Continuous evidence between pen tests
A penetration test is a snapshot; your application changes every week after it. NightVision keeps evidence continuous between engagements, tied to the code that shipped.
Auditors ask what your posture is now, not the week of last year's test.
Between engagements most teams have no runtime evidence at all: the report goes stale while the application keeps shipping, and audit prep becomes a scramble to reconstruct the gap.
Compliance evidence, on a schedule
Runtime artifacts, not paperwork
Request-level findings retain HTTP evidence; where a curl replay is available, your team can validate the behavior and keep that result with the audit record.
Tied to the code that shipped
Scan artifacts can be associated with a code revision, and Code Traceback can add file and line context on supported source-discovered API scans. When the auditor asks about a release, you export the evidence for that release.
Coverage that includes the hard parts
Authenticated scanning with TOTP/MFA, and internal apps reached over the Smart Proxy: evidence for the estate that actually holds the sensitive data.
Built to work with your pen test, not replace it
Penetration tests deliver what automation cannot; NightVision's job is the other eleven months. The baseline stays continuously tested, and your testing partner starts from a current API inventory and scan history instead of rebuilding the map. The pen test gets deeper; the gap between pen tests stops being undocumented.
One evidence stream, whichever framework asks
SOC 2, PCI DSS, HIPAA, and internal audit programs ask for application security testing evidence in their own vocabulary. NightVision produces the underlying artifacts those requests are built on: scan history, findings with request and response evidence, and remediation records ending at the human-approved merge, all exportable and routable to Jira.
NightVision holds SOC 2 Type 2 (report available under NDA). The same discipline applies to your evidence: repeatable scans and retained artifacts.
Audit and compliance questions
Does NightVision replace our annual penetration test?
No. Penetration tests deliver human depth: business logic abuse, chained attacks, authorization design review. NightVision keeps runtime evidence continuous between those engagements, and your testers start from a current API inventory and scan history instead of rebuilding the map.
What evidence does a finding include?
Request-level findings retain HTTP evidence and, where supported, a curl replay; on supported API scans backed by source discovery, Code Traceback can add the file and line that defined the endpoint. Scan history and finding artifacts export for use in your audit evidence workflow.
Which compliance programs can use the evidence?
Teams commonly use NightVision scan evidence in SOC 2, PCI DSS, HIPAA, and internal audit programs. Auditor expectations vary by program and firm; NightVision produces the underlying runtime artifacts, tied to code revisions, that those requests are built on.
Can the evidence cover internal applications?
Yes. The Smart Proxy reaches applications on private networks without inbound firewall changes, and a Terraform module can deploy scanning inside your own AWS VPC, with the same authenticated scans and evidence as public apps. See private network scanning.
Is NightVision itself audited?
NightVision holds SOC 2 Type 2, with the report available under NDA.
Make audit prep an export, not a project.
Book a demo to see the evidence trail end to end, or start free and run your first authenticated scan.