Weekend MVP leaked every profile
RLS policies fixed in 2 hours. IDOR patched in one middleware line.
Authorized AI agents test your web app like a real attacker — map vulnerabilities, validate findings, and get fix guides. First finding free.
Target
myapp.vercel.app
Ref
scan-a3f8c
› Initializing reconnaissance...
At a glance
Fast scans, deep coverage, findings you can trust
<30 min
Typical scan time
From URL to first findings
47+
Checks per endpoint
Auth, IDOR, injection & more
<10%
False positive target
Validated before your brief
02 · The problem
Verification skipped, sessions that never expire, reset tokens replayed — scaffolds don't catch logic flaws.
IDOR on user routes, Supabase RLS off, CORS wide open. One missing check exposes every record.
Keys in client JS, debug mode in prod, verbose errors leaking schema. Invisible until exploited.
03 · How it works
URL, ownership proof, and test credentials — scoped and encrypted.
Recon, auth, IDOR, API, injection — chained like a real attacker.
Example attack chain
Login
Auth bypass
/api/users
Endpoint found
IDOR
Vulnerability
Agents chain findings like a real attacker — leaked route → auth test → IDOR confirmed.
Severity-ranked findings with reproduction steps. First finding free.
04 · Product
app.aipentest.app/projects/acme
SECURITY POSTURE
78
● Critical 0
● High 2
● Medium 7
● Low 11
Last scan: 12 minutes ago · myapp.vercel.app
05 · Coverage
06 · AI engine
Maps pages, APIs, forms, and auth flows without manual configuration or agents to install.
Leaked endpoint → auth test → IDOR validation. Context-aware, not payload spam.
Independent verification before reporting. Target under 10% false positives at launch.
07 · Field reports
RLS policies fixed in 2 hours. IDOR patched in one middleware line.
Key rotated within the hour. Had been exposed for 4 months.
All fixes deployed in 3 hours. Burn rate from key abuse stopped.
Unblocked $200K enterprise deal. Security review passed in 2 weeks.
07.1 · Comparison
| Criteria | Manual pentest | Traditional scanner | AIPentest |
|---|---|---|---|
| Cost | $15K–$50K | $500–$2K/mo | $99 unlock |
| Time to results | 2–4 weeks | Hours (noisy) | <30 min |
| False positives | Low | 40–60% | <10% target |
| Auth / IDOR testing | Yes | Rarely | Built-in |
| Developer fix guides | PDF report | CVE dump | AI + evidence |
08 · Pricing
Tier I
See your first vulnerability
Tier II
Unlock the complete report
Tier III
For teams shipping regularly
Preview
What you see after a free scan
✓ 37 endpoints discovered
✓ 8 API routes mapped
CRITICAL — Broken access control · /api/users/:id
HIGH — Missing rate limit on login[REDACTED]
MEDIUM — CSP header not configured[REDACTED]
3 more vulnerabilities detected. Unlock full brief — $99
09 · Security
DNS TXT, HTML meta tag, or .well-known verification before any active testing begins.
Never modifies your data, never writes to your database. Non-invasive by design.
Encrypted at rest with KMS. Passwords never enter LLM prompts — only scoped refs.
Isolated scan containers destroyed after completion. Your SaaS stays protected.
09.1 · FAQ
10 · Get started
First finding free · No credit card · Results in ~15 min