Audits

An audit is one offensive engagement against a verified app. You choose a mode, review the targets, and Golem takes over.

The modes

Shallow

Baseline scan + asset discovery + live probing. ~45 min.

Deep

Everything in shallow plus the LLM agent’s full attack chain. ~3.5 hrs.

Autonomous

Deep + your own mission brief. ~4 hrs. Plan-gated.

Mobile

Static + dynamic analysis for iOS and Android apps.

How an engagement runs

You can watch the engagement live from the dashboard, and you get an email (and Slack message, if connected) when the audit completes or fails.

What every audit produces

  • Findings — confirmed vulnerabilities with severity, evidence, and remediation. See Findings & Evidence.
  • Security score — a 0–100 score and letter grade, with a full breakdown showing exactly which finding cost how many points. See Security Score.
  • Coverage summary — every phase and technique attempted, with status (completed / partial / blocked / not applicable) and failures. See below.
  • Markdown report — executive summary, scope and coverage, findings with evidence, remediation priorities. See Reports.
  • PDF export — generate a branded PDF of the same report from the dashboard.

Security focus

Security focus areas tell Golem what matters most to you. Pick up to 8 per app (with a per-run override): Focus areas are injected into the agent’s prompt for deep audits. Shallow scans don’t consume them. On mobile apps they shape the report emphasis.

Time budgets

Each mode has a fixed task budget; the agent is force-stopped before the wall-clock expires so the report always gets written: Nuclei (post-agent) is capped to the remaining budget so it can never overrun the audit. Even on a forced stop you receive everything confirmed before the cutoff.

Audit statuses

Authorization

Golem AI assumes every target you submit is authorized for full-scope offensive testing. Apps must pass ownership verification before any audit runs, and launching an audit requires accepting the authorized-testing terms with a signed attestation.

Next steps

Shallow Audits

The fast mode for frequent runs.

Deep Audits

The full phased attack chain.