A managed fleet of intentionally-vulnerable apps (Juice Shop, DVWA, WebGoat, VAmPI, crAPI, faultline, and more) to point security scanners and recon tools at. One manager runs each target as its own isolated container stack, with per-app ground-truth vuln catalogs. Local testing only.