Skip to main content

First-party security platform

Continuous testing for applications you own.

Waldok verifies ownership, enforces first-party scope, and runs assessments without ever becoming an arbitrary attack tool. Third-party vendors stay out of active scanner traffic.

Ownership verified First-party only Scope enforced No third-party scanning

Verify ownership

DNS TXT or HTTP proof

Enforce scope

Fail closed by design

Assess safely

First-party traffic only

Track findings

Evidence & retests

How it works

One clear path from owned asset to assessed finding.

Add what you own, prove it, assess within scope, then remediate with evidence. Nothing active runs until ownership is verified.

  1. 01 Create project
  2. 02 Add target
  3. 03 Verify ownership
  4. 04 Review scope
  5. 05 Start assessment
  6. 06 Review findings
  7. 07 Remediate
  8. 08 Retest

Hard product rule

Many capabilities. One boundary.

DNS, HTTP, TLS, discovery, findings, and reports all operate behind the same ownership and scope engine. There is no override that enables third-party pentesting.

Ownership Scope DNS HTTP TLS Discovery Findings Evidence Retests Reports

Capabilities

Features that keep assessments responsible

Built for operators who need real coverage without losing control of what can be scanned.

01

Ownership verification

DNS TXT and HTTP file challenges prove control before any active scanner traffic is allowed.

  • Cryptographically random tokens
  • Expiring challenges
  • Audited verification events
02

Scope enforcement engine

Every active request is revalidated. Redirects, discoveries, and uncertain hosts fail closed.

  • First-party only
  • Third-party blocklist
  • No advanced override
03

Organization-aware workspace

Projects, targets, and findings stay isolated by organization from day one.

  • Roles & membership
  • Cross-tenant denial
  • Audit trail
04

Asset discovery with brakes

New hosts can be discovered, but they stay unverified until ownership is proven.

  • Candidate inventory
  • Manual promotion
  • No auto-scan on discovery
05

Findings with evidence

Every finding carries context, severity, and proof so remediation is actionable.

  • Evidence attachments
  • Severity & status
  • Retest workflow
06

Production-shaped foundation

PostgreSQL, Redis, Docker, nginx, queue workers, and scheduler — not a prototype stack.

  • Docker Compose stack
  • Redis queues & sessions
  • Isolated scanner network
07

Scan profiles you control

Choose depth and intensity inside policy, without opening the door to arbitrary targets.

  • Profile presets
  • Job orchestration
  • Rate & scope limits
08

Audit-ready decisions

Ownership checks, scope denials, and scan starts leave a clear record of what happened and why.

  • Immutable event log
  • Actor & reason
  • Exportable history

Why it matters

Security leverage without reckless scanning

Applications you own

Your own apps, APIs, WordPress sites, and other customer-owned properties can be assessed after verification. Arbitrary third-party websites cannot.

Third parties stay observed, not attacked

Stripe, Google, OpenAI, Twilio, and similar vendors may appear as integrations. Active scanner traffic never goes to them.

Fail closed when uncertain

If ownership, classification, or scope is unclear, Waldok does not scan. Decisions are recorded for audit.

Built for operators who need trust

Clear records, encrypted secrets, organization isolation, and production infrastructure from the foundation up.

Built for

Security teams Platform owners Product engineers Compliance leads Agency operators Founders DevOps leads Consultants

Governance

Classification you can see. Scanning you can trust.

Hosts are classified before active testing. Only verified first-party assets can receive scanner traffic.

Mode 1

Observe

Inventory and classify hosts. No active scanner traffic until ownership is proven.

Mode 2

Verify

DNS or HTTP challenges prove control. Unverified first-party candidates stay blocked.

Mode 3

Assess

Active testing runs only on verified, in-scope first-party assets — never on third parties.

FP-V

First-party verified

Ownership proven. Active testing may proceed when in scope.

Example: verified app.example.com

FP-U

First-party unverified

Candidate owned host. Active testing stays blocked.

Example: newly discovered subdomain

3P

Third-party

Known vendor or external dependency. Never actively scanned.

Example: api.stripe.com

BLK

Blocked

Localhost, metadata, or infrastructure that must not be touched.

Example: 169.254.169.254

Put owned applications under continuous command.

Verify what you own, assess within scope, and keep third-party infrastructure out of the blast radius.