AUTONOMOUS AI THREAT ASSEMBLY

Autonomous AI Penetration Testing That Starts Where an Attacker Does

It begins with no credentials and no source code — the outsider's view — mapping what your estate exposes and testing what that reaches. Grant code, cloud and identity access and it goes deeper. Either way, a finding ships only with evidence behind it.

17Specialist agents
8Assessment modes
E0-E4Evidence tiers
6Deployment models
SCOPE AND LIMITS

What Autonomous AI Penetration Testing Is, and What It Is Not

Every assessment is authorized, scoped and non-destructive. AATA proves risk without weaponising it, and reports findings rather than certifying a system. Consoles shown on this page are illustrations with sample data.

Verifynever weaponised against production
Provea model's confidence is not evidence
Scopedauthorized in writing before any test
Assessfindings and evidence, not certification
Reportnothing leaves your organisation
HOW IT GETS IN

Eight Ways In, Starting With No Access at All

How much context you supply changes what can be proven and what is allowed to run. The first two modes need nothing from you but written permission.

Passive external

Publicly observable data only. What your estate leaks to anyone looking, with no interaction beyond ordinary retrieval.

Black-box

No credentials, no code. Authorized testing of your external attack surface exactly as an outsider would reach it.

Gray-box

A constrained test account. Authenticated workflows, tenant boundaries and the paths a low-privilege user could take.

White-box

Code, cloud, identity and configuration. Deep design and implementation review through read-only connectors.

Smart-contract fork

Code plus forked chain state. Invariant and economic simulation, where transactions execute only inside the fork.

Pre-production

Staging and synthetic data. Release assurance, where active testing is permitted within the agreed policy.

Continuous

Event integrations on approved assets. Incremental checks on every material change, escalating when risk moves.

Incident assist

A time-bound incident scope. Evidence correlation and containment advice, human-led, with no autonomous action.

THE RUN LIFECYCLE

From Signed Scope to Verified Fix, in Six Stages

The same path whether it runs once before a launch or on every merge. The first two stages happen before an agent touches anything.

1

1. Authorize the scope

The Scope Guardian resolves a machine-readable manifest: legal owner, included and excluded assets, permitted testing classes, rate limits and windows.

2

2. Map the estate from outside

The Asset Cartographer graphs domains, certificates, cloud accounts, identities and contracts. Change Intelligence isolates what moved since the last run.

3

3. Plan the mission

The Mission Planner splits the work into parallel workstreams, each with an agent, a model, a tool budget and a deadline. Restricted data can be pinned local.

4

4. Investigate in parallel

Specialists work their own paths across surface, code, cloud, contracts and money flows, publishing every observation to a shared evidence graph.

5

5. Challenge, then verify

The Adversarial Challenger argues against each hypothesis. Contradictory evidence blocks a finding even when several agents agree on it.

6

6. Route the fix, re-verify it

Findings are scored, routed to Jira, Linear, ServiceNow or Slack with an owner, and re-tested on the deployment that claims to have fixed them.

External attack surface

Domains, certificates, DNS, ports, services and cloud assets reconciled, including shadow infrastructure and impersonation.

Black-box and gray-box testing

Authorized testing of web, API, GraphQL and mobile backends: authentication, tenant boundaries and business logic.

White-box code review

Static and semantic analysis across repositories, with cross-repo data flow, secrets exposure and release deltas.

Cloud, container and identity

AWS, Azure and GCP posture, Kubernetes, and IAM graph analysis that surfaces privilege-escalation paths.

Smart contracts and protocols

Solidity, Vyper, Rust, Move and Cairo reviewed with symbolic execution, fuzzing and forked-chain simulation.

Exchange, custody and wallets

Hot, warm and cold architecture, MPC and HSM signing quorums, and the deposit, withdrawal and sweep flows.

DEX, router and liquidity logic

Router, pool, LP, hook and solver review, including MEV exposure, pricing paths and slippage handling.

Economic attack simulation

Oracle manipulability, flash-loan feasibility and liquidation paths modelled against real liquidity depth.

Ledger and payment integrity

Double-entry invariants, reconciliation, idempotency, retries and race conditions across the whole lifecycle.

