A DataHubz product

Authorized penetration testing, with end-to-end traceability.

Rubro runs real offensive-security engagements inside a provable safety envelope: admission-gated tools, scope-locked egress, WORM evidence and compliance-mapped findings, from intake to client acceptance.

CVSS v3.1OWASP API 2023MITRE ATT&CKNIST CSF 2.0NIST 800-53r5CIS v8.1ISO 27001

A platform built for authorized offense

Safety, evidence and compliance are structural, not afterthoughts bolted onto a scanner.

F-01

Safety spine

Every action passes a server-side admission gate: signed authorization, open phase, no active STOP-TEST, scope, window and technique checks, enforced before any tool runs.

F-02

Scope-enforcing egress

Tools run in ephemeral containers whose only network path is a scope-locked proxy. Out-of-scope is unreachable by construction, not by policy.

F-03

WORM evidence & chain of custody

Output is captured as write-once evidence with a SHA-256 manifest and an append-only, hash-chained audit log. PII is redacted at capture.

F-04

Compliance cross-map

Findings are scored in CVSS v3.1 and mapped to OWASP API 2023, MITRE ATT&CK and cross-walked to NIST CSF 2.0 / 800-53r5 / CIS v8.1 / ISO 27001.

F-05

Real black-box + grey-box toolkit

A comprehensive adapter toolkit (network, web, API, cloud and code) produces tool-generated candidate findings that operators validate into HALLAZGOs.

F-06

Client portal

Clients complete intake questionnaires, follow status, review redacted findings and accept reports, with a one-tap emergency STOP-TEST, all role-scoped.

How an engagement flows

A durable lifecycle that refuses to advance until each obligation is met.

01

Intake

The client completes the pre-engagement questionnaires that scope the assessment.

02

Authorization

Four monotonic legal gates (intake, SoW, Rules of Engagement, authorization letter) must be satisfied before testing.

03

Black box

An uninformed, external assessment, sealed with a checkpoint before any privileged knowledge is shared.

04

Grey box

Credentialed and cloud-config testing behind an enforced information barrier from the black-box phase.

05

Report & acceptance

Bilingual deliverables with an evidence package; the client accepts or files observations.

Security & governance, by construction

Rubro is designed for engagements where the blast radius matters: regulated clients, production systems and a clear chain of custody for every byte of evidence.

Sign in
  • Mandatory MFA on every account
  • Row-level multi-tenant isolation
  • Append-only hash-chained audit
  • AES-256-GCM evidence at rest
  • Sealed black-box → grey-box barrier
  • 15-minute STOP-TEST kill switch

Run your next engagement on Rubro

Sign in to your operator console or client portal.

Sign in