The Cidra platform
Four operational paths. One honest finding ledger.
Start with an inventory, release binary, API contract or authorised public URL. Cidra turns each supported observation into evidence, a remediation decision and a reproducible rescan—without pretending planned scanners are already coverage.
A module is live only when it executes, records evidence and participates in rescan closure.
Unsupported, unresolved and unavailable inputs stay visible instead of becoming clean results.
Packet-generating and executing modules remain disabled until isolated-runner controls exist.
OPERATIONAL NOW
Choose the evidence you already have.
Each module is deliberately narrow enough to explain exactly what it did—and what it could not establish.
Composition analysis
Upload CSV, TSV, CycloneDX or SPDX. Resolve identities, match versions and keep unknowns visible.
Inventory → affected rangeExplore module →02OperationalNative binary assurance
Inspect PE, ELF and Mach-O hardening, signature structure and redacted high-confidence secret signals.
Artifact → hardening evidenceExplore module →03OperationalAPI contract audit
Audit OpenAPI and Swagger transport, authentication, inventory and resource-limit declarations without traffic.
Contract → policy gapsExplore module →04Passive liveWebsite testing
Assess one authorised public page and bounded redirects for transport, headers, cookies and limited HTML signals.
URL → passive observationsExplore module →ONE REMEDIATION SYSTEM
Different evidence. The same decision surface.
Automated observations are deduplicated by scanner and target. Human workflow state survives rescans, while a previously resolved weakness reopens when it returns.
What needs attention now
Operational scanner results, one prioritised queue.
CND-1042Missing Content Security PolicyWebsiteHighCND-1043DEP is not enabledBinaryHighCND-1044Anonymous API operationAPI contractMediumTHE APPROACH
Evidence before confidence.
Cidra separates observation, interpretation and remediation so a technical signal never silently becomes an exploit claim.
- 01Bound the input
Validate identity, byte size, target authority and execution mode before assessment.
- 02Run one named technique
Each module has a finite parser or request budget and a stated evidence boundary.
- 03Persist the finding
Stable deduplication, provenance and redacted evidence feed one remediation ledger.
- 04Verify the fix
A complete rescan updates or resolves only findings that technique conclusively reassessed.
CURRENT BOUNDARY
Static and passive modules are live. Intrusive testing is not.
Authenticated crawling, API fuzzing, network probing, dynamic binary/mobile sandboxing and attack-path validation remain on the gated roadmap. They are not included in current execution coverage.