Financial messaging

FIX, SWIFT, ISO 20022, ACH, RTP and open banking reviewed for integrity and entitlement enforcement.

Order, execution and settlement

Order entry, matching, margin, liquidation and settlement examined as one chain, not separate systems.

Fraud and AML controls

Rules, models, alerts and case flows exercised as live controls, to establish what actually gets through.

Change-triggered runs

A merge, deployment, IAM change, contract upgrade or signer rotation triggers a targeted reassessment.

Release gates

A build can be blocked on an unresolved critical finding, set per environment and per severity.

Fix verification

The original evidence is replayed against the new code before a finding is ever marked verified.

Regression detection

Proven attack paths are recomputed on every material change, so a reintroduction surfaces as a regression.

REFERENCE ARCHITECTURE

Four Planes, So Authorization and Execution Never Share a Boundary

Agents never talk to your systems directly. Authorization and orchestration sit in the control plane, the asset and evidence graphs sit in the data plane, and every tool, fork and browser harness runs in an execution plane that is destroyed when the mission ends.

Four-plane architecture: customer environment, control plane, security data plane and isolated execution plane

A misbehaving agent cannot widen its own scope, because the policy that binds it lives in a different plane and every outbound call passes an egress allowlist. Credentials are short-lived and issued per task, and every tool call is versioned and written to a tamper-evident ledger.

THE ASSEMBLY

Seventeen Specialist Agents, Not One General-Purpose Model

Each task routes to a specialist, and the specialists have to argue. Seven of the seventeen roles are shown here.

Scope Guardian
Authorization

Scope Guardian

Holds a veto over every active action. Enforces the authorization manifest, exclusions, rate limits, testing windows and stop conditions, and writes every refusal to the audit ledger.

1 of 7
INSIDE ONE RUN

Follow One Finding From Hypothesis to Verified Fix

A withdrawal endpoint re-checks the daily limit before applying it, leaving a window where two concurrent requests both pass. Here is how that becomes a finding, and how it stops being one.

Authorization first before anything runs

The run starts against a manifest, not a target list: who authorized it, what is in scope, what is explicitly out, and which classes of testing are permitted in each.

  • Legal owner and authorizing party, with an expiry date
  • Excluded routes, data classes and third-party assets named
  • Rate, concurrency and spend caps applied per target
  • Testing windows enforced, not advisory
Rules of engagement manifest showing included scope, exclusions, rate limits and testing windows
EVIDENCE, NOT CONFIDENCE

Why a Model Saying So Is Not a Finding

Agreement between agents is useful and insufficient. Every claim carries an evidence tier, and contradictory evidence can block one that all of them believe.

icon
E0 is never publishedA model hypothesis with nothing behind it stays a hypothesis. It is never surfaced as a confirmed vulnerability, at any severity.
icon
E2 needs a deterministic resultA plausible code path is a candidate. Publishing it needs supporting tool output or a trace, with a confidence label attached.
icon
E4 is required for criticalA critical designation needs independent confirmations plus proof of impact. Nothing reaches a dashboard on one agent's opinion.
icon
Seven lifecycle statesHypothesis, observed, corroborated, validated, accepted, remediated, verified. State is a fact about evidence, not about age.
icon
Counterevidence outranks consensusA claim can be blocked by evidence contradicting it even when several agents repeat it. Agreement is recorded, never proof.
icon
Reproducible after the factFindings retain their inputs, tool versions and validation history, so a result can be re-derived months later in an audit.
See How Findings Are Scored
HOW IT COMPARES

Conventional Scanner, Single AI Assistant, or an Assembly

Three ways to look for the same vulnerability. A scanner is precise inside one domain and blind outside it. A single assistant reasons across domains with no mechanism to disprove itself.

