Platform

Pentesting · Prevent

An autonomous agent tests your public assets within the scope and the window you authorize. Every finding arrives with its evidence, its CWE and its OWASP category, and the report of each cycle is approved by an Axyom operator with their name and the date.

The free analysis is non-intrusive reconnaissance; the pentest is activated afterwards, with authorization.

What it is

A recurring pentest on your public surface.

A penetration test, or pentest, is an authorized exercise in which someone tries to get into your systems the way an attacker would, to prove with evidence what can really be exploited. A recurring pentest repeats that exercise every so often on the same scope, instead of delivering a snapshot once a year.

The practical difference is expiry. A consultancy's report describes one particular Tuesday, and that same month you deploy dozens of times, stand up a subdomain for a campaign and update libraries. Whoever asks you for proof — from the security questionnaire in the big contract to the investor's due diligence — wants it recent, and last year's report stretches the sales cycle or blocks it.

The cost of not having it is paid in two places. In the sale, when the buyer or their auditor makes signing conditional on a recent pentest and the one you have describes a scope that has already changed. And in your findings list, where the scanner flags exposure and nobody has tested which of those exposures really leads to your data.

3

safeguards checked before every run

What it is
A recurring pentest on your public surface, with an autonomous agent that executes and an Axyom operator who approves the report. The cycle repeats on the same authorized scope.
Who it is for
Companies of 10 to 250 employees with their own domain that are already being asked for a recent pentest by a customer, an auditor or an insurer.
Where it fits
Recurring pentesting comes with the Pro plan, and Max inherits it with a dedicated advisor. A one-off pentest can be contracted on any plan, with its scope and its window in writing.
What we need
The domain verified with a TXT record in your DNS, validation through your email domain or assignment by Axyom, and the scope in writing. No installed agents and no credentials to your applications.
Cadence
Recurring cycles on the same scope, inside the authorized window. Recurrence is configured per domain with its own schedule; without a schedule, you or Axyom launch the run from the portal.

What each cycle tests

The surfaces the agent tests under authorization.

Each cycle chains deterministic, repeatable reconnaissance with an agent that works on that material and tests concrete paths.

Subdomain discovery
Forgotten assets, pre-production environments and exposed services that do not appear in your inventory.
Exposed ports and services
What is exposed to the internet and which version it runs.
Technologies and versions
Components with known vulnerabilities and version leakage in headers.
Security headers
Missing or weak configuration, including the redirect to HTTPS.
Hidden paths and content
Panels, configuration files and copies reachable without authentication.
Injection points
Points where user input reaches an interpreter unchecked.
Access control
Resources reachable without the permission they should demand.
Information leakage
Technical or business data visible from outside, misconfigured CORS included.
Confirmed exploitation
What the agent manages to demonstrate, with the trace of how it did it.

The first rows come from deterministic reconnaissance, which repeats the same phases in every cycle so you can compare one cycle with the previous one. The last ones are tested by the agent on that material, with the request, the response and the reproduction steps documented.

Authorization

Authorization is checked before every request.

Three conditions have to hold at the same time; if any is missing, the run stays pending and no tool gets launched.

Engagement

Active engagement

The engagement exists, is tied to this domain and has not expired. Activating the module creates that formal authorization, with the assets in scope, the date window, the exclusions and the rate limits in writing.

Scope

Scope with assets

The list of what can be touched cannot be empty. Before each job, the assets in your scope are resolved to IPs and the host's firewall opens only those addresses; when it finishes they are removed.

Window

Window currently open

The start date has passed and the end date has not arrived. Outside that window the system schedules nothing, and the test host has all outbound traffic denied by default while no jobs are running.

Who approves the report

The report starts as a draft and moves through the In review, Approved and Sent states. An Axyom operator approves the report of each cycle, and their name and the date are recorded next to the document. The agent can only claim finding types declared in the catalog, and anything outside that list waits as a candidate in the curation queue.

What each cycle delivers

Three pieces that hold up in front of a third party.

01

The report

A branded, versioned, downloadable PDF with an executive summary, a score out of 100 and every finding mapped to its CWE and its OWASP Top 10 2021 category. Inside go the evidence, the remediation plan by severity and the scope and methodology annexes.

02

The living findings

Every finding enters your file with its score, its closing action and its detection history. When it shows up again in the next cycle it updates the same record instead of duplicating it, so you can prove what was closed and what is still open.

03

The proof of execution

The full transcript of the session and the agent's structured trace, plus the status of every tool with its result and its duration. It is what you show when the customer, the auditor or the insurer asks what was tested.

