SWR7
Home/FAQ
FAQ

Questions we get on the first call

Short answers on what SWR7 does, what it never does, and how an engagement starts. For the long version, see the Insights.

Frequently asked questions

What is SWR7?

SWR7 is an agentic swarm for authorized security testing. Specialized agents, coordinated by one orchestrator, detect vulnerabilities with non-destructive tests, generate a ready-to-apply remediation for each finding and monitor your sites 24/7. It is built for iGaming, fintech and SaaS platforms.

Does SWR7 attack our systems?

No. The default is to find without breaking: passive and non-destructive detection (levels S0–S1) on production. Controlled and intrusive tests (S2–S3) run on staging, only after you sign for them, and are gated by the orchestrator; S3 never runs on production.

What do we need to sign before anything starts?

The Rules of Engagement (RoE): targets in and out of scope, your ownership or written authorization, the safety levels allowed, time windows, emergency contacts and data handling. Nothing is tested before the RoE is signed.

Who applies the fixes?

Your team. SWR7 produces the concrete remediation for the root cause of each finding — configuration, code or process — and verifies afterwards that the finding is gone. On your systems the swarm is propose-only.

What does 24/7 monitoring cover?

Availability and latency from the outside, TLS expiry and protocol strength, security headers, exposed files and paths, subdomain changes, leaked credentials tied to your domain, traffic anomalies against a learned baseline and content integrity of critical pages. Hardening and the under-attack runbook are the DDoS add-on.

How are we alerted?

High-severity findings and confirmed attacks trigger an alert to your operators within minutes. Everything else is visible in the client area and in the PDF report produced after each run.

Can SWR7 test targets we do not own?

No. SWR7 tests only targets you own or hold written authorization to test. Third-party providers and processors are out of scope by default.

Is our data safe with you?

Findings and evidence are stored for the duration agreed in the RoE, visible only to the people you name, and deleted when the engagement ends. Nothing is shared with third parties.

Which industries do you work with?

Primarily iGaming (casinos, crypto-casinos, sportsbooks), fintech and SaaS: platforms that deploy often and have money on the other side of every form. The method applies to any web-facing business.

How do we start?

Book an intro call from the home page. If it makes sense, you receive the Rules of Engagement to sign; once signed, the first run can start within a day.

Want to know what your surface looks like from outside?

An intro call, no commitment. If it makes sense, you receive the Rules of Engagement — nothing is tested before you sign.

Book an intro call