A governance standard for autonomous penetration testing platforms. APTS defines what these systems need to do to operate safely, transparently, and within defined boundaries, whether delivered by vendors, operated as a service, or built in-house by enterprise security teams.
OWASP APTS is a governance standard for autonomous penetration testing platforms. It defines what these systems need to do to operate safely, transparently, and within defined boundaries.
APTS is not a testing methodology. It complements PTES, OWASP WSTG, and OSSTMM by addressing the problems unique to autonomous operation: scope enforcement, safe autonomy, manipulation resistance, and accountability.
At a Glance
173 tier-required requirements | 8 domains | 3 compliance tiers
Domains
Scope Enforcement (SE) — 26 requirements
Safety Controls (SC) — 20 requirements
Human Oversight (HO) — 19 requirements
Graduated Autonomy (AL) — 28 requirements
Auditability (AR) — 20 requirements
Manipulation Resistance (MR) — 23 requirements
Supply Chain Trust (TP) — 22 requirements
Reporting (RP) — 15 requirements
Compliance Tiers
Tier 1 - Foundation: 72 requirements. Minimum bar for responsible deployment.
Tier 2 - Verified: 157 cumulative. Full transparency and tamper-proof audit trails.
Tier 3 - Comprehensive: 173 cumulative. Highest assurance for critical infrastructure.