Nothing gets reported until it has been exploited
Every candidate finding is now validated by replay before it reaches your queue. Unreproducible candidates are dropped rather than downgraded, which is what takes a scanner queue from thousands to dozens.
- Version
- 4.0
- Released
- January 31, 2026
- New features
- 3
- Category
- Accuracy
What's new
Features and improvements in this update
New features
3Validation replay before reporting
Each candidate is re-executed in isolation and the exploit outcome is checked against the expected effect. A finding that cannot be reproduced twice does not become a finding.
LLM-assisted triage with evidence grounding
Model-assisted analysis is constrained to the captured request, response and code context, and any claim it makes must be supported by that evidence. It ranks and explains; it does not decide that something is exploitable.
Suppression with recorded reasoning
Dropped candidates are retained with the reason they were dropped and re-evaluated when the relevant code or configuration changes, so a suppression is auditable rather than invisible.
Improvements
2Cross-scanner deduplication
The same issue found by SAST, DAST and dependency analysis is reported once, with all three pieces of evidence attached, instead of as three tickets for three teams.
Confidence surfaced on every finding
Where a finding is validated but context-dependent, the confidence and what it depends on are stated on the finding rather than left to be inferred from severity.
Benefits
What it changes for you
Stated as work removed rather than capability added, the only version of a benefit that can be checked.
A queue small enough to actually read
Customers moving from multi-scanner setups typically see reported findings fall by more than 90% while the count of genuinely exploitable issues goes up, because the real ones stop being buried.
Engineering trust, which is the scarce resource
One unreproducible finding costs more than it appears: it teaches the team that the queue is noise. Validating before reporting is how that trust is kept.
Defensible suppressions at audit time
An auditor asking why a known CVE is not in the remediation plan gets a recorded reason and the date it was last re-evaluated.
Upgrade
Getting it
Getting this update
Default behaviour from 4.0.0. Unvalidated candidates remain available through the API for teams that want to review them separately.
pip install --upgrade aiptxRelated
Other updates
Security testing that runs in the pull request
SARIF output, inline PR annotations and configurable merge blocking bring findings to the engineer who wrote the code, at the moment they can still change it cheaply.
ReadActive Directory and OSINT, in the same assessment
Internal path enumeration and external footprint discovery join the same engine, so the route from a leaked credential to a domain controller is one graph rather than two reports.
ReadBusiness logic testing, as a first-class scan type
Twenty-nine abuse patterns (race conditions, IDOR, price manipulation, workflow bypass) now run as their own scan phase, against the class of flaw that has no CVE and no signature.
ReadSee Your Attack Surface in Real-Time
Run a comprehensive VAPT assessment powered by advanced security tools. Get actionable findings in hours, not weeks. No credit card required.