Nullify proves every vulnerability before it ever reaches a human. Pentests validate findings through active, multi-stage exploitation — not reported theory — and every exploit is independently re-reviewed against its own evidence before it counts. The same discipline verifies fixes: a proposed patch has to prove it actually closes the hole before Nullify opens the pull request.
Nullify's pentest agent runs continuously and hands-off, launched from the console, the CLI or a GitHub Action. Rather than stopping at a signature match, it actively exploits what it finds — chaining requests and application logic the way an attacker would — using what it already knows about your codebase, dependencies and cloud environment. That exploitation produces first-hand evidence: request/response pairs, screenshots, video. Every exploit is then independently re-reviewed against its own evidence before it counts as a finding, so what reaches triage is a fact rather than a first draft. Triage layers on reachability, exploitability and business context to decide what's urgent versus what can wait — and the same standard for proof applies on the way out: before Nullify opens a fix PR, the remediation is independently reviewed and has to prove it actually works, not just look right in the diff. A human still makes the final call on both ends — the finding and the fix — but neither one shows up without proof behind it.
It means a finding isn't reported until Nullify has proven it. Nullify's own description of the loop: it finds vulnerabilities, validates exploitability with a reproducible proof, scores impact against your business context, writes the fix, and routes the PR to the right owner until it merges. The proof step is exploit validation.
A CVSS score is a guess about theoretical impact. Nullify's pentest agent validates vulnerabilities through active, multi-stage exploitation — it doesn't stop at "this looks reachable," it exploits the path and hands you the evidence.
Request/response pairs, screenshots and video for anything the pentest agent exploits, plus a second, independent review of the exploit against its own evidence before it's reported. It's built to be handed straight to a developer or an auditor, not re-verified by hand.
Live, evidence-backed exploitation is how Nullify's pentest agent validates REST and GraphQL API findings; SPA and SSR applications are covered through Bug Hunts, which promote confirmed exposure into a full pentest. Across all finding types, triage still checks reachability and exploitability before anything reaches a human — pentests are where that proof becomes a first-hand exploit.
Both. Before Nullify opens a pull request, the remediation is independently reviewed and has to prove it works — the fix gets the same standard of proof as the original finding, so a merge-ready PR isn't a guess either.
Read the docs: Pentests · Remediations · Triage · From the blog: Exploit Validation: Proof, Not Guesses · Fixes You Can Prove · Related: Code Security · AI Pentest Agent · Triage & Remediation
Book a demo and watch Nullify find, exploit and prove a vulnerability in your own stack — evidence included.
Book a Demo