#CapabilityConventional scannerSingle AI assistantAutonomous AI Threat Assembly
1Testing with no access at allSurface scanning onlyNeeds to be told the targetDiscovers, then validatesblack-box from one domain
2Deterministic security toolsStrong in one domainOften limitedOrchestrated across domainsversioned and sandboxed
3Cross-domain reasoningLowMedium to highHighgraph- and evidence-backed
4Independent verificationRule-dependentUsually weakChallenger and verifieras first-class agents
5Business and financial contextLimitedPrompt-dependentStructured and persistentcarried between runs
6Smart-contract economic analysisSpecialist tools onlyInconsistentDedicated agents and forksinvariant and economic simulation
7TradFi workflow expertiseLimitedGenericEncoded invariantsledger, settlement, entitlements
8Continuous change awarenessScan-basedUsually ad hocEvent-drivenincremental, risk-based
9Privacy and model choiceNot applicableProvider-dependentPolicy-based routinglocal, private or external
10Reproducible evidence lineageGood for tool outputOften weakEnd to endclaim through to evidence
11Enterprise workflow integrationVariesLimitedConnector and event platformticketing, SIEM, SOAR, GRC
12Authorization and safety policyProduct-specificOften informalMachine-enforcedScope Guardian holds a veto

Where a scanner still wins

Inside a narrow domain a good scanner is fast, cheap and deterministic. AATA runs several as tools rather than competing with them. What they cannot do is carry business context across a boundary.

Where a single assistant falls short

A frontier model reasons across domains well, and is confidently wrong at a rate no security programme can absorb. Without a challenger and deterministic corroboration, confidence is the only support.

What the assembly adds

Independent investigation paths, structured claims instead of a shared conversation, a challenger whose job is to disprove, and an evidence bar a finding must clear before anyone is paged.

INTEGRATIONS

It Connects to the Stack You Already Run

Read-only scopes by default, least privilege per connector, short-lived tokens and a kill switch on every connection. These are supported integration targets across source control, cloud, identity, security operations, chains and payment rails.

GitHub
GitLab
Bitbucket
Azure DevOps
Jenkins
Argo CD
Terraform
Kubernetes
AWS
Azure
Google Cloud
Cloudflare
Okta
Microsoft Entra ID
HashiCorp Vault
CrowdStrike
Splunk
Microsoft Sentinel
Datadog
Elastic
Wiz
Tenable
Snyk
Semgrep
CodeQL
Trivy
Burp Suite
Jira
Linear
ServiceNow
Slack
Microsoft Teams
PagerDuty
Vanta
Drata
Foundry
Hardhat
Tenderly
Etherscan
Chainlink
Fireblocks
Safe
Chainalysis
TRM Labs
Stripe
Plaid
SWIFT
ISO 20022
FIX
SARIF
CycloneDX
OpenTelemetry
BEFORE YOU AUTHORIZE

What Security Leaders Ask Before They Let It Run

Six questions that decide an autonomous testing evaluation, answered the way we would want them answered if it were our estate.

  • Will this take down production?Nothing is destructive by default. Rate caps, blackout windows and stop conditions are fields in the manifest, and the kill switch is immediate.
  • What happens the first time it is wrong?It is built to be wrong quietly. A tier E0 hypothesis is never published, and contradictory evidence blocks a finding several agents believe.
  • Do we lose control of what gets tested?Windows, excluded routes, excluded data classes and an expiry date are manifest fields. Production-impacting actions sit behind human approval.
  • Does this replace our auditors?No. AATA produces findings and evidence; certification is the work of accredited auditors. It holds coverage between their engagements.
  • How do we know the coverage is real?Every run records what was assessed, what was skipped and why, and which tools and model versions ran. Gaps are named rather than implied.
  • What if it is wrong about scope?Scope is the one thing not left to a model. The Scope Guardian holds a veto over every active action and writes its decisions to an audit ledger.
Talk to a Security Engineer
BUILT FOR

Teams Whose Failure Mode Is Measured in Funds, Not Downtime

Built for organisations where a security failure moves money, breaks a regulated obligation, or ends a protocol.

Protocol and contract teams

Invariants, exploit paths and funds at risk before a launch or an upgrade, not after the governance vote.

Exchange and custody operators

Withdrawal flows, signing quorums, listing pipelines and reconciliation reviewed as one chain.

Banks, fintechs and payment firms

Ledger invariants, entitlements and settlement controls tested against the workflows a regulator asks about.

