Testing on behalf of your clients
If you deliver security testing, your ceiling is consultant hours. AIPTx takes the recurring, breadth-first work so your people spend their time where a person is genuinely irreplaceable.
If you are building a platform, the API is open and the findings come out as SARIF.
Consultancies, MSSPs and testing firms
Your clients want testing more often than your team can deliver it, and the work that fills the gap is the work your senior people find least interesting: recurring coverage, regression checking, the same OWASP categories across the same kinds of application.
AIPTx runs that continuously. Your team keeps the architectural review, the novel business logic, the client conversation and the judgement.
What you get
- Separation between client engagementsEach customer's data is logically isolated, with strict boundaries between tenants, so one client's assessment data is not reachable from another's.
- White-label reportingReports go out under your brand rather than ours. Available on the Enterprise plan.
- Multi-role authenticated testingSupply credentials, a session token or an SSO service account per role. The agent holds those sessions across the whole run, re-authenticates when they expire, and points each role at the others' data and actions, so you assess a client's application across every role rather than only the unauthenticated surface.
- Evidence on every validated findingA finding reaches confirmed status when the attack is performed, not when a version matched. Each one carries a proof_of_concept with the exact request, the response and a reproducible curl_command, which is what makes a report defensible in front of your client's engineers.
- Compliance mapping across seven frameworksPCI DSS, SOC 2, ISO 27001, HIPAA, GDPR, NIST and CIS, with gap analysis and retest history generated per run.
What it does not do
It will not replace your specialists, and we would not suggest it does. Novel business logic, social engineering, architectural review and anything needing client context still need a person. That is the point: it clears the ground so those hours go somewhere worthwhile.
Platforms embedding security testing
If you run a DevOps platform, a GRC tool or a cloud service and your users need security testing inside your workflow, the integration surface is already there.
REST API
Full access to scans, findings and reports. Several teams build their own view rather than using the dashboard, and the API supports that fully.
Webhooks
Scan events routed to any endpoint you nominate, for custom dashboards and internal tooling.
SARIF 2.1.0 output
Findings drop into anything that already reads SARIF (GitHub code scanning, GitLab, Azure DevOps) with no custom parser to maintain.
CI/CD reference integrations
GitHub Actions, GitLab CI and Jenkins, with pull request and merge triggers and severity-threshold build gating.
Consultants and advisers
If you work with organisations that need continuous security testing and you would rather recommend something than build it, tell us. Straightforward arrangement, no integration required.
Four reasons, honest about stage
The product does something specific
Validation by exploitation, multi-role access control testing, and risk weightings published at 40/30/20/10. Not a scanner with a new interface, and your technical clients will be able to tell the difference.
We are small enough to be responsive
You will deal with people who can change things. That is a genuine advantage of this stage, and it will not last forever.
We publish our limits
Our own product pages state what autonomous testing cannot do. You will not be put in front of a client with claims that fall over in the first technical question.
Your clients' data is separated properly
Multi-tenant architecture with strict boundaries and logical isolation between customers, and cross-tenant access control is a class of flaw we test for a living.
The limits of autonomous testing are set out in full on our autonomous testing page, and how we separate and protect customer data is on /security. Both are worth reading before you put your name next to ours.
There is no application form and no tiers to qualify for
Tell us what you do and what you are trying to build.
- 1Tell us about your practiceWhat you deliver, to whom, and where the constraint is.
- 2We will run through it with youTechnically, with someone who can answer. Not a qualification call.
- 3Trial it on a real engagementNot a demo environment. The fastest way to judge this is to point it at something that matters.
- 4Agree commercial terms that fitTerms built around what you are actually doing, rather than a tier you have to grow into.
Who you would be contracting with
Tell us what you have in mind
No tiers, no badges and no portal to log into. Just a conversation about what you deliver and whether this helps you deliver more of it.