User Guide
Using SiegePoint
How to scope, authorize, run, and act on a SiegePoint engagement — for clients commissioning a test and partners delivering one.
SiegePoint is authorized offensive security: we test your environment the way a real attacker would, under a signed engagement, on a documented standards-based methodology. What sets it apart is the acceptance model — every engagement is measured against a pre-agreed Surrender Level, so "the test succeeded" is a contractual fact, not an opinion.
There are two service lines — Engagements (offensive testing) and Verify (detection validation) — delivered directly or white-labeled by a partner firm.
How to read this guide. SiegePoint is built out in stages. Every capability is tagged Live (usable now) or In build (documented ahead of release). The Build Status table below is the single source of truth.
Build Status
| Capability | Status | Notes |
|---|---|---|
| Methodology & Architecture Guide | Live | Published at /architecture-guide.html. |
| Acceptance / Surrender Levels | Live | Published at /surrender-levels.html. |
| Engagement templates | Live | Authorization, RoE, SOW, report skeleton — legal ones require your attorney & insurer review. |
| AI-assisted voice (vishing) simulation | Live | Dry-run by default; consented, allowlisted numbers only. |
| Client Portal | Live | Live at siegepoint.apintelligence.ai/portal over TLS, with role-based access (admin / scoped client), per-client engagement isolation, and a tamper-evident action audit log. See Client Portal. |
| SiegePoint Verify (detection validation) | In build | Service defined; engine & reporting being scaffolded. See Services, the Verify user guide, and the Verify architecture guide. |
| Mangonel (attack engine), methodology plugins & subscriptions | In build | Mangonel engine, registry, Authorization Gate + external-recon plugin built & self-tested (passive S0–S1), and wired into the portal — recon results land on the engagement. See How Engagements Run. |
| Partner / white-label program | In build | Model defined; onboarding being stood up. See Partners. |
Use the sidebar to move through the guide, or the Next link at the bottom of each page.