FAQs
FAQs
Frequently Asked Questions
Find clear answers about our design process, pricing, & creative collaboration approach.
General Questions
Learn more about Codexa, how the platform operates behind the scenes, and how it helps teams automate.
Can we control what OffensIQ tests?
Yes. You define the targets, credentials, exclusions, testing boundaries, and environment requirements before the test starts.
Can we control what OffensIQ tests?
Yes. You define the targets, credentials, exclusions, testing boundaries, and environment requirements before the test starts.
How is OffensIQ different from a traditional pentest?
A traditional pentest depends on manual work throughout the engagement. OffensIQ uses AI agents to run much of the workflow, which makes testing faster to launch and easier to repeat. People still control the scope and review the results.
How is OffensIQ different from a traditional pentest?
A traditional pentest depends on manual work throughout the engagement. OffensIQ uses AI agents to run much of the workflow, which makes testing faster to launch and easier to repeat. People still control the scope and review the results.
Can OffensIQ test authenticated areas?
Yes. You define targets, credentials, exclusions, testing boundaries, and safeguards before the run.
Can OffensIQ test authenticated areas?
Yes. You define targets, credentials, exclusions, testing boundaries, and safeguards before the run.
What does OffensIQ do?
OffensIQ uses AI agents to map web applications, test attack paths, validate exploitable vulnerabilities, and report evidence with remediation guidance.
What does OffensIQ do?
OffensIQ uses AI agents to map web applications, test attack paths, validate exploitable vulnerabilities, and report evidence with remediation guidance.
Is OffesnIQ a vulnerability scanner?
No. Scanners produce alerts that often need triage. OffensIQ follows application behavior and validates exploitability before reporting a finding.
Is OffesnIQ a vulnerability scanner?
No. Scanners produce alerts that often need triage. OffensIQ follows application behavior and validates exploitability before reporting a finding.
Can OffensIQ test production applications?
Yes. Testing stays within an approved scope using exclusions, rate limits, testing windows, and human review.
Can OffensIQ test production applications?
Yes. Testing stays within an approved scope using exclusions, rate limits, testing windows, and human review.
Does OffensIQ exploit vulnerabilities?
OffensIQ validates suspected vulnerabilities only within the approved scope and captures the evidence needed to fix them.
Does OffensIQ exploit vulnerabilities?
OffensIQ validates suspected vulnerabilities only within the approved scope and captures the evidence needed to fix them.
Is a human involved?
Yes. People define scope, safeguards, and approvals. AI agents perform the repetitive testing work.
Is a human involved?
Yes. People define scope, safeguards, and approvals. AI agents perform the repetitive testing work.
What can OffensIQ test today?
OffensIQ supports five assessment types: Web, API, Network, Mobile, and Cloud.
What can OffensIQ test today?
OffensIQ supports five assessment types: Web, API, Network, Mobile, and Cloud.
How long does a pentest take?
Under 15 hours
How long does a pentest take?
Under 15 hours
Setup & Installation
Everything you need to get Codexa installed, configured, and running smoothly.
How do I install Codexa?
Install the Python SDK (pip install codexa) or download the desktop app for macOS/Windows to manage workflows visually.
How do I install Codexa?
Install the Python SDK (pip install codexa) or download the desktop app for macOS/Windows to manage workflows visually.
What are the system requirements?
Codexa supports macOS 13+, Windows 11+, and modern Linux distributions for CLI/SDK usage.
What are the system requirements?
Codexa supports macOS 13+, Windows 11+, and modern Linux distributions for CLI/SDK usage.
How do I deploy workflows to production?
Push workflows to the Codexa cloud or deploy the runtime to your own servers using Docker.
How do I deploy workflows to production?
Push workflows to the Codexa cloud or deploy the runtime to your own servers using Docker.
Can I connect external APIs or databases?
Yes — Codexa workflows can use any Python library to access APIs, storage, or databases.
Can I connect external APIs or databases?
Yes — Codexa workflows can use any Python library to access APIs, storage, or databases.
Does Codexa require Docker?
Not required, but recommended for self-hosting or isolated environment setup.
Does Codexa require Docker?
Not required, but recommended for self-hosting or isolated environment setup.
Is version control supported?
Yes, Codexa is fully Git-friendly. Your workflows remain plain Python files in your repository.
Is version control supported?
Yes, Codexa is fully Git-friendly. Your workflows remain plain Python files in your repository.
Workflows & Automation
Understand how to build, run, and optimize workflows using Codexa’s automation engine.
Who is OffensIQ built for?
Application security, security, engineering, and regulated teams that need faster, repeatable application pentesting.
Who is OffensIQ built for?
Application security, security, engineering, and regulated teams that need faster, repeatable application pentesting.
