What we still need to verify : 3 points in this profile are not yet confirmed against vendor documentation.
- Integration list: partially confirmed, verify against vendor docs
- Which analysis types are included in which service level: confirm with vendor
- Open source components the vendor publishes and their current status: verify
Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.
What it does
Fluid Attacks sells continuous hacking rather than a scanner. The automated layer runs dynamic testing against deployed applications and static and composition analysis against source repositories, feeding findings into a central platform. The layer that defines the offering is human: a standing team of testers works the same targets on an ongoing basis rather than in a scheduled window, chasing the things automation does not reach, which in practice means authorization gaps, business logic abuse and chained exploitation paths.
Findings land in a shared platform where each one carries evidence, reproduction detail and a severity, and where developers and testers can argue about it in place. The platform also ships an agent that can break a build when policy defined vulnerabilities are present, which turns the finding queue into an enforced gate rather than a backlog. The vendor publishes some of its scanning components under open source licenses, so parts of the automated layer can be inspected.
Where it fits
This sits across the whole lifecycle rather than at one point. Repository analysis runs on commits, dynamic testing runs against deployed environments, the human team works continuously, and the build breaking agent enforces policy at release time. It is bought by organizations that want testing capability without hiring it, and it needs commitment: source access, environment access, credentials for multiple roles, and someone internally who will work the queue. Turning on the build gate before the existing backlog is under control will stop delivery, so sequencing matters.
Strengths
- Continuous human testing finds the vulnerability classes that automation structurally cannot, and does so between scheduled assessments rather than only during them.
- Static, dynamic and composition findings arrive in one queue rather than three separate tools.
- The build breaking agent makes policy real instead of advisory.
- Publishing parts of the tooling openly is unusual for a service vendor and allows some independent scrutiny.
Limitations
- Requires deep access to source, environments and credentials, which is a significant trust and onboarding decision.
- Output volume is high by design, and without internal ownership the queue grows faster than it is worked.
- The value is concentrated in the human component, so it depends on the assigned team and on the service level purchased.
- Enforcing a build gate on a legacy codebase is disruptive and needs a deliberate rollout.
Who it suits
Suited to organizations that want sustained testing coverage across several applications and have decided to buy the capability rather than build it, with enough engineering discipline to absorb continuous findings. Less appropriate for teams that only need a point in time report for compliance, or for organizations unwilling to grant a third party ongoing source and environment access.
Used Fluid Attacks? Recommend it under your own name and title.
Recommend this tool