Cloud-native and AI product teams

Code, cloud, identity and supply chain in one graph, plus prompt injection on the AI features you ship.

AppSec and platform security

Continuous coverage between human engagements, so the next engagement starts from a known state.

Compliance, risk and audit

Control mapping, coverage history and evidence integrity, so an assessment produces the audit artefact.

WHERE TO GO NEXT

The Programmes and Systems This Connects To

Autonomous assessment is one layer of a security programme. These are the pages for the controls it tests and the operations it feeds.

Risk, security and compliance

The full programme: platform security, operational risk and regulatory duty as one stack rather than three.

Exchange security architecture

How a Coiny venue is built secure: key management, multi-tier custody, hardening and incident response.

Smart-contract security review

The human-led engagement: contract findings and DeFi risk assessment at a named commit.

Token due diligence

Listing reviews covering holder concentration, governance powers and treasury exposure.

AML, KYC and KYT

Identity verification, sanctions screening and transaction monitoring, with the decision trail.

Trade surveillance

Wash trading, spoofing and layering detection with alert replay, so controls can be evidenced.

Wallet and custody

MPC and HSM signing, quorum policy, address allowlists and the withdrawal path behind them.

Operations and reconciliation

Ledger-versus-chain reconciliation, investigation workflow and approval thresholds.

COMMON QUESTIONS

Autonomous AI Penetration Testing, Answered

Autonomous AI penetration testing uses coordinated AI agents to discover, investigate and validate security weaknesses without a person driving each step. Unlike a scanner it reasons about how a system works and chains issues into attack paths. Unlike a single model, every claim must be supported by reproducible evidence before it becomes a finding.

Yes. Passive external and black-box modes need no credentials and no source code. AATA works from what your estate exposes publicly, discovers assets you may not know you own, and tests the authorized external surface the way an outsider would reach it. Code, cloud and identity access is optional and adds depth rather than being the starting point.

It is non-destructive by default. AATA proves risk using static evidence, read-only queries, synthetic canaries, isolated reproductions, chain forks and staging environments rather than exploitation. Destructive testing, persistence, denial of service and production data modification are prohibited actions enforced by a dedicated Scope Guardian agent, not left to agent judgement.

Every claim moves through a lifecycle: hypothesis, observed, corroborated, validated, accepted. An Adversarial Challenger argues against it and an Evidence Verifier replays or independently corroborates it. Findings carry an evidence tier from E0 to E4, and a critical designation requires E4, meaning multiple independent confirmations plus proof of impact.

A machine-readable rules-of-engagement manifest defines the legal owner, included and excluded assets, permitted testing classes, rate limits, testing windows and blackout periods. Agents run in sandboxes behind egress allowlists with short-lived scoped credentials, and a kill switch stops a run immediately. No active test starts before that manifest resolves.

A one-time engagement describes a system as it was during one particular week. AATA reassesses on the events that actually change risk, such as a merge, a deployment, an IAM change, a contract upgrade or a signer rotation, and it re-verifies fixes. Human expertise is not replaced; the Managed Security Program adds analyst validation on top.

AI can review contract code, storage layout, access control, upgrade paths and economic assumptions, and can run fuzzing, symbolic execution and fork simulation far faster than a person. It does not replace an accredited audit. AATA produces findings, reproduction evidence and remediation, and re-verifies fixes. It does not issue audit certificates.

That is a routing decision you control. Every model version in the registry declares its data classification limit, permitted regions and retention policy, and policy can pin secrets, keys, personal data or regulated content to local or customer-hosted models. AATA also runs in your VPC, fully self-hosted, or as a clean room destroyed after the mission.

It generates the evidence and the mapping: authorization history, assessment coverage, tool and model versions, finding lifecycle, remediation results and control drift. Mappings include SOC 2, ISO 27001, NIST CSF and 800-53, PCI DSS, DORA, NIS2 and NYDFS. Certification itself remains a decision for your auditor.

START WITH A SCOPE

Scope an Authorized Assessment

Bring your architect and whoever owns the authorization. We agree the estate, the exclusions and the safety policy first, then run a baseline and walk the findings with the evidence attached.

Scope an Assessment