pr0h0
Security Tools

Boundary (AI Bug Bounty)

A self-hosted platform for running authorized web security assessments with AI agents kept inside strict, auditable guardrails.

Boundary is a self-hosted platform that explores a specific question: how can AI agents help with a security assessment without being handed the keys? The usual worry with autonomous tooling is that it does too much, drifts outside what was agreed, or leaves no clear record of what happened. Boundary is designed around the opposite principle.

The guiding rule is the model proposes, the platform decides. Before any work begins, the engagement scope is defined, reviewed for ambiguity, and frozen as an immutable policy snapshot. From then on an agent can only suggest the next step; Boundary checks each suggestion against that approved scope and carries out the allowed ones through its own constrained gateway. Everything that is proposed, approved and performed is recorded, so the entire assessment can be audited afterwards.

It is intended strictly for systems the operator is explicitly authorized to assess, and the generated scope has to be reviewed and approved before anything runs. The project is really about governance and control for AI-assisted security work rather than about any single technique.

Key features

  • Scope defined and approved up front, stored as immutable policy snapshots
  • Every proposed step checked against the approved scope before it can run
  • A constrained execution gateway that the agents cannot bypass
  • Read-only source review from a Git or archive import
  • Pluggable agent runtimes, including a local deterministic mode and common agent CLIs and APIs
  • Evidence capture, finding review and report generation in one workflow
  • A full audit trail of what was proposed, approved and executed