Driving efficiency in pentesting: new features live in Escape

Offensive security teams are covering more dev teams every quarter without their own headcount growing to match. Their roles continue to be forced into project management and firefighting instead of finding the vulnerabilities that get them speaking spots at conferences.

Our latest batch of features removes manual steps that eat away a security engineer's week. Waiting on a full re-run to confirm a fix, manually entering credentials into scan configs, zipping source code over Slack, or chasing a separate firm for a signature keep your team from doing their actual job. 

All four are generally available and live by default on October 7.

Here's what's new:

  1. Issue Retest:  prove a fix worked without running a full pentest
  2. Secrets vault integration: centralized credential across all your scan targets
  3. OSCP certification: certified sign-off on your pentest, from the same team that ran it
  4. GitHub whitebox integration: test the code where it lives

1. Issue Retest: prove the fix, skip the full re-run

Retest issues immediately

A developer tells you the issue is fixed. Now what? Until today, your options were to retest it by hand or kick off a full pentest to check one finding. Either way, the developer waits for confirmation, the company pays for a whole run, and you sift through two result sets just to compare A to B.

Issue Retest is an on-demand retest for one or more specific issues. Pick the findings that were patched, run the retest, and Escape re-runs only the tests needed to validate the fix.

What you get:

  • Confirmed fixes, fast. Know whether the patch resolved the issue, not whether someone believes it did.
  • Hours and budget back. Run only the tests you need instead of a full pentest.
  • A dashboard you can trust. Resolved issues close out, so what's open is what's actually open. 

2. Secrets vault integration: credentials that keep themselves current

Authenticated testing needs credentials and every scan target has its own. Today that means someone on your team manages each secret by hand, updates it every time it rotates, and copies it into the platform. Multiply that by every target and it adds up fast.

Escape now connects directly to secrets vaults to pull the latest secret every time a test is run.

What you get:

  • Less platform upkeep. The time you save scales with the number of secrets you manage: more targets, bigger payoff.
  • Safer secrets. No more copy-pasting credentials between tools.
  • One source of truth. A secret reused across targets updates everywhere at once.

3. OSCP certification: sign-off from the team that ran the test

Some regulations and internal policies require pentest results to be signed by an Offensive Security Certified Professional (OSCP). That has often meant bringing in a second firm just for the signature, meaning another contract, another handoff, and another calendar to wait on.

Escape on-staff OSCPs who can review and certify your pentest results. Once you order a certification, one of our OSCPs is assigned to your project, completes the assessment, and delivers the documentation you need.

What you get:

  • One partner, not two. We run the pentest and sign off on it.
  • Compliance without the detour. Meet OSCP sign-off requirements without sourcing a separate vendor.

4. GitHub whitebox integration: test the code where it lives

GitHub Whitebox configuration

Security teams continue to face more codebases, more versions, more places to keep track of. And for whitebox pentests, the workflow hasn't kept up: a developer zips the source code, sends it over, and a security engineer uploads it by hand.

The GitHub whitebox integration connects your GitHub repos directly to Escape. So, no zip files and no guessing which version you were sent.

What you get:

  • Faster pentests. Skip the zip-and-upload step entirely.
  • Safer code handling. Source code never has to be moved by hand.
  • Always current. Escape reads directly from GitHub, so repo updates show up as soon as you refresh.

Less busywork, more offensive security

Together, these new features take out the manual work that keeps pentesting stuck as a point-in-time exercise, freeing your team to spend its time finding and fixing real issues, not chasing confirmations, credentials, code, and signatures.

All four are live by default for Escape customers on October 8. Want to see them in action? Book a demo.