Authorized testing platform
Authorized AI security / Live evidence

AI penetration testing
with proof.
Not more noise.

Continuous security testing for websites, APIs, Android apps, codebases, and servers—run by six specialist agents while you control every boundary and inspect every finding.

Checking access See the boundary
Ownership verified Work visible live Evidence attached
Voxy logo
Health92 logo
Kiind logo
Nohsis logo
Trivoh logo
Rodos College logo
Specialist clock / 06 online

Not one AI guessing.
A team finding.

Every six seconds the specialist clock advances. The agent arriving at the right-side live slot takes over the evidence brief.

02 / WEB Live view

RIGHT-SIDE LIVE SLOT / AUTO CYCLE 06S

Axel

Black-box testing

Drives a real browser across your web app and returns evidence for every finding.

Evidence
Replayable browser evidence
Operating mode
Human checkpoints
Axel / Security-agent evaluation

Measured where security agents matter.
CyberGym only.

One security benchmark keeps the comparison direct: the published CyberGym score for each listed runtime, presented on the same scale.

  • 02

    Claude Fable 5

    General-purpose model · fallback enabled

    83.8/ 100
    PROMINENT USEGeneral-purpose reasoning
    Web executionTooling required
    EvidenceResponse context
    BoundaryPrompt boundary
    RemediationSuggested remediation
  • 03

    GPT-5.6 Sol

    General-purpose model

    83.6/ 100
    PROMINENT USEGeneral-purpose agentic work
    Web executionTooling required
    EvidenceResponse context
    BoundaryPrompt boundary
    RemediationSuggested remediation
  • 04

    Claude Opus 4.8

    General-purpose model

    78.1/ 100
    PROMINENT USEGeneral-purpose analysis
    Web executionTooling required
    EvidenceResponse context
    BoundaryPrompt boundary
    RemediationSuggested remediation

CyberGym scores only. Higher is better. Product-layer tooling, authorization policies, and deployment settings are outside this benchmark.

Autonomy with a visible boundary

The agents move fast.
You hold the line.

Prove ownership before a scan starts. Watch the work. Approve anything that could cross the boundary.

CONTROL PLANE / RUN 7F2APOLICY ENFORCED
01

Ownership proved

Signed target scope accepted

02

Agents observed

Every action streamed live

03

Human checkpoint

Potential impact requires you

04

Audit sealed

Decision and evidence linked

policy://active-scanPause before impactimmutable log 184/184
01

Ownership first

No active testing begins until the target is verified.

02

Human checkpoints

Potentially disruptive actions pause for your explicit approval.

03

Rate limited

Every run stays inside controlled request and concurrency ceilings.

04

Traceable by design

Actions, decisions, evidence, and findings stay connected.

Signed authorization Controlled rate limits Safe expiry Traceable decisions
Live catalog / No surprise tiers

Start with Nova.
Scale when evidence asks.

Four passive reconnaissance checks are included every month. Deeper specialists unlock when your scope needs them.

CATALOG STATE DATABASE SYNCEDUSD · monthly · credits reset each cycle
01FREE

Free

Essential reconnaissance for getting started.

$0/month
  • 4 credits each month
  • 1 project
  • Nova passive reconnaissance
  • Community support
4credits1projects1concurrent
Start with Nova
02STARTER

Starter

A practical toolkit for shipping teams.

$19/month
  • 12 credits each month
  • All specialist agents
  • 2 targets per project
  • Email support
12credits1projects1concurrent
Choose Starter
04BUSINESS

Business

Higher capacity and control for security teams.

$149/month
  • 100 credits each month
  • 10 active projects
  • 2 concurrent scans
  • Priority support
100credits10projects2concurrent
Choose Business

Failed agent runs are refunded automatically. Free is web-only and Nova-only; paid tiers unlock all specialist agents and scan depths.

Supported technology / Connected evidence

Systems your team
already ships.

Bring repositories, Android packages, web journeys, server context, and compatible evidence storage into one accountable workflow.

GitHubrepository intake
GitLabrepository intake
AndroidAPK analysis
Webbrowser evidence
Linuxserver review
S3 compatibleevidence storage
PROOF BEFORE PRAISETrust should be inspectable.
01

Every result linked

Requests, responses, screenshots, code paths, and decisions remain attached.

02

Authorization first

Ownership and scope are established before active testing begins.

03

Systems stay yours

Integrations support the workflow without being presented as endorsements.

Early-access voice / Presentation preview

What early security teams value.
Evidence they can act on.

These cards are illustrative early-access feedback used to demonstrate the review experience. Replace them with approved customer quotations before public attribution.

Share verified feedback
01Illustrative early-access feedback
The connected evidence trail turns a security conversation into work an engineering team can actually pick up.
S

Security lead

SaaS platform

02Illustrative early-access feedback
Visible boundaries and approval checkpoints make autonomous testing much easier to introduce responsibly.
E

Engineering manager

Financial technology

03Illustrative early-access feedback
Requests, browser actions, findings, and remediation context finally read as one continuous investigation.
A

AppSec engineer

Digital marketplace

04Illustrative early-access feedback
Specialist agents map more naturally to the work than another general-purpose security chat window.
P

Product CTO

Software studio

Illustrative presentation copy—not published customer endorsements. Identity and permission are required before attribution.

Human channel / Scope first

Set the boundary.
Then start the work.

Bring the target type, authorization context, and outcome you need. We will establish safe scope before active testing.

CONTACT BRIEFStraight to our inbox
Do not include passwords, tokens, exploit payloads, or personal data.