.
Capability

Exploit Validation

Nullify proves every vulnerability before it ever reaches a human. Pentests validate findings through active, multi-stage exploitation — not reported theory — and every exploit is independently re-reviewed against its own evidence before it counts. The same discipline verifies fixes: a proposed patch has to prove it actually closes the hole before Nullify opens the pull request.

What it does

  • Proves before it reports. Nullify's pentest agent validates in-scope REST and GraphQL pentest findings through active, multi-stage exploitation instead of reporting a theoretical finding, informed by what it already knows about your code, dependencies and cloud footprint.
  • Independently re-reviewed. Every exploit is checked a second time against its own evidence before a finding ever surfaces — a re-review pass, not a single agent's word.
  • Ships with evidence, not a severity guess. Deliverables include request/response pairs, screenshots and video — proof a developer or auditor can actually look at.
  • Fixes have to prove themselves too. Before Nullify opens a pull request, the remediation is independently reviewed and proof that it works is required — not just a diff that looks plausible.
  • Scoped honestly. Live exploitation targets REST and GraphQL APIs; SPA and SSR applications are covered separately through Bug Hunts, which promote confirmed exposure to a full pentest.

How it works

Nullify's pentest agent runs continuously and hands-off, launched from the console, the CLI or a GitHub Action. Rather than stopping at a signature match, it actively exploits what it finds — chaining requests and application logic the way an attacker would — using what it already knows about your codebase, dependencies and cloud environment. That exploitation produces first-hand evidence: request/response pairs, screenshots, video. Every exploit is then independently re-reviewed against its own evidence before it counts as a finding, so what reaches triage is a fact rather than a first draft. Triage layers on reachability, exploitability and business context to decide what's urgent versus what can wait — and the same standard for proof applies on the way out: before Nullify opens a fix PR, the remediation is independently reviewed and has to prove it actually works, not just look right in the diff. A human still makes the final call on both ends — the finding and the fix — but neither one shows up without proof behind it.

Frequently asked questions

What does "exploit validation" actually mean?+

For in-scope pentest findings, exploit validation means a finding is reported with reproducible exploit evidence. Nullify then scores impact against your business context, prepares a fix, and manages the pull request through review until your team merges it.

How is this different from a CVSS score or a scanner's severity rating?+

A CVSS score is a guess about theoretical impact. Nullify's pentest agent validates in-scope REST and GraphQL pentest findings through active, multi-stage exploitation — it doesn't stop at "this looks reachable," it exploits the path and hands you the evidence.

What evidence do we actually get?+

Request/response pairs, screenshots and video for anything the pentest agent exploits, plus a second, independent review of the exploit against its own evidence before it's reported. It's built to be handed straight to a developer or an auditor, not re-verified by hand.

Does every finding get this same live-exploit treatment?+

Live, evidence-backed exploitation is how Nullify's pentest agent validates REST and GraphQL API findings; SPA and SSR applications are covered through Bug Hunts, which promote confirmed exposure into a full pentest. Across all finding types, triage still checks reachability and exploitability before anything reaches a human — pentests are where that proof becomes a first-hand exploit.

Does exploit validation apply to fixes, or just findings?+

Both. Before Nullify opens a pull request, the proposed fix is independently reviewed and validated against the build and relevant tests, so your team receives a merge-ready change with evidence.

Read the docs: Pentests · Remediations · Triage · From the blog: Exploit Validation: Proof, Not Guesses · Fixes You Can Prove · Related: Code Security · AI Pentest Agent · Triage & Remediation

Watch Nullify Prove It, Not Guess It

Book a demo and watch Nullify find, exploit and prove a vulnerability in your own stack — evidence included.

Book a live demo