Skip to main content

Audits

An audit is one offensive engagement against a target domain. You choose a mode, pick targets, and Golem takes over.

The three modes

Shallow

OWASP Top 10 + PoC only. ~30 min. No post-exploitation.

Deep

Full 10-phase attack chain. ~2 hrs. Includes post-exploitation.

Autonomous

Operator-defined mission brief. ~4 hrs. You write the scope.

How an engagement runs

You can watch the entire engagement in real time from the dashboard, or wait for the completion notification (email or Slack).

What every audit produces

  • Findings — confirmed vulnerabilities with severity, evidence, and remediation. See Findings & Evidence.
  • Security score — letter grade A+ to F derived from finding weights. See Security Score.
  • PDF report — cover page, executive summary, per-finding pages with evidence and recommendations. See Reports & Recordings.
  • Asciinema recording — full terminal session replay of every command Golem ran.
  • Screenshots — automatic visual evidence captured at the moment of discovery.

Choosing a mode

Audit statuses

Time budgets

Each mode has a default time budget that controls when Golem stops exploring and starts writing the report:
  • Shallow: 30 minutes
  • Deep: 2 hours
  • Autonomous: 4 hours
The agent’s final phase is always “write report” — even if interrupted, you’ll receive whatever findings were confirmed before the budget expired.

Authorization

Golem AI assumes every target you submit is authorized for full-scope offensive testing. You are responsible for ensuring written authorization before each engagement.