AI application penetration testing
Autonomous agents test your chatbots, agents and RAG endpoints against the OWASP LLM Top 10, mapped to MITRE ATLAS. Every finding carries a reproducible proof of concept — or it isn't reported.
The agent narrates what it tried, and what came back.
Nine things it could not prove never reach your queue. That is the whole difference.
10 / 10, and where each one maps.
OWASP LLM Top 10 — mapped to CVE · CWE · CVSS · MITRE ATLAS + PoCAll ten classes are in every test plan; each report says which were observed, which were exercised with no finding (not proof of absence), and which were not covered. The full traceability matrix — OWASP LLM 2025 → MITRE ATLAS → NIST AI RMF / ISO 42001 / EU AI Act Art. 15 — is in the docs.
Three documents, because three people need to read it.
Every engagement produces the same evidence in three shapes. Procurement gets something safe to forward. Engineering gets the reproduction steps. Your compliance platform gets JSON.
Letter of Attestation
One page, redacted by construction. Legal entity, test window, assessment type, severity counts, provider signature. No endpoints, no proof-of-concept, nothing an attacker could use. This is the document you send a customer who asked whether you pentest.
Full compliance report
Executive summary, rules of engagement and scope, severity distribution, every finding with its working reproduction, the framework cross-map, and a remediation roadmap phased by severity. For engineering and for auditors under NDA.
Machine-readable twin
The same report as JSON, control mappings included, so it lands in Vanta, Drata or Secureframe as evidence against a control instead of being re-typed by a human the week before an audit.
What we test to
The methodology the engagement follows and the report cites.
What findings map to
Every finding carries the control references your auditor already works from.
Those mappings are stated as evidence toward a control — never as a pass. We hold no certification of our own and we are not your auditor: a vendor that tells you it has certified you has told you something untrue. Reports are signed by the platform, and optionally counter-signed by a CREST/OSCP-certified reviewer. See what a report contains.
Priced per engagement, not per finding.
The complete estate scan — code, website, cloud, agents and services, with one pentest scan — is free, no card. After that an engagement is one assessment against one client target, with optional review by a CREST/OSCP-certified reviewer.
- 4 engagements / month included
- 1 analyst seat
- Unlimited client apps
- Working PoC on every finding
- Overage $399 / engagement
- 25 engagements / month included
- Up to 5 analyst seats
- Unlimited client apps
- White-label + co-brand option
- Overage $299 / engagement
- Unlimited seats
- SSO / SCIM, on-prem / BYO-key
- Dedicated success manager
- Engagement volume negotiated (50+ / month)
- Volume overage from $249 / engagement
Every tier’s per-engagement rate is lower than the tier below it — $399, then $299, then from $249. The more you run, the less each one costs, and a solo plan passes the Firm price at about 20 engagements a month. These plans assume a book of clients. If you are securing your own applications rather than clients’, the platform is quoted on the size of your estate instead — tell us what you run.