A pentest that never goes stale — and comes back to check your fix held.
You tell it what it may touch. It works that surface every day, shows you the way in rather than a list of maybes, and hands you the report your customer is asking for. Then, after you fix something, it attacks the same hole again — because "fixed" should mean it stopped working, not that someone closed a ticket.
Only what you authorise · Never destructive · You see the request that worked
Four steps, and three of them are ours.
You say what it may touch
List the hosts and URLs it is allowed near, and set a cap on how hard it may push. Everything else is off limits — enforced by the system, not by the agent behaving itself.
It goes looking, every day
It works your authorised surface the way an attacker would, continuously. Every single action is checked against your rules before it fires, so it cannot wander.
You get the report they asked for
A downloadable pentest report: what was found, how bad it is, and how to fix it — with the evidence attached to every entry, so nothing in it has to be taken on trust.
It attacks the same hole again
After you fix something, it comes back and tries it again. If it still works, you hear that from us — not from a customer, and not next year.
Safe by construction, not by promise.
An agent that tests your live systems has to be safe by design. Every action passes the same gate before it can fire — scope, budget, an absolute destructive ban, and the active-exploitation lock.
It can only touch what you list
An engagement reaches the targets you authorised and nothing else. Out of scope is blocked by the system before the request goes out — it does not depend on the agent being well behaved.
It proves, it never breaks
A pentest shows a weakness exists; it does not damage anything to make the point. Anything destructive is refused outright, in every mode, no matter who authorised it.
Real exploitation needs your signature
It will not attempt an actual break-in until you have explicitly allowed it and a named person has signed off on the limits. There are no surprises here.
One switch stops everything
Halt it instantly and a run in flight stops where it is. Nothing starts again while the switch is on.
You can show what it did, afterwards
The authorisation and every run are recorded in a signed log. If anyone ever asks what was tested and when, the answer is there and it cannot have been edited.
It leads with what actually reaches you
Issues are ordered by how far they get — a route to something that matters comes first, ahead of a long list sorted by a scanner's default severity.
It shows you the way in — or it says it is only a lead.
A scanner tells you a pattern looks risky. This one tries it, and only calls something proven when the attempt actually worked and it captured the exact request so you can run it yourself. Anything it could not demonstrate is reported as a lead and labelled as one — so you are never sent chasing a false alarm, and your report carries the proof for everything it does claim.
Reading your database through a form
SQL injection — proven with a harmless true/false question that reaches the database, without pulling out a single row of your data.
Running code in your users' browsers
Reflected and DOM XSS — the marker comes back in the page, or actually executes in a real headless browser for the client-side cases.
Making your server fetch things for them
SSRF, including the blind kind — a harmless fetch proves it, and where nothing comes back, an out-of-band callback does.
Letting any website read your users' data
A CORS misconfiguration — the server accepts an attacker's origin and sends logged-in responses with it.
Executing expressions on your server
Server-side template injection — an injected sum comes back calculated, which only happens if the server evaluated it.
Sending your users somewhere else
Open redirect and CRLF — a marker host in a redirect or header parameter lands in the real redirect the server sends.
Reading another customer's records
IDOR and broken object-level authorisation — one tenant's session returns another tenant's object on replay.
Benign by construction — canary probes and true/false differentials that extract no data and write nothing. Active exploitation runs only under an explicit, signed authorization.
The deliverable your customers ask for.
"Do you have a recent pentest?" — answer it with a signed, grounded VAPT report that regenerates continuously, never goes stale, and links every finding to its evidence. The agent verifies what detection found; active, exploitation-proven testing runs under an explicit, signed authorization.
Run your first engagement today.
Scope it, run it, get the report — with hard safety bounds and a kill-switch you control.