Crossfyre
Distributed recon and verified vulnerability scanning.
- Recon runs across distributed nodes you control, orchestrated from one console.
- Operations are stateful and resumable; a dropped node does not lose the run.
- Adaptive rate limiting backs off and recovers based on how targets respond.
- It will not send payloads to a host outside the scan's scope. A form on the target that posts to another site is skipped, never sent a payload.
- It is built not to change the application it tests. A change-password form loses its password fields before it is injected, and a GraphQL field called deleteEverything is reported, not called.
- It is built not to send credentials to an AI model. Its AI triage and chat are switched off on crossfyre.io, and when they run, a credential it can recognize by name or format is replaced before anything is sent.


