WardizonWARDIZON
Docs // How_Wardizon_Works

Documentation

Getting Started/Quickstart

Your first pentest, end to end

From empty console to a delivered co-branded PDF: the full Wardizon workflow.

1 · Create the client

Every engagement belongs to a client record. Clients are tenant-isolated by Row-Level Security from the moment they exist, with no configuration required.

2 · Send the authorization request

No scan runs without a signed Rules-of-Engagement. Send the authorization request from the Scan Wizard. Wardizon emails the signing link straight to your client's approver; it is never shown to you. The approver needs no account. (The authorization email and page are currently in Portuguese.)

Sending the request uses credits, whether or not the client signs. See Core concepts.

ENFORCED AT THE WORKFLOW LEVEL
The RoE check runs inside the scan workflow itself, not only at the API. There is no setting or admin role in the product that skips it. A SHA-256 signature hash, the signer and the time of signature are recorded for the audit trail.

3 · Launch the scan

Once the RoE shows signed, launch the scan from the console. The engine selects specialised agents by scan type, plan and the signed scope.

4 · Generate the report

A co-branded PDF with an AI executive summary, remediation steps per finding, and a compliance appendix for SOC 2, ISO 27001, PCI DSS, LGPD and GDPR. The console also shows stack-specific fix code; how many findings get it depends on your plan. Reports are delivered in Brazilian Portuguese today.

TIP
Press N anywhere in the console to launch the Scan Wizard.
Something unclear or out of date?Suggest an edit →