Security assessment orchestration

Make the assessment process as reviewable as the result.

ChaosEngine replaces fragile hand-built pipelines with visible workflows that connect authorized scope, human decisions, worker execution and output artifacts.

Representative interface previewExternal reconnaissance workflow
Pending approval
01 / InputTarget domainexample.com
02 / ToolAsset discoveryPassive discovery
03 / ToolService validationLive host probing
04 / AgentResult triageApproved agent definition
05 / Conditional edgeFindings present?Continue when true
06 / OutputAssessment resultsStructured export

This preview represents the current product model. Labels and controls may change during early access; example targets and outputs are illustrative.

The operating problem

Security teams have tools. The missing layer is repeatable execution.

Bash scripts and one-off commands are fast to create, but difficult to review, hand off and reproduce. Tool output becomes fragmented, approval context lives in chat, and the next assessment starts by reconstructing the previous one.

ChaosEngine makes the sequence explicit: what enters the workflow, what can run, who must approve it, where it executes and which artifacts it produces.

Implemented product capabilities

Design, govern, execute and inspect from one control plane.

01Workflow design

Visual DAG builder

Compose input, tool, script, agent and output nodes on a visible graph with explicit dependencies.

Input / Tool / Script / Agent / Output
02Conditional execution

Branch on structured results

Route a downstream node when a JSON field equals, differs from or contains the value your workflow expects.

Equals / Not equals / Contains
03Copilot beta

Edit workflows with AI

Describe a change, review the updated canvas and undo the last AI modification when it is not right.

Prompt / Review / Undo
04Scope registry

Model the target precisely

Manage approved targets across domains, IPs, repositories, APIs, mobile apps, networks, files and URLs.

12 supported scope types
05Governance

Approval before execution

Move workflows and supporting resources through draft, pending, approved or rejected states with reviewer context.

Draft / Pending / Approved / Rejected
06Arsenal

Catalog reusable building blocks

Keep tool actions, agent definitions and runtime configurations available as governed workflow resources.

Tools / Agents / Configurations
07Execution control

Run, schedule, cancel and resume

Track queued and running work, apply node timeouts and retries, cancel an execution or resume from a failed node.

Local workers / Batch backend
08Evidence

Structured results and artifacts

Keep node status, errors, table-ready outputs and execution artifacts connected to the run that produced them.

JSON / JSONL / Text / Files
09Access and automation

Organization controls and MCP

Apply organization-scoped permissions, manage users, retain audit activity and operate supported resources through MCP.

Permissions / Audit logs / MCP
Execution model

The workflow definition is only the start.

Before execution, ChaosEngine validates the graph and checks the applicable approval state. During execution, nodes run through the configured backend and retain their status and artifacts.

  1. 01
    Define authorized scope

    Start with a supported target type and the context needed by later nodes.

  2. 02
    Compose and validate

    Connect nodes into a reachable, acyclic workflow with a clear output path.

  3. 03
    Approve

    Record the reviewer decision required by the organization and workflow state.

  4. 04
    Execute through workers

    Run node commands and agent operations in the configured execution environment.

  5. 05
    Review artifacts

    Inspect node outputs and final exports together with the execution status.

Product boundaries

What ChaosEngine is—and is not.

Is ChaosEngine a vulnerability scanner?

No. ChaosEngine orchestrates registered tools, scripts and agents. The scanner remains the tool node; ChaosEngine governs how it participates in the wider assessment.

Is it a managed pentest service?

No. Your team remains responsible for authorization, assessment design, reviewer decisions and interpretation of results.

Is every CLI tool automatically supported?

No. A tool must be represented in the ChaosEngine catalog or deliberately wrapped, and its binary and dependencies must exist on the selected worker.

Does catalog availability prove runtime readiness?

No. Early-access onboarding confirms the actual worker environment and tool behavior before a workflow is treated as executable.

ChaosEngine early access

Bring one real assessment workflow.

We are onboarding a focused group of security teams and helping each one translate an existing process into a governed ChaosEngine workflow.