ZERODAY / PROPRIETARY OFFENSIVE TECHNOLOGY
OBSIDIAN
Autonomy, given a boundary.
01 / 05 · BOUNDARY
The target exists before the engine does.
Authorized assets, methods, exclusions, timing, and stop conditions define the space Obsidian may explore. The engine cannot widen that space for itself.
02 / 05 · DISCOVERY
It follows reach, not a checklist.
Obsidian maps endpoints, identities, and trust relationships, then reasons across separate signals to construct candidate attack paths inside the approved ROE.
03 / 05 · VALIDATION
Proof is deliberately small.
It attempts the minimum authorized proof needed to distinguish a reachable path from a theoretical possibility—without crossing the agreed proof boundary.
04 / 05 · EVIDENCE
What moves forward must be reproducible.
Evidence is preserved for technical review, remediation ownership, and retest. The aim is a defensible record, never spectacle.
05 / 05 · HUMAN RELEASE
The machine stops here.
Obsidian prepares the draft. A qualified person checks technical truth, business meaning, and the final deliverable before anything reaches the client.
WHAT IT IS
Obsidian is Zeroday's proprietary end-to-end autonomous offensive-security engine. Within an approved ROE, it performs reconnaissance, attack-path discovery, exploitation or validation, evidence capture, and draft reporting. Humans authorize scope, remain accountable, and approve deliverables.
It is not separately licensed.
ONE AUTHORIZED TARGET
Put the engine inside a real, accountable engagement.
The public route to Obsidian is Zeroday’s hybrid penetration-test engagement: written scope, approved Rules of Engagement, technical validation, and human-approved delivery.
Request the engagementOutcomes vary by target and scope. Obsidian is not separately licensed. A qualified human approves every client deliverable.