There is a growing wave of companies selling AI pentesting. Finding and comparing every vendor is tedious, so we made a list to help you.
Large Language Models (LLMs) have now gotten competent enough at performing security assessments, to the point where it is possible for them to carry one out without human supervision. Results vary based on the harness and platform, but there has been no shortage of development effort dedicated to autonomously discovering and exploiting vulnerabilities. If you've been running a bug bounty program, you've no doubt seen how most researchers now use AI to augment their efforts, resulting in a massive increase in incoming reports.
As rapidly improving AI raises the baseline for attackers and defenders alike, regular security testing matters more, not less. An ethical hacker may sit on a lower-priority finding until they find some way to escalate, in order to get a bigger bounty. A not-so-ethical hacker might beat them to the punch, or use the low-priority XSS or Open Redirect to run a phishing campaign using your brand. The days where a scanner was good enough are in the past, and the financial impact of a hack could be devastating.
Here is a list of vendors that, as of writing, provide AI pentesting services, with links to each one's pages for more information. If you need help evaluating them more comprehensively, we have a guide and a checklist that can help.
The main tools
| Tool | Sample report | Price | Access | Includes mobile | Autonomy |
|---|---|---|---|---|---|
| XBOW | Open | Quote† | Sales | No | Autonomous |
| Armadin1 | None | Quote | Sales | No | Autonomous |
| Horizon3 (NodeZero)1 | On request | $25k–42.5k/yr | Demo / AWS | No | Autonomous |
| Pentera1 | Open | Quote† | Sales | No | Autonomous |
| Novee | None | $100k/yr† | Sales / AWS | Android + iOS (extra) | Autonomous |
| RunSybil | Open | Quote | Sales | No2 | Autonomous |
| Terra Security | None | $5k–10k/mo† | Sales / AWS | No | Hybrid |
| FireCompass | None | Quote† | Hybrid | Yes3 | Autonomous |
| Escape | None | Quote | Sales | No | Autonomous |
| Aikido | Open | ~$4,000/test4 | Hybrid | No | Autonomous |
| Cobalt | None | Quote† | Sales | No5 | Hybrid |
| Equixly | None | €4,999/test | Hybrid | No | Autonomous |
| Hadrian | Open | from €3,000/test | Sales | No | Autonomous |
| Ostorlab | Open | $499 one-off | Self-serve | Android + iOS (incl.) | Autonomous |
| Astra | Open | $2,999/yr | Hybrid | Android + iOS (extra) | Autonomous |
| Strix | None | Free / $29/seat/mo | Open-source | No | Autonomous |
| Stingrai (Snipe) | Gated | $3,000/assessment | Sales | No | Autonomous |
| Haxact | Open | ~€700–750/test | Self-serve | Android (incl.) | Autonomous |
Scope, pricing and features as each vendor lists them, October 2026. Every tool here tests web apps and APIs; the “Includes mobile” column flags which also test a native mobile app. “Access” is how you start a test; “Quote” means no public price. “Sample report” is whether you can see a representative or redacted report without a sales call: Open = you can download it ungated; Gated = behind an email form; On request = shown only if you ask; None = not published. In “Includes mobile”, (incl.) = covered in the base price; (extra) = priced per extra app or target (Novee bills each app as a separate asset; Astra from $2,200/app). This market moves fast, so check the vendor’s own page before you buy.
1 Armadin, Horizon3 (NodeZero) and Pentera focus on internal-network and breach-simulation testing (including Active Directory) rather than application pentesting; they are included for completeness. Armadin’s site sits behind bot protection.
2 RunSybil tests the mobile API/backend, not the native app.
3 FireCompass tests mobile but does not specify Android vs iOS, nor break out its mobile pricing.
4 Aikido tests white-box from your source by default; a black-box test, the attacker’s view, costs extra.
5 Cobalt’s autonomous product covers web/API; its human pentesters also test mobile (Android + iOS), network and cloud.
† On pricing. Novee and Terra publish list prices on AWS Marketplace ($100,000/yr per app for Novee; $5,000–$10,000/month by scope for Terra; enterprise deals may differ). For the quote-only vendors, here is what buyers have reported. Cobalt: a median of about $30,000/yr across 194 purchases (Vendr), plus a promotional $3,500 autonomous test through end-2026. Pentera: around $120,000/yr for the full platform (a reseller’s figure, PeerSpot). XBOW: now usage-based, with earlier per-test tiers reported at ~$4,000–$8,000. FireCompass: the vendor states under $1,000 per app but publishes no list price. Armadin and RunSybil publish nothing and we found no credible figure. These are third-party or vendor-stated, not official quotes.
Others worth knowing
The list above covers the tools you are most likely to run into. The market is bigger than that, and moving fast; here are others we found, often newer or more specialised, each linked so you can look closer.
| Tool | Autonomy | Notes |
|---|---|---|
| TurboPentest | Autonomous | Self-serve from $99/target; also tests network & cloud; orchestrates open-source scanners under an agent layer. |
| Hacktron | Autonomous | Code-review first ($40/dev/mo); white-box only, pentest billed by usage. |
| Corgea | Autonomous | AI code scanner with a black-box pentest add-on ($4k–$8k per pentest). |
| MindFort | Autonomous | Self-serve ($199–$999/mo); opens fix PRs and re-tests. |
| Parameter | Autonomous | Broad scope (web, API, cloud, AI, Android); open sample report; quote-only. |
| OpenHack | Autonomous | Dev tiers $0–$100/mo (pentest gated); has real public CVEs. |
| Aptori | Autonomous | Runtime + code validation; API-focused; quote-only. |
| Penetrify | Autonomous | Transparent $100–$7,500/mo; open sample; claims mobile (unverified). |
| Penligent | Hybrid | Freemium ($39.92/mo Pro); orchestrates 200+ Kali tools. |
| Beagle Security | Autonomous | Self-serve ($99–$299/mo); web, API, GraphQL. |
| Plexicus | Hybrid | AI swarm with a human approval gate; also reviews source; quote-only. |
| ZeroThreat | Autonomous | Self-serve ($100/mo per target); REST/GraphQL/SOAP; strong SPA rendering. |
| Trident | Autonomous | Self-serve signup; also tests cloud; reviews every PR and answers in Slack. |
| Antigen | Hybrid | Nightly automated testing plus a monthly human red team. |
| Veria Labs | Autonomous | White-box, runs against staging; strong public bug-bounty record. |
How to choose
Pentests are expensive. Getting one that does not match your needs and requirements does not help you become more secure. Proper due diligence is needed to properly understand what each vendor is offering, and whether they are the best option for you. To help you decide, we have compiled a guide that goes into depth about what is important to consider when evaluating agentic pentest vendors, which comes with a scorecard to help you grade them.
Two things are worth watching for. Be wary of a vendor that leads with a benchmark score instead of a report you can read; public benchmarks are easy to game, and some of their challenges are broken. And when a vendor shows you a sample, check that it is a redacted real engagement. Most of the samples you can open above are runs against demo apps, which say little about how a tool handles a real one.
Where we fit
Haxact is around €700 to €750 per test, self-serve, with a working proof-of-exploit on every finding. The open redacted sample you can read right now comes from a real client engagement, published with their permission. We test web, APIs, and Android. We are not the cheapest, but we cost a fraction of a traditional pentest.
We hope the tables and our guides give you a clearer picture of the market and what to look for in a pentest vendor. If you think we might be a good fit, you can sign up and try the platform before you decide whether to pay for an engagement.
You can create a free account to look around, or for more. No obligation.