Glossary
Key terms used across the Maximus platform.
Application route
—Sidebar
Reference → Glossary
RolesAll
| Term | Definition |
|---|---|
| Engagement | Scoped penetration test effort with targets, findings, and canvas |
| Finding | Documented vulnerability with severity, evidence, and remediation state |
| Scan | Automated tool run (nmap, nuclei, etc.) against engagement targets |
| Canvas | Interactive diagram — defensive (threat modeler) or adversarial (pentest) |
| Maximus | In-product AI assistant with platform tool access |
| MCP | Model Context Protocol — IDE integration standard |
| Arsenal | Catalog of runnable security tools |
| Report Studio | AI-assisted narrative editor for pentest deliverables |
| Organization (org) | Isolated tenant — users, data, credentials, settings |
| Platform Admin | Cross-org administrator who can create tenants |
| STRIDE | Spoofing, Tampering, Repudiation, Info disclosure, DoS, Elevation — web threat methodology |
| MAESTRO | AI/agentic threat modeling methodology with KC layers |
| PM | Read-only stakeholder role |
| SME | Subject matter expert / operator role |
| Proof state | Adversarial testing status on canvas nodes |
| Kill chain | Attack path from entry point to objective |
| Trust zone | Boundary grouping components by trust level (trusted / semi-trusted / untrusted) |