Skip to content
RiftX

Why this exists

Nobody should be paid to run the same loop twice.

RiftX is one company aimed at one loop: the retest that runs the same way on every engagement and ends in a call somebody has to be willing to sign. What follows is what we are trying to make true, what it cost to refuse the easier versions, and what would make us wrong.

What this is for.

A retest queue that behaves like a scheduled job rather than a staffing question. Findings go in the way a tester wrote them up, come back with a verdict and the evidence underneath it, and the only step left for a person is the one that always needed one.

That is the whole ambition, and it is deliberately one loop. Not the engagement, not the report, not the judgment that goes on the deliverable. The part that repeats identically, every single time.

One product, sold to the people who work those queues, and no second line of business underneath it. Everything on the rest of this page was decided by a company with only this one thing to get right.

The loop this was built to end.

A retest queue is made of findings a senior tester has already seen a dozen times. Navigate to the parameter, paste the payload, watch the reflection, take the screenshot, write the paragraph. The finding changes every time. The loop never does.

It is not a hard problem. It is a repetitive one, and repetitive work does not get better when you hand it to someone more experienced. It only gets more expensive. The part that genuinely needs a pentester, deciding whether what came back proves the fix held, is the smallest part of the job and the first thing a tired queue erodes.

The hard part was never the browser work. It is that a retest has to end in a decision, and a system that says Fixed when the fix does not hold is worse than no system at all. One wrong clear costs more than fifty correct ones earn, and nothing about that asymmetry is symmetrical in the other direction.

So RiftX is aimed at the loop and not at the judgment. It runs the cycle unattended and hands the evidence back, leaving the call with the person whose name goes on the report. The order below follows from that.

Right at a small scope beats useful at a large one.

The order is the part we are strict about, because each step is what buys the right to take the next one. None of them is a date.

First

Be right about one thing.

Retesting a finding somebody already reported, done well enough that a consultancy will put the verdict in front of a client without redoing the work behind it. Nothing below is worth anything until that holds, and it is the only thing we ask to be judged on today.

Then

Publish the record with the misses in it.

A number without its residual is a number nobody has to believe. What the loop got wrong sits on the home page beside what it got right, in the same view, and the whole set is re-scored on every change rather than measured once and quoted from then on.

Only then

Widen, and not before.

We wrote the benchmark we score against. Until somebody outside can run it and arrive at our numbers, everything published here is our own bench test and should be read as one, and widening the scope first would only widen what we could be wrong about.

Every choice here had a cheaper version.

Each could have gone the other way, and the other way was cheaper every time. The price we still pay is part of the entry.

RiftX only ever works on a finding somebody already reported and wrote up.

The price

The larger half of the market.

Scanning is the bigger category and the bigger budget, and everything we can sell is bounded by findings that already exist. The same engine could have gone hunting for new ones instead of waiting to be handed them.

The input is what a tester already wrote for their client, in the shape they wrote it.

The price

An intake we could have made exact.

A field naming the thing to inject would have made intake deterministic and the engineering straightforward. Reading prose means inheriting whatever the reporter wrote, thin write-ups included, and reasoning about it.

A verdict has to rest on evidence that survives being shown to a client.

The price

The verdict people want to buy.

A system willing to treat a reflected string as proof returns a clean Fixed far more often, and a clean Fixed is the answer people are paying for. Holding the bar sends those findings to Needs Review, which nobody is glad to pay for.

There are no customer names on this site, in a strip under the fold or anywhere else.

The price

Social proof where a skeptic looks for it.

A reader wants a name to check right about here, and we do not have one we are cleared to print. Nothing goes on that wall until a client says it can, and that is a slower answer than a strip of borrowed logos.

What would make us wrong.

Four tests, none of which we can pass by shipping something. All four are yours to run on us later rather than ours to report on.

If a verdict still has to be redone before it can be sent.

The whole thesis is that a retest can end in a decision. If our verdicts routinely need a tester to reproduce the finding again before the report goes out, the loop has not left the queue. It has moved, and a queue with an extra step in it is worse than the one we started with.

If Needs Review quietly stops appearing.

It is the outcome nobody wants to pay for, and it is the one that makes the other two worth reading. A system under pressure to look decisive can retire it without changing anything else it does, and when it goes, stop trusting Fixed, because Fixed is what it turns into.

If the evidence stops being enough to argue with.

A verdict you cannot check is an assertion with a screenshot attached. Everything that comes back is meant to be sufficient for you to overturn it, and if it ever stops being sufficient for that, the product has become the thing this company was started to replace.

If what we are paid ever depends on which way a verdict goes.

A retest costs the same against the allowance whichever answer it reaches, and it has to stay that way. If one outcome is ever worth more to us than another, every verdict becomes a claim with an interest behind it and the three tests above stop being possible to pass.

See it run

Watch it retest a finding you already know the answer to.

Every one of those decisions is worth exactly what it holds up to. Bring a finding your team has already retested by hand, watch this one reach its own verdict, and check it against the answer you already own.