The Application Security Verification Standard defines verification requirements across chapters V1–V14, at three assurance levels — L1, L2, L3. Pentr verifies the requirements a penetration test can exercise and seals a real request/response proof for each one. Not a scanner's maybe — a captured, signed proof per requirement.
Each row is an ASVS chapter, the phase in the agent that exercises it, and the request/response artifacts the locker holds.
Agrees the routes in scope and the ASVS level to verify.
Fingerprints the stack, entry points, and configuration.
Derives abuse cases from the mapped attack surface.
Authentication and session weaknesses as req/resp.
Access control, injection, SSRF, and API abuse, proven.
Workflow abuse and state-machine violations chained.
sha-256 chain signed at seal time. Verifier-ready.
Point Pentr at a set of routes and pick a level. The agent verifies the requirements it can exercise across V1–V14 and seals a request/response proof for every one it confirms.