Sample finding record · Sample data

Finding
Local file inclusion
Severity
High · exploitation confirmed in the example
Mapping
CWE-98 · OWASP A03:2021 Injection
Evidence
Request sent, response observed and numbered reproduction steps
Action
Remediation plan with owner and follow-up
History
First detection, cycles in which it reappears and verified closure

Where it fits in the platform

Pentest findings go into the same file.

Pentest findings are scored with the same OWASP-based Axyom risk engine that orders the rest of your list, so a finding confirmed by the agent and one from the scanner can be read on the same scale. Severity is assigned according to the evidence and the risk engine. The score, the closing action and the evidence live in the platform's shared file, without exporting anything or keeping a separate list.

Limits

What this module does not do.

Check the scope before turning on the module and coordinate with your team the actions that fall to them.

Nothing outside the scope is touched

The host's firewall only opens for the addresses you have authorized, during the run, and closes when it ends.

No verified domain, no pentest

If ownership of the domain is not proven, the run is rejected before it is scheduled, and no tool gets launched.

Today it covers what is visible from the internet

It works on assets reachable from outside. No agents are installed on your machines and no credentials to your applications are used.

It does not replace a manual, scoped exercise

Long exercises with chained exploitation or social engineering are contracted separately, with their own scope and their own budget.

It does not schedule itself by default

Recurrence is configured per domain. Without a schedule, you or Axyom launch the run from the portal.

It fixes nothing on its own

It delivers findings, evidence and a prioritized plan. Your team owns each action, and the portal keeps count of what is closed.

The catalog decides what goes in the report

What does not fit the catalog waits as a candidate in the curation queue, and gets in only if an operator promotes it.

The free analysis is not a pentest

The pre-sales analysis runs non-intrusive reconnaissance and threat intelligence. Offensive testing starts once the engagement with its scope exists.

Plans

Recurring pentesting starts on the Pro plan.

Pro includes it and Max inherits it with a dedicated advisor. Free and Base let you see your surface with the external scanner and your up-to-date risk map, without offensive testing.

Free

To see your real risk before deciding anything.

€0

No cost · No card.

Everything to get looking:

  • Continuous scan External surface, 24/7
  • Posture and risk map Real-time CyberScore
  • Leaked credentials Counted, no detail
Start free

Base

For companies that want the whole platform without a security team of their own.

€190 / month

Self-serve · No commitment.

Everything in Free, plus:

  • Integrations Microsoft 365, Google Workspace and cloud
  • AI risk Apps with permissions over your data
  • Prioritized backlog Monthly remediation
  • 1 domain Continuously scanned
Get Base

Pro

For teams that need every sensor active and an expert behind it.

€990 / month

Advisor on escalation · No commitment.

Everything in Base, plus:

  • Security advisor On escalation, with SLA
  • Threat Intelligence Exposed credentials, under watch
  • Recurring pentesting Authenticated, report reviewed by Axyom
  • MDR 24/7 Up to 20 managed devices
  • Up to 5 domains All continuously scanned
Get Pro

Max

For high exposure or compliance demands.

€1,990 / month

Dedicated advisor · No commitment.

Everything in Pro, plus:

  • Dedicated security advisor A fixed person, monthly session
  • Priority response Incidents
  • Compliance by framework Downloadable evidence and attestation
  • Audit support Customer questionnaires and due diligence
Contact sales

FAQs.

Does this replace a manual pentest?

It does not replace it. This module covers your public surface with an agent that executes and a person who reviews, and its advantage is frequency: the cycle repeats instead of happening once a year. Long manual exercises, with deep chained exploitation or social engineering, are contracted separately and by scope.

Can it break something or take my website down?

Reconnaissance is declared non-destructive and audit-oriented, and the agent works under instructions that force it to stay inside the authorized scope. In the engagement you set exclusions and limits on requests and packets per second. The host only reaches the addresses in your scope while the run lasts.

How do I check it did not touch anything outside my scope?

The exercise keeps evidence of execution, assets and tests within the authorized scope. The reviewed report records the findings and the limitations. If an auditor needs additional documentation, Axyom reviews what evidence can be provided for that exercise.

Are the findings real or does the model make them up?

The agent can only claim finding types declared in the catalog; anything else is downgraded to candidate and waits in the curation queue. Severity is decided by Axyom's OWASP-based risk engine, and a demonstrated finding is never published below high.

What do you need from us to get started?

The verified domain and the scope in writing. Verification is done by publishing a TXT record in your DNS, validating your email domain or through assignment by Axyom. There is no need to install agents on your machines or hand over credentials to your applications.

Choose how to start.

On your own

Analyze your domain and start with your security posture. Then connect your systems and turn on the capabilities you need.

With our team

Tell us what you need to protect and which requirements you have. We will review the scope and the right plan with you.

Start now.