Does OffensIQ integrate with our security workflow?
Reports include evidence and remediation context. Available workflow integrations depend on the selected plan and implementation scope
Does OffensIQ integrate with our security workflow?
Reports include evidence and remediation context. Available workflow integrations depend on the selected plan and implementation scope
Which deployment options does OffensIQ support?
Dedicated SaaS, hybrid SaaS, and on-premises deployment are available. On-premises is Enterprise only.
Which deployment options does OffensIQ support?
Dedicated SaaS, hybrid SaaS, and on-premises deployment are available. On-premises is Enterprise only.
Does application data leave our environment?
It depends on deployment. SaaS data resides in the OffensIQ cloud; on-premises data and inference can stay inside your cloud VPC.
Does application data leave our environment?
It depends on deployment. SaaS data resides in the OffensIQ cloud; on-premises data and inference can stay inside your cloud VPC.
How does model inference work on premises?
In an on-premises setup, inference runs inside your cloud VPC, keeping prompts, outputs, application data, and findings in your infrastructure.
How does model inference work on premises?
In an on-premises setup, inference runs inside your cloud VPC, keeping prompts, outputs, application data, and findings in your infrastructure.
How does OffensIQ control AI-led testing?
Set scope, exclusions, rate limits, testing windows, approval points, and review rules before a test.
How does OffensIQ control AI-led testing?
Set scope, exclusions, rate limits, testing windows, approval points, and review rules before a test.
Can we limit what agents are allowed to test?
Yes. Define targets, domains, credentials, roles, excluded routes, testing intensity, and restricted actions.
Can we limit what agents are allowed to test?
Yes. Define targets, domains, credentials, roles, excluded routes, testing intensity, and restricted actions.
Can OffensIQ test production environments?
Yes. Configure an approved scope, exclusions, rate limits, testing windows, monitoring, and human review.
Can OffensIQ test production environments?
Yes. Configure an approved scope, exclusions, rate limits, testing windows, monitoring, and human review.
How does OffensIQ handle test credentials?
Credentials are used only for approved authenticated workflows. Storage and access controls depend on deployment requirements.
How does OffensIQ handle test credentials?
Credentials are used only for approved authenticated workflows. Storage and access controls depend on deployment requirements.
Can we see what agents are doing?
Yes. Review activity across discovery, mapping, testing, validation, and reporting.
Can we see what agents are doing?
Yes. Review activity across discovery, mapping, testing, validation, and reporting.
Billing & Plans
Find answers about pricing, subscriptions, upgrades, and payment options.
How many credits does a small application use?
An application with up to 30 pages typically uses about 30 credits. Complexity can change the final amount.
How many credits does a small application use?
An application with up to 30 pages typically uses about 30 credits. Complexity can change the final amount.
Can you confirm the exact credit use before a pentest?
We can estimate usage after reviewing size, scope, and complexity. Final use depends on what agents discover and validate.
Can you confirm the exact credit use before a pentest?
We can estimate usage after reviewing size, scope, and complexity. Final use depends on what agents discover and validate.
What affects credit use?
Application size, authenticated areas, roles, workflows, forms, APIs, testing depth, and validation work.
What affects credit use?
Application size, authenticated areas, roles, workflows, forms, APIs, testing depth, and validation work.
Do rescans and fix validation use credits?
Yes. Focused retesting usually uses fewer credits than a full pentest.
Do rescans and fix validation use credits?
Yes. Focused retesting usually uses fewer credits than a full pentest.
Do custom testing requests use additional credits?
They can. We share an estimated credit range after reviewing the requested scope.
Do custom testing requests use additional credits?
They can. We share an estimated credit range after reviewing the requested scope.
When do credits expire?
Yes — you can add multiple members, assign roles, and manage seat-based billing from the dashboard.
When do credits expire?
Yes — you can add multiple members, assign roles, and manage seat-based billing from the dashboard.
What happens if a pentest stops before completion?
If an OffensIQ issue stops the run, unused credits are restored. Other interruptions are reviewed before restart.
What happens if a pentest stops before completion?
If an OffensIQ issue stops the run, unused credits are restored. Other interruptions are reviewed before restart.
Can we buy more credits?
Yes. Buy additional credits or move to a larger annual allowance.
Can we buy more credits?
Yes. Buy additional credits or move to a larger annual allowance.
Can we use credits across applications?
Yes. Use plan credits across applications, pentests, rescans, and fix validation.
Can we use credits across applications?
Yes. Use plan credits across applications, pentests, rescans, and fix validation.
What if our application has more than 200 pages?
Applications over 200 pages are scoped separately based on structure, workflows, authentication, and testing depth.
What if our application has more than 200 pages?
Applications over 200 pages are scoped separately based on structure, workflows, authentication, and testing depth.