Enterprise pilots · Separate from the core developer toolkit

Bring agent-readiness evidence into your release workflow.

Start with one approved public page, one useful finding, and a reviewed change. This is a scoped engineering pilot—not a promise to make every enterprise application agent-ready.

Useful today

  • Bounded checks of public, unauthenticated HTML. Findings come with source evidence and recommendations.
  • Node SDK/CLI and a local GitHub Actions adapter. Save reports in your own artifact store and compare compatible source findings.
  • Review supplied tool contracts and retrieve implementation guidance through the shared MCP server.
  • Two starter recipes: a browser search-tool adapter and an accessible search form. Your developers review, integrate, and deploy.

Requires a separate development phase

  • Private or authenticated application execution inside the enterprise environment.
  • A connected-browser runner that executes authorized tasks and verifies independent outcomes.
  • Tenant isolation, SSO/RBAC, controlled report history, configurable hosted retention, and enterprise audit logs.
  • Dedicated service limits, operational support and an agreed SLA. These are not included in the public utility.

One workflow. A decision based on evidence.

  1. 01

    Agree on one public workflow

    Use an already-public page owned by a consenting team. Agree on data handling, a named reviewer, and what counts as a useful finding. Never weaken access controls for a scan.

  2. 02

    Save a reviewed baseline

    Run the hosted source scan through the toolkit. Keep JSON in the team’s own controlled artifact store. A report ID is not durable evidence.

  3. 03

    Review and apply one relevant fix

    A developer checks the recommendation, chooses a supported recipe if appropriate, and implements through the normal change process. No automatic code edits or deployment.

  4. 04

    Compare and decide whether to continue

    Check the same URL with matching inputs, model and complete inventories. Review false alarms, setup effort, actionable findings, and voluntary repeat usage. Task success requires a separate browser trial.

Running the CLI inside your CI does not make the scan private: it sends approved inputs to our hosted scanner. Source comparisons can run locally. Hosted URL-attempt retention is 90 days, with deletion during subsequent writes, and is not controlled by your CI artifact policy. Do not send secrets or private paths.

Review data handling before a pilot →

What would make the pilot worth keeping?

A reviewer confirms a useful finding, a developer can act on it, comparable evidence survives the change, and the team chooses to reuse the check. Measure setup effort, actionable findings, false alarms, inconclusive checks and repeat usage. Runtime success, cost savings and ROI remain unmeasured until a separate evaluation establishes them.