SecurityBoat

TriNetra · Offensive Testing

Agents map the surface. Humans sign off on every finding.

A coordinated swarm of AI agents runs reconnaissance and exploit-chaining around the clock; certified human testers direct the work, review everything that surfaces, and sign off before anything reaches you as a finding. Same engagement lifecycle and dashboard as PTaaS — at a cadence a human-only team can't sustain.

Agent-Surfaced

Potential IDOR on /api/v2/statements/{id}

HIGH

Exposed .env in webpack source map

MEDIUM

Under Human Review

Refund-batch endpoint missing authz check

CRITICAL

Rohan Mehta · reviewing

GraphQL introspection enabled in production

MEDIUM

Confirmed

Public S3 bucket allows unauthenticated PUT

CRITICAL

Human Verified ✓

Dangling CNAME on partner-api subdomain

HIGH

Human Verified ✓


The problem

Attack surface grows faster than tester headcount. Double your assets and you need roughly double the tester-hours — but budgets and skilled-pentester availability don't scale that way, so testing frequency stalls exactly when release velocity, and risk, are climbing.

How Agentic Pentest answers it

Agentic Pentest changes the cost curve of frequency without changing who's accountable. The product frames this as two things at once — Attacker-Speed Coverage and AI-Native Engineering Resilience — with certified humans directing the swarm and validating every result before it counts.

How it actually works

Agents map. Humans sign off.

Live Recon maps endpoints around the clock; the Human Review Queue decides what ever becomes a finding.

Live Recon — swarm active

0 endpoints mapped

GET /api/v2/statements/{id}200 — mapped
POST /api/v2/refunds/batch403 — queued for review
fingerprint: nginx · React · GraphQLprofiled
chaining IDOR candidates on sequential ids6 / 40 reproduced

Around the clock, not on a scheduled scan window — humans direct where it digs next.

Scoped up front

Four fixed engagement tiers.

2 wks

Gap Assessment

A fast, focused read on one system — where most teams start.

4 wks

Focused Cycle

Deep coverage of a single product, sustained over a full cycle.

8 wks

Multi-System

Coordinated coverage across several applications at once.

12 wks

Full-Stack

Organization-wide surface, tested on a continuous rhythm.

Attacker-Speed Coverage

Agents work at the pace an actual attacker would — recon and exploit-chaining running continuously, not on a scheduled scan window.

AI-Native Engineering Resilience

Your engineering org gets tested at the rate it actually ships, not the rate a human-only team can staff.

The Sign-Off Log

FindingValidated byEvidence
Potential IDOR on /api/v2/statements/{id}HIGH · CVSS 8.2Certified human testerSequential-ID scan reproduced across 6 of 40 IDs before rate-limiting kicked in; confidence 0.82 via response-diff clustering.
Refund-batch approval endpoint missing authorization checkCRITICAL · CVSS 9.4Rohan MehtaReproduced against 3 batch IDs from the staging refund queue — the role check exists client-side only, not enforced at the service layer.
Public cloud storage bucket allows unauthenticated PUT requestsCRITICAL · CVSS 9.8Certified human testerConfirmed write access to a storefront CDN asset bucket with no auth header required; escalated for immediate fix.

Capabilities

What ships in the box.

Agent swarm, human command

Coordinated AI agents run recon and exploit-chaining across your scope continuously, always under the direction of certified human testers who decide where the swarm digs next.

Live Recon feed

Watch discovery happen in real time — endpoints mapped, technologies fingerprinted, entry points surfaced — with Endpoints Mapped and Active Agent Runs tracked live.

The Human Review Queue

A real kanban — Agent-Surfaced → Under Human Review → Confirmed — where only Confirmed items become findings you see.

The Sign-Off Log

An append-only record of who validated each finding, when, and on what evidence.

Four fixed engagement tiers

Gap Assessment, Focused Cycle, Multi-System, or Full-Stack — scoped by duration, not by guesswork.

Same rails as PTaaS

Findings land on the same live dashboard with the same CVSS scoring, remediation flow, and retest loop — one governed record of risk across human and agentic testing.

FAQ

Common questions.

They recon and chain exploit paths continuously under the direction of certified human testers. Nothing becomes a finding until it moves from Agent-Surfaced through Under Human Review to Confirmed in the queue — and every Confirmed finding is logged in the Sign-Off Log with who validated it and on what evidence.

Test at the speed you ship.

Tell us how fast your attack surface is growing. We'll show you what a swarm — with certified humans signing off on every result — can cover before your next release.

Related: PTaaS · Attack Surface Management · Ish · Continuous Testing