Audits
An audit is one offensive engagement against a verified app. You choose a mode, review the targets, and Golem takes over.The modes
Shallow
Baseline scan + asset discovery + live probing. ~45 min.
Deep
Everything in shallow plus the LLM agent’s full attack chain. ~3.5 hrs.
Autonomous
Deep + your own mission brief. ~4 hrs. Plan-gated.
Mobile
Static + dynamic analysis for iOS and Android apps.
How an engagement runs
What every audit produces
- Findings — confirmed vulnerabilities with severity, evidence, and remediation. See Findings & Evidence.
- Security score — a 0–100 score and letter grade, with a full breakdown showing exactly which finding cost how many points. See Security Score.
- Coverage summary — every phase and technique attempted, with status (completed / partial / blocked / not applicable) and failures. See below.
- Markdown report — executive summary, scope and coverage, findings with evidence, remediation priorities. See Reports.
- PDF export — generate a branded PDF of the same report from the dashboard.
Security focus
Security focus areas tell Golem what matters most to you. Pick up to 8 per app (with a per-run override):
Focus areas are injected into the agent’s prompt for deep audits. Shallow scans don’t consume them. On mobile apps they shape the report emphasis.
Time budgets
Each mode has a fixed task budget; the agent is force-stopped before the wall-clock expires so the report always gets written:
Nuclei (post-agent) is capped to the remaining budget so it can never overrun the audit. Even on a forced stop you receive everything confirmed before the cutoff.
Audit statuses
Authorization
Next steps
Shallow Audits
The fast mode for frequent runs.
Deep Audits
The full phased attack chain.