with SARIF upload to GitHub code scanning | Same as Pro | One record per vulnerability per repository across scans and scanners, with status history, auto-reopen, ownership, SLAs, dashboards, and audit evidence | Same as Pro | @@ -1439,7 +1439,7 @@ Shannon focuses on injection, XSS, SSRF, and broken authentication and authoriza ### Proof by exploitation -The pentesting engine is a hardened fork of Shannon with the same rule: a pentest finding requires a working exploit. No exploit, no finding. Pro and Enterprise store the exploit and replay it later to verify the fix. +The pentesting engine is an enhanced, enterprise-grade version of the Shannon engine, built on the same methodology and the same rule: a pentest finding requires a working exploit. No exploit, no finding. Pro and Enterprise store the exploit and replay it later to verify the fix. The Blackbox Pentester applies the same rule without source access. It attacks the running application from the outside with a real browser and terminal, and it can take up to 4 login credentials (Google OAuth, GitHub, or custom auth) to test privilege escalation and IDOR across roles.