Kissaki Docs
Agentic web & API pentesting, documented.
Point Kissaki at an asset, prove you own it, and let bounded AI agents run a campaign with deterministic OSS tools. Every high finding comes with reproducible proof. Start below.
- Reproducible proof
- EU data residency
- Pull-request gating
Getting started
What Kissaki is, the proof-driven principles, and a five-minute first scan.
Concepts
Assets, ownership verification, findings and proof, campaigns, RoE and consent.
Guides
Onboard each asset kind, read and triage findings, gate pull requests, allow the scanner through your WAF.
API reference
Call the Kissaki API: assets, findings, reports and git integrations.
Trust & compliance
EU data residency, the hard guardrails, and why every high finding carries proof.