A security engineer inside the build loop.
BreachLabs is not a scanner with a chat interface. It is a sequence of seven stages, each producing a specific artefact, each dependent on the one before it. This page is that sequence in detail.
An application is created, modified, or handed over.
The loop starts from an artefact that exists: a repository, a running service, or both. BreachLabs records what it was given so every later claim can be traced back to a specific revision.
Input
Repository path or service endpoint, plus the environment it should run in.
Action
Validate the target, record the revision, confirm authorisation to test it.
Output
A scoped, reproducible assessment target with a fixed reference point.
The application tells you what it exposes.
Reconnaissance is not guesswork about hidden endpoints. It is a structured enumeration of what the running application already answers to.
Enumerated surface
Why it matters
A finding without a surface is not actionable. Every later stage attaches to something on this map — which is why discovery comes before any test runs.
Boundary
Enumeration is limited to the authorised target. If the map is incomplete, the report says so rather than implying full coverage.
Deterministic tools, one question each.
Each tool family answers a narrow question precisely and reproducibly. Measurement is not delegated to a language model, because measurement should not vary between runs.
SAST
Where are risky patterns in the source?
Dependencies
Which versions have known issues?
Secrets
Did credentials reach the repository?
DAST
How does the running service respond?
Browser
What is observable client-side?
Reasoning is written down, not implied.
The agent opens the source around each reported location, traces the data flow, and correlates it with what the running application did. The trace is part of the output.
What investigation adds
What investigation does not do
It does not promote a finding to verified. Correlation raises confidence and produces context; only a targeted reproduction attempt can change the verification state.
Reproduce it, or say you could not.
Verification probes are specific to the claim: parameterisation behaviour for injection, reflection for output encoding, authorisation comparison for object references.
Attempt succeeds
VERIFIED
The probe reproduced the behaviour and the evidence is attached to the finding.
Attempt fails
UNCONFIRMED
The claim could not be reproduced. It stays in the report with that state, rather than being dropped or overstated.
Remediation for this code path.
Guidance names the file, the construct to change, and the reason the change removes the condition — not just the symptom.
Example
Then prove the condition is gone.
A retest repeats the same probe against the changed application. Resolution is recorded only when the probe no longer reproduces the behaviour.
Scope
The probe is replayed for the affected surface, not the whole suite.
Comparison
Before and after behaviour are recorded side by side.
Result
Pass, fail, or still unconfirmed — with the evidence either way.