Offensive security
that never clocks off.

Rift deploys autonomous AI pentesters against your web apps and external network — finding, exploiting, and verifying real vulnerabilities continuously. No false-positive noise. No annual blind spots.

Exploit-verified findings Re-tests every deploy Human-grade reports
rift — agent sessionLIVE

Trusted to break things, quietly, for teams at

NORTHWINDLumen BankQuantleVault7 HealthApex LogisticsCirruspay
0+
Vulns exploited & proven
0%
False-positive SLA
0 min
Median time-to-first-finding
0×
Cheaper than a manual retest
// 01 — Solutions

Two surfaces. One adversary.

Each product is a standalone engagement — run it once for a compliance tick, or leave it armed for continuous coverage. Both share the same exploit-first brain.

P-01Web Application Pentesting

Web App Pentesting

Point Rift at a URL for black-box pressure, or hand it source for full white-box reach. It maps every route, walks every auth flow, and chains bugs the way a real attacker would.

  • White-box or grey/black-box
    Give it code for depth, or just a URL — it adapts its strategy to what you share.
  • Business-logic, not just signatures
    Reasons about checkout, RBAC, and multi-step flows to find IDOR, auth bypass, and abuse.
  • Every bug comes with a receipt
    A working request, payload, and impact note — verified, never a speculative 'possible' finding.
White-boxGrey-boxBlack-boxSAST+DAST
Pricing model
By application size — routes × auth surface
Explore Web
route coverage · acme-app214 mapped
GET/clean
POST/api/auth/loginhigh
GET/api/orders/{id}high
POST/api/checkoutclean
GET/admin/userscrit
PUT/api/profilemed
POST/trackcrit
GET/api/searchclean
2
critical
2
high
0
false pos.
P-02Network Pentesting

Network Pentesting

Autonomous agents take your external perimeter the way an outsider would: enumerate the surface, find the soft edge, and prove the path in — per asset, on repeat. Internal pentesting is coming next.

  • External perimeter, agent-driven
    Subdomains, exposed services, TLS posture, forgotten hosts — enumerated and pressure-tested.
  • Priced per asset
    Pay per subdomain or IP in scope, with unit costs that fall as your surface grows.
  • Continuous drift detection
    New asset appears at 2am? It's discovered, scoped, and tested before your standup.
ExternalContinuousInternal — soon
Pricing model
Per asset — per subdomain / IP in scope
Explore Network
external surface · 38 assetsprobing
vpn.acme-corp.com:443TLS 1.0 — weak
mail.acme-corp.com:25open relay test
legacy.acme-corp.com:8080exposed admin
38
assets
1
critical
2
high
$90
/ asset

A sample of what the loop surfaces — every one exploit-verified

critCWE-89Blind SQLi → full DB read
highCWE-639IDOR exposes 1.2M records
highCWE-918SSRF to cloud metadata
medCWE-79Stored XSS in support inbox
critCWE-502Insecure deser → RCE
highCWE-287Auth bypass via JWT alg
medCWE-200Verbose errors leak stack
highCWE-352CSRF on funds transfer
critCWE-78OS command injection
medCWE-16Missing HSTS on api edge
critCWE-89Blind SQLi → full DB read
highCWE-639IDOR exposes 1.2M records
highCWE-918SSRF to cloud metadata
medCWE-79Stored XSS in support inbox
critCWE-502Insecure deser → RCE
highCWE-287Auth bypass via JWT alg
medCWE-200Verbose errors leak stack
highCWE-352CSRF on funds transfer
critCWE-78OS command injection
medCWE-16Missing HSTS on api edge
// 02 — The Rift Loop

Where SAST, DAST & pentesting
stop being separate tools.

Static scanners find suspects. Dynamic scanners make noise. Pentesters prove impact — once a year. Rift fuses all three into a single agentic loop that runs every time your code or surface changes.

One loopALWAYS ON1SAST2DAST3EXPLOIT4TRIAGE5REMEDIATE
Stage 1 / 5

Read the code

Agents ingest your source, infra-as-code, and CI config — building a white-box model of where untrusted input can reach sensitive sinks.

// 03 — Why it's different

Three tools' jobs, one verdict.

