AI penetration testing

Your app is live. Is it secure?

Authorized AI agents test your web app like a real attacker — map vulnerabilities, validate findings, and get fix guides. First finding free.

Credentials encrypted in vault — never sent to AI
scan-dossier.live
Running

Target

myapp.vercel.app

Ref

scan-a3f8c

Initializing reconnaissance...

First finding freeNo credit card~15 min results

At a glance

Fast scans, deep coverage, findings you can trust

<30 min

Typical scan time

From URL to first findings

47+

Checks per endpoint

Auth, IDOR, injection & more

<10%

False positive target

Validated before your brief

02 · The problem


Shipping fast is great. Shipping insecure isn't.

A

Auth flows fail quietly

Verification skipped, sessions that never expire, reset tokens replayed — scaffolds don't catch logic flaws.

B

APIs leak by default

IDOR on user routes, Supabase RLS off, CORS wide open. One missing check exposes every record.

C

Secrets hide in bundles

Keys in client JS, debug mode in prod, verbose errors leaking schema. Invisible until exploited.

03 · How it works


Three steps to a full security brief

01

Authorize

URL, ownership proof, and test credentials — scoped and encrypted.

02

Agents test

Recon, auth, IDOR, API, injection — chained like a real attacker.

Example attack chain

Login

Auth bypass

/api/users

Endpoint found

IDOR

Vulnerability

Agents chain findings like a real attacker — leaked route → auth test → IDOR confirmed.

03

Receive brief

Severity-ranked findings with reproduction steps. First finding free.

04 · Product


The report developers actually read

app.aipentest.app/projects/acme

SECURITY POSTURE

78

Critical 0

High 2

Medium 7

Low 11

Last scan: 12 minutes ago · myapp.vercel.app

Open live sample report →

05 · Coverage


Full-spectrum testing. Every endpoint.

06 · AI engine


Frontier agents. Evidence, not guesses.

Scan OrchestratorReconAuthAPIValidation Agent

Autonomous recon

Maps pages, APIs, forms, and auth flows without manual configuration or agents to install.

Chained reasoning

Leaked endpoint → auth test → IDOR validation. Context-aware, not payload spam.

Validated evidence

Independent verification before reporting. Target under 10% false positives at launch.

07 · Field reports


Real vulnerabilities in apps like yours

Next.js + Supabase8 min

Weekend MVP leaked every profile

RLS policies fixed in 2 hours. IDOR patched in one middleware line.

Bubble + Stripe12 min

Stripe secret key in frontend bundle

Key rotated within the hour. Had been exposed for 4 months.

FastAPI + React7 min

OpenAI key in response headers

All fixes deployed in 3 hours. Burn rate from key abuse stopped.

Node.js + PostgreSQL18 min

Multi-tenant isolation flaw

Unblocked $200K enterprise deal. Security review passed in 2 weeks.

07.1 · Comparison


Why teams choose AIPentest

CriteriaManual pentestTraditional scannerAIPentest
Cost$15K–$50K$500–$2K/mo$99 unlock
Time to results2–4 weeksHours (noisy)<30 min
False positivesLow40–60%<10% target
Auth / IDOR testingYesRarelyBuilt-in
Developer fix guidesPDF reportCVE dumpAI + evidence

08 · Pricing


First finding free. Full brief for $99.

Tier I

Free

$0

See your first vulnerability

  • 1 quick scan
  • First finding visible
  • Security grade
  • Basic A–F assessment
Begin free
Most popular

Tier II

Full brief

$99one-time

Unlock the complete report

  • All findings from scan
  • Full PDF brief
  • Attack surface map
  • Remediation steps
  • Evidence chain
Unlock report

Tier III

Developer

$29/month

For teams shipping regularly

  • 3 projects
  • 10 scans per month
  • AI fix guides
  • Scan history
  • Email support
Subscribe

Preview

What you see after a free scan

✓ 37 endpoints discovered

✓ 8 API routes mapped

CRITICAL — Broken access control · /api/users/:id

[REDACTED]

[REDACTED]

3 more vulnerabilities detected. Unlock full brief — $99

09 · Security


Safe by design. Authorized by you.

Authorization required

DNS TXT, HTML meta tag, or .well-known verification before any active testing begins.

Read-only testing

Never modifies your data, never writes to your database. Non-invasive by design.

Credential vault

Encrypted at rest with KMS. Passwords never enter LLM prompts — only scoped refs.

Ephemeral workers

Isolated scan containers destroyed after completion. Your SaaS stays protected.

09.1 · FAQ


Common questions

10 · Get started


Your users trust you.
Make sure you deserve it.

First finding free · No credit card · Results in ~15 min