Authorize
Record the exact program, scope, policy, identities, and hard stops before testing.
BBX is a controlled research environment for authorized web and API security testing. It keeps coding agents inside scope, accounts for every endpoint, and refuses conclusions that are not backed by reproducible traffic.
Agentic security work becomes useful when a second person can reconstruct it. BBX binds scope, traffic, coverage, validation, and reporting into one continuous record.
Record the exact program, scope, policy, identities, and hard stops before testing.
Recover frontend routes, lazy bundles, source maps, endpoints, parameters, and runtime flows.
Send identity-aware requests through a single mediated and recorded traffic path.
Challenge each candidate from a fresh context and prove impact before promotion.
Produce a minimal, reproducible, human-reviewed disclosure without internal secrets.
The hard problem is not making an agent send requests. It is preserving authorization, evidence, and epistemic discipline while the agent works for hours.
Every request receives a durable operation record. Claims whose cited evidence cannot be resolved are rejected before they enter the triage queue.
An autonomous run cannot quietly declare completion while mapped endpoints remain untested. Skips require an explicit reason.
Declared hosts and target policies constrain the traffic broker. Related infrastructure is not treated as permission.
Promising candidates are re-tested from an independent context before impact, severity, or report readiness is accepted.
Security agents should be judged by what another person can verify—not by how confidently they narrate a result.
BBX keeps the model in the reasoning loop while deterministic controls own authorization, target traffic, evidence integrity, completion criteria, and the publication boundary.
BBX comes from repeated authorized research across real web and API programs. Its controls encode the parts of the workflow that decide whether a promising signal becomes a defensible security finding: scope, identity, evidence, validation, and clear disclosure.
The project began in July 2026 and is a bootstrapped, founder-led working prototype. The next phase is controlled evaluation with independent researchers and small security teams.
BBX is built for coordinated vulnerability disclosure, internal application security, and other explicitly authorized research. It is not offered for indiscriminate scanning or unauthorized access.
Operators must document the program or system owner, exact targets, permitted techniques, identities, and stop conditions before an agent sends target traffic.
The current prototype is local-first. Credentials, captured traffic, and unpublished findings remain in the operator's environment. Shared reports are minimized to the evidence needed for reproduction.
BBX is preparing for a private design-partner phase focused on measurable coverage, reproducibility, false-positive rejection, human-review time, and cost per validated result.