AI Pentesting - Enterprise

Confirmed.
Not just flagged.

Active Testing tells you something looks exploitable. AI Pentesting proves it - sandboxed runs of sqlmap, dalfox, ffuf, nuclei, and jwt_tool attempt real exploitation against targets your scan already found, and every confirmed finding carries the exact request and response that proved it.

A fixed toolkit, not an AI improvising attacks

Five real tools. Every run is auditable.

Targets are derived from findings your scan already produced - reflected-input findings, discovered API endpoints, forced-browsing hits, crawled login forms and JWTs - never improvised by an LLM mid-scan. That's what makes informed consent meaningful and every run reproducible.

sqlmap

SQL injection

Every GET parameter and login/contact form your scan found gets tested for real SQL injection - not just a suspicious-looking pattern match.

dalfox

Cross-site scripting

Confirms reflected-input findings are actually exploitable XSS, with the exact payload and response that proved it.

ffuf

Hidden parameters

Fuzzes for undocumented parameters your scan wouldn't otherwise know to test - the ones a form or API never advertised.

nuclei

Exposure & misconfiguration

Deepens the exposures your scan already flagged, checking for known misconfiguration signatures a passive check can't confirm alone.

jwt_tool

JWT weak secrets

Offline cracking against any JWT-shaped token discovered while crawling - never a live tamper-and-replay attempt.

Real exploitation, safely contained

Sandboxed, scoped, and consent-gated.

Ephemeral, isolated sandboxes

Every run happens in a fresh Daytona sandbox, destroyed afterwards - nothing persists between scans or between customers.

Domain-scoped network egress

Each sandbox's network access is scoped to only the domain being tested - it cannot reach anything else, by construction, not just by policy.

Explicit, separate consent

AI Pentesting requires its own consent checkbox on top of Active Testing's - a deliberate second attestation, since this is real exploitation, not observation.

Scored and reported on its own

Independent from your main report and your DAST report.

Enterprise

AI Pentesting

Real exploitation-confirmation testing

Sandboxed runs of sqlmap (SQL injection, including login forms), dalfox (XSS), ffuf (hidden parameter discovery), nuclei (exposure & misconfiguration deepening), and jwt_tool (JWT weak-secret cracking) against targets your scan already flagged - a fixed toolkit, not an AI improvising attacks.

Enterprise

AI Pentesting

Proof-of-exploit evidence

Every confirmed finding carries the exact request and response that proved it, not just a plausible-looking signal - and results that were blocked or inconclusive (a WAF, a TLS handshake failure) are labelled as such rather than shown as a false clean or false positive.

Enterprise

AI Pentesting

Sandboxed, consent-gated testing

Each run happens in an ephemeral, isolated sandbox with network egress scoped to only the domain being tested. Requires its own explicit consent checkbox on top of Active Testing's - real exploitation attempts, not passive observation.

Enterprise

AI Pentesting

Independent Pentest Score

Computed only from confirmed pentest findings and shown alongside - never blended into - your overall security score and your Active Testing Score, so you can see exactly what real exploitation attempts found.

Enterprise

AI Pentesting

Standalone Pentest Report PDF

A dedicated, auditor-ready PDF scoped to pentest results only - proof-of-exploit evidence included - separate from both your main report and your DAST report.

Enterprise

AI Pentesting

Evidence package bundling

The Pentest Report PDF is bundled into the same audit evidence ZIP export as your main and DAST reports, ready to hand to an auditor without hunting down a third download.

Pricing

AI Pentesting ships on Enterprise.

Everything in Pro, plus Active Testing and AI Pentesting, at a fraction of what a manual pentest engagement costs.

Free

£0
  • 1-page scan per submission
  • All 8 scan layers
  • Vibe-coded platform security scan (Supabase, Lovable, Base44 & more)
  • AI executive summary
  • Scan history in your account
  • Re-scan and delete anytime
  • Shareable public link
  • Visual scoreboard dashboard
Create free account

Starter

Popular
£29/ month
  • Full AI agent investigation
  • Up to 50 pages per scan
  • Per-finding remediation guidance
  • Priority Remediation Plan (top fixes, AI-written, exportable PDF)
  • AI assistant chat
  • DNS & SSL/TLS security analysis
  • Subdomain takeover detection
  • Open port & service discovery for IP scans
  • PDF evidence export
  • Scheduled recurring scans
  • Scan comparison reports
  • Email alerts for new criticals
Get started

Pro

£79/ month
  • Everything in Starter
  • Up to 200 pages per scan
  • ISO 27001 / SOC2 / NIS2 / DORA control mapping
  • Remediation tracking
  • Team access and finding assignment
  • Slack and webhook notifications
  • API access
  • Audit evidence packages
  • Audit activity log
  • White-label PDF branding
Get started

Enterprise

Full DAST
£99/ month
  • Everything in Pro
  • Active Security Testing (DAST)
  • Independent Active Testing Score
  • AI Pentesting (exploitation-confirmation testing)
  • Forced browsing, CORS, reflected-input probes
  • API endpoint discovery & testing (REST, GraphQL, SOAP)
  • Authenticated scan mode (session capture)
  • Enable active testing via API / MCP
  • Priority support
Get started