Hi folks
We’ve been working on something in this space (continuous testing + exploit validation + fix suggestions), and a few things keep coming up in conversations:
- Even validated vulns still don’t always get fixed — they just compete with everything else
- Proof-of-exploit is great, but teams still ask “what actually matters this week?”
- Auto-generated fixes are promising, but trust varies a lot (especially for auth / logic changes)
Feels like we’re moving from:
I wanted to learn:
- Are continuous pentesting tools actually useful in practice?
- What % of findings (even high-quality ones) get fixed?
- What’s still missing in your workflow?
What would make it easy for companies to continuously maintain a secure state?