CidraOpen the platform

The Cidra platform

Four operational paths. One honest finding ledger.

Start with an inventory, release binary, API contract or authorised public URL. Cidra turns each supported observation into evidence, a remediation decision and a reproducible rescan—without pretending planned scanners are already coverage.

01Operational is a measured state

A module is live only when it executes, records evidence and participates in rescan closure.

02Unknown is an answer

Unsupported, unresolved and unavailable inputs stay visible instead of becoming clean results.

03Intrusion requires a higher gate

Packet-generating and executing modules remain disabled until isolated-runner controls exist.

ONE REMEDIATION SYSTEM

Different evidence. The same decision surface.

Automated observations are deduplicated by scanner and target. Human workflow state survives rescans, while a previously resolved weakness reopens when it returns.

CCidraNorthwind / Product overviewREPRESENTATIVE DEMO
CURRENT EXPOSURE

What needs attention now

Operational scanner results, one prioritised queue.

Operational
Open findings143 need review
Modules reporting4all current
Act now3evidence-backed
ReferenceFindingModuleSeverity
CND-1042Missing Content Security PolicyWebsiteHigh
CND-1043DEP is not enabledBinaryHigh
CND-1044Anonymous API operationAPI contractMedium
Representative product data. Every module writes into one finding and remediation ledger.

THE APPROACH

Evidence before confidence.

Cidra separates observation, interpretation and remediation so a technical signal never silently becomes an exploit claim.

  1. 01
    Bound the input

    Validate identity, byte size, target authority and execution mode before assessment.

  2. 02
    Run one named technique

    Each module has a finite parser or request budget and a stated evidence boundary.

  3. 03
    Persist the finding

    Stable deduplication, provenance and redacted evidence feed one remediation ledger.

  4. 04
    Verify the fix

    A complete rescan updates or resolves only findings that technique conclusively reassessed.

CURRENT BOUNDARY

Static and passive modules are live. Intrusive testing is not.

Authenticated crawling, API fuzzing, network probing, dynamic binary/mobile sandboxing and attack-path validation remain on the gated roadmap. They are not included in current execution coverage.