Production Beta v1.0.0 — For authorized security testing only
Z2m Red TeamStatus

Scope & SLA

What Z2m Red Team covers today—and what sits outside product scope.

Safe to say

  • · Dual-account IDOR/BOLA when two test users (User A and User B) are provided.
  • · Confirmation gate: no customer vulnerability without replayable HTTP or OOB evidence.
  • · CVSS v3.1 on confirmed findings, with redacted replay PoCs.
  • · 12 first-party authenticated checks (BOLA when two test users are provided) + optional Nuclei/Prowler when those tools are installed. Nuclei/Prowler IDs are labeled separately and are not counted as Z2M playbooks.
  • · Owner's-risk Metasploit auxiliary/check is not Hard Proof unless replayable HTTP or OOB evidence exists.

In scope

  • · 12 first-party authenticated playbooks (BOLA needs a peer User B; race/CSRF only on optional endpoints). Nuclei/Prowler IDs are labeled when those tools run — not counted as Z2M playbooks.
  • · Web, API, and AI pentest with finding triage
  • · Confirmation gate: customer vulns require replayable HTTP/OOB evidence plus a PoC; Potential is not logged as a vuln unless report_mode includes investigate
  • · CVSS v3.1 on confirmed findings; Hard Proof ZIP with redacted request/response. Metasploit check output is an msf.txt appendix, not CONFIRMED.
  • · Agent-assisted remediation, tickets, Hard Proof exports
  • · Client remediator portal, engagement reports, continuous programs
  • · Org SSO, audit export, billing, and trust / RoE controls

Engagement restrictions

  • · Destructive actions, denial of service, and mass targeting are disabled (fail-closed). Scan config cannot turn them on.
  • · Race tests: at most 8 parallel requests, and only if you set race_endpoint.
  • · Metasploit MCP stays off on shared SaaS workers. Auxiliary/check or write/session can run on a private customer agent after Trust owner's-risk consent (write needs a second phrase and a 4-hour window). Issues badge those as Owner's risk, not Confirmed, unless HTTP/OOB replay exists.

We do not claim

  • · 200+ offensive playbooks
  • · Zero false positives on novel zero-days
  • · 150 native tools
  • · Hermes reasoning engine
  • · Playwright via MCP / MCP browser as a product feature
  • · 70–85% token reduction as a production SLA
  • · Metasploit on every authorized scan
  • · Metasploit MCP on shared SaaS workers
  • · Metasploit write/session on shared SaaS workers
  • · Sessions or payloads as Hard Proof without HTTP/OOB

Out of scope (N/A)

  • · Physical red team / social engineering engagements
  • · Full cloud CSPM as a managed service (worker hooks only)
  • · CPA-issued SOC 2 Type II attestation (we provide readiness evidence only)

Service levels

  • · Platform uptime target: 99.9% monthly (excludes planned maintenance)
  • · Support response: critical 4h · high 8h · standard 24h (business days, Enterprise+)
  • · Finding SLA inside continuous programs is org-configurable (defaults: critical 24h / high 72h)

Full operational runbook: see docs/ops and the live status page.