Trust

A pentest needs access. Here is what we do with it.

You are letting an agent probe your systems. This page is the short version of our security review, so your team can start it before the first call.

Scope

Agents go where you point them.

Targets you list
Each scan is pointed at the hosts and repositories in its scope.
Isolated runs
Each run executes in its own isolated environment.
Staging first
Most teams start on a staging environment and widen scope once they have seen the results.
Control

You can stop it, and it stops itself.

Hard spend caps
Caps per scan and per project are set before anything runs. A scan stops when it’s done or when it reaches its cap.
A stop button
Anyone on your team with access can end a run at any point.
Live visibility
Every action an agent takes is recorded and visible while the run is in progress.
Models and data

You decide which models see your code.

Model per scan
You pick the model for each scan.
No provider retention
Model traffic runs through our own gateway, under provider agreements that keep none of your data.
Covered by our DPA
Customer data is processed under our Data Processing Agreement.
Accounts

Your identity provider, your roles.

Single sign-on
Sign in through your own identity provider over OIDC.
An audit trail
Every scan, finding and fix is kept as a record you can export.
Book a call

See it on your own app.

Book a 30-minute call. Tell us how you test today, and we’ll show you what AI pentesting would look like for your team.

Book a call

Or write to the founders

Nicolas Berthiaume nicolas@alambic.ai

Jacob Bouchard jacob@alambic.ai