Evidence-bound security agents

Autonomy you can prove.

BBX is a controlled research environment for authorized web and API security testing. It keeps coding agents inside scope, accounts for every endpoint, and refuses conclusions that are not backed by reproducible traffic.

Authorized targets onlyLocal-first evidenceHuman-reviewed reports
research-session / authorization-sweep
SCOPEapi.example.test · verified program boundary
MAP147 endpoints recovered · 23 client-only parameters
IDENTITYanonymous · user-a · user-b · administrator
PROBEGET /api/documents/7 across 4 identities
SIGNALbyte-identical 200 response across tenant boundary
EVIDENCErequest + response + actor + timestamp preserved
VALIDATEfresh-context review rejects confounders
REPORTreproducible sequence ready for human review
29CLI operations across the research lifecycle
33automated control tests passing in the current prototype
100%of in-scope prototype traffic routed through the evidence boundary by design
0unsupported findings promoted by the tested evidence gate
Research lifecycle

One chain of custody.

Agentic security work becomes useful when a second person can reconstruct it. BBX binds scope, traffic, coverage, validation, and reporting into one continuous record.

01

Authorize

Record the exact program, scope, policy, identities, and hard stops before testing.

02

Map

Recover frontend routes, lazy bundles, source maps, endpoints, parameters, and runtime flows.

03

Probe

Send identity-aware requests through a single mediated and recorded traffic path.

04

Validate

Challenge each candidate from a fresh context and prove impact before promotion.

05

Report

Produce a minimal, reproducible, human-reviewed disclosure without internal secrets.

Control plane

Designed against confident mistakes.

The hard problem is not making an agent send requests. It is preserving authorization, evidence, and epistemic discipline while the agent works for hours.

Evidence gate

No traffic, no finding.

Every request receives a durable operation record. Claims whose cited evidence cannot be resolved are rejected before they enter the triage queue.

Coverage gate

Unknown work stays visible.

An autonomous run cannot quietly declare completion while mapped endpoints remain untested. Skips require an explicit reason.

Boundary gate

Scope is executable state.

Declared hosts and target policies constrain the traffic broker. Related infrastructure is not treated as permission.

Validation gate

Discovery does not certify itself.

Promising candidates are re-tested from an independent context before impact, severity, or report readiness is accepted.

Security agents should be judged by what another person can verify—not by how confidently they narrate a result.

BBX keeps the model in the reasoning loop while deterministic controls own authorization, target traffic, evidence integrity, completion criteria, and the publication boundary.

Founder–problem fit

Built from the work, not around a demo.

BBX comes from repeated authorized research across real web and API programs. Its controls encode the parts of the workflow that decide whether a promising signal becomes a defensible security finding: scope, identity, evidence, validation, and clear disclosure.

The project began in July 2026 and is a bootstrapped, founder-led working prototype. The next phase is controlled evaluation with independent researchers and small security teams.

StagePre-launch prototype
FundingBootstrapped
Model roadmapClaude API evaluation planned
Operating policy

Authorization is a product boundary.

BBX is built for coordinated vulnerability disclosure, internal application security, and other explicitly authorized research. It is not offered for indiscriminate scanning or unauthorized access.

Authorized use

Operators must document the program or system owner, exact targets, permitted techniques, identities, and stop conditions before an agent sends target traffic.

  • No out-of-scope hosts or redirects
  • No credential spraying or destructive testing
  • No denial-of-service or volume-based testing
  • Human review before external disclosure

Privacy by default

The current prototype is local-first. Credentials, captured traffic, and unpublished findings remain in the operator's environment. Shared reports are minimized to the evidence needed for reproduction.

  • No public signup or user tracking
  • No sale of visitor or research data
  • No target data collected by this website
  • Routine hosting logs may be processed by the hosting provider
Current stage

Working prototype. Deliberate next steps.

BBX is preparing for a private design-partner phase focused on measurable coverage, reproducibility, false-positive rejection, human-review time, and cost per validated result.

Researchers and security teams interested in a structured prototype evaluation can contact founder@sorah-nft.io.