Scanners flag suspects and flood you with noise. A yearly pentest proves impact — then goes stale by the next sprint. Rift does both, on every change.

Capability
Legacy SAST
Legacy DAST
Annual pentest
Rift
Reads your source code
Tests the running app
Writes & fires real exploits
Proof, not just a 'possible'
Near-zero false positives
Business-logic & chained bugs
Runs on every deploy
Re-verifies the fix
Routes into your tickets
Cost scales with surface

◐ partial / depends on tooling · ✓ native & automatic· swipe table →

// 04 — How it works

Wired into how you already ship.

Rift respects your existing process instead of replacing it — it slots in beside your CI, your ticketing, and your humans.

01Onboard

Connect & scope

Add a domain or a repo, define authorized scope, set guardrails. OAuth into GitHub, GitLab, or hand over a target URL. Two minutes, no agents to install.

02Execute

Agents go to work

Recon, reasoning, exploitation, verification — autonomously. The agent thinks like an attacker and only reports what it could actually prove.

03Operate

Route, fix, re-arm

Verified findings flow to Jira, GitHub, or Slack with reproduction steps. On the next deploy, the loop re-tests the fix and watches for new surface.

GitHubGitLabJiraLinearSlackServiceNowBurpAWSCloudflareWebhooksSARIF / CI
// 05 — Pricing

Pay for surface, not seats.

Web apps are priced by size. Network is priced per asset. Pick a cadence — one-off, annual for compliance, or always-on. Drag the sliders for a live estimate.

Standard SaaS app
~120 routes3 auth flows
Est. engagement
$17,600
/ yr
  • Verified, exploit-backed findings
  • Near-zero false-positive SLA
  • SAST + DAST fusion
  • SOC 2 / ISO-ready reports
Start for free

Indicative only — final scope confirmed in onboarding.

Volume & portfolio discounts availableCompliance attestation letters included on annual+Need enterprise scoping? Talk to us
// 06 — Trust & safety

Autonomous, not reckless.

An AI that writes real exploits needs real guardrails. Rift operates strictly inside authorized scope, throttles itself against production, and records every action it takes for full replay.

SOC 2 Type II
ISO 27001
GDPR

Scope-locked by design

Agents physically cannot act outside the assets and domains you authorize. Every target is verified before a single packet flies.

Safe-by-default exploitation

Proof-of-impact without the damage. It confirms a SQLi exists — it won't dump your database or alter state.

Full action replay

Every request, decision, and payload is logged. Hand your auditors a complete, reproducible trail of what ran and why.

Production-aware throttling

Rate-limits and quiet-hours respect live traffic, so a continuous scan never reads as a self-inflicted DoS.

// 07 — Questions

The fine print, up front.

Both — it's your call. Run a single point-in-time engagement when you need a fast answer, schedule an annual cadence for compliance, or leave the loop armed so it re-tests on every deploy. You can start one-off and switch to continuous without re-scoping.

Yes. Annual and continuous plans include attestation letters and auditor-ready reports mapped to the frameworks you care about. Every finding ships with reproduction steps and a full action log, so the trail stands up to review.

Either. Hand Rift your source and it runs white-box — reasoning from code to exploit. Give it just a URL and it works grey/black-box from the outside. Sharing code deepens coverage, but it's never required to get started.

Network pentesting is priced per asset — per subdomain or IP in scope — with unit costs that fall as your surface grows. Web app pentesting is priced by application size (routes and auth surface). Cadence (one-off, annual, continuous) sets the multiplier. The calculator above gives a live estimate.

It's built for it. Agents are scope-locked to assets you authorize, exploit safely (proving a SQLi exists without dumping your database), and throttle themselves against live traffic with quiet-hours so a continuous scan never reads as a self-inflicted DoS.

Scanners pattern-match and hand you a pile of maybes. Rift fuses static and dynamic analysis, then writes and fires a real exploit to confirm impact — so what reaches you is verified, deduped, and exploitable, not a backlog of false positives.

Find your next breach
before someone else does.

Spin up an autonomous pentest in minutes. Point it at one app, one domain, or your whole surface — and let the loop run.

No credit card to start · First findings in under 10 minutes