.
Capability

Exploit Validation

Nullify proves every vulnerability before it ever reaches a human. Pentests validate findings through active, multi-stage exploitation — not reported theory — and every exploit is independently re-reviewed against its own evidence before it counts. The same discipline verifies fixes: a proposed patch has to prove it actually closes the hole before Nullify opens the pull request.

What it does

  • Proves before it reports. Nullify's pentest agent validates vulnerabilities through active, multi-stage exploitation instead of reporting a theoretical finding, informed by what it already knows about your code, dependencies and cloud footprint.
  • Independently re-reviewed. Every exploit is checked a second time against its own evidence before a finding ever surfaces — a re-review pass, not a single agent's word.
  • Ships with evidence, not a severity guess. Deliverables include request/response pairs, screenshots and video — proof a developer or auditor can actually look at.
  • Fixes have to prove themselves too. Before Nullify opens a pull request, the remediation is independently reviewed and proof that it works is required — not just a diff that looks plausible.
  • Scoped honestly. Live exploitation targets REST and GraphQL APIs; SPA and SSR applications are covered separately through Bug Hunts, which promote confirmed exposure to a full pentest.

How it works

Nullify's pentest agent runs continuously and hands-off, launched from the console, the CLI or a GitHub Action. Rather than stopping at a signature match, it actively exploits what it finds — chaining requests and application logic the way an attacker would — using what it already knows about your codebase, dependencies and cloud environment. That exploitation produces first-hand evidence: request/response pairs, screenshots, video. Every exploit is then independently re-reviewed against its own evidence before it counts as a finding, so what reaches triage is a fact rather than a first draft. Triage layers on reachability, exploitability and business context to decide what's urgent versus what can wait — and the same standard for proof applies on the way out: before Nullify opens a fix PR, the remediation is independently reviewed and has to prove it actually works, not just look right in the diff. A human still makes the final call on both ends — the finding and the fix — but neither one shows up without proof behind it.

Frequently asked questions

What does "exploit validation" actually mean?+

It means a finding isn't reported until Nullify has proven it. Nullify's own description of the loop: it finds vulnerabilities, validates exploitability with a reproducible proof, scores impact against your business context, writes the fix, and routes the PR to the right owner until it merges. The proof step is exploit validation.

How is this different from a CVSS score or a scanner's severity rating?+

A CVSS score is a guess about theoretical impact. Nullify's pentest agent validates vulnerabilities through active, multi-stage exploitation — it doesn't stop at "this looks reachable," it exploits the path and hands you the evidence.

What evidence do we actually get?+

Request/response pairs, screenshots and video for anything the pentest agent exploits, plus a second, independent review of the exploit against its own evidence before it's reported. It's built to be handed straight to a developer or an auditor, not re-verified by hand.

Does every finding get this same live-exploit treatment?+

Live, evidence-backed exploitation is how Nullify's pentest agent validates REST and GraphQL API findings; SPA and SSR applications are covered through Bug Hunts, which promote confirmed exposure into a full pentest. Across all finding types, triage still checks reachability and exploitability before anything reaches a human — pentests are where that proof becomes a first-hand exploit.

Does exploit validation apply to fixes, or just findings?+

Both. Before Nullify opens a pull request, the remediation is independently reviewed and has to prove it works — the fix gets the same standard of proof as the original finding, so a merge-ready PR isn't a guess either.

Read the docs: Pentests · Remediations · Triage · From the blog: Exploit Validation: Proof, Not Guesses · Fixes You Can Prove · Related: Code Security · AI Pentest Agent · Triage & Remediation

Watch Nullify Prove It, Not Guess It

Book a demo and watch Nullify find, exploit and prove a vulnerability in your own stack — evidence included.

Book a Demo