AI penetration testing
that brings receipts.

Rift reads your source code, reasons from code to a real vulnerability, and confirms it against a running instance when you authorize one. Every finding is backed by concrete evidence and diffed against your last run.

Evidence-backed findings Re-run any time, diffed vs last Reasons from your source code
rift · agent sessionDEMO
Your attack surface· move to probe

Built to break things before an attacker does, for security teams across

FintechHealthcareB2B SaaSMarketplacesInfrastructureAI platforms
0+
Findings surfaced in testing
0%
False-positive target
0 min
Median time-to-first-finding
0×
Cheaper than a manual retest

Target figures from internal testing, shown to illustrate the model. Verified customer benchmarks publish at launch.

// 01: Products

Web apps, tested from your source code.

Rift reasons from your source to a real, evidence-backed vulnerability, then confirms it against a running instance when you authorize one. Run it once for a compliance tick, or re-run on a cadence you control. External network testing is on the roadmap.

P-01Web Application Pentesting

Web App Pentesting

Hand Rift your source and it reasons from code to a real vulnerability, mapping every route and auth flow and chaining bugs the way an attacker would. Authorize a running instance and it confirms them live.

  • White-box, from your source
    Rift reads your code for taint-aware depth. Point it at a running instance to confirm findings live.
  • Business-logic, not just signatures
    Reasons about checkout, RBAC, and multi-step flows to find IDOR, auth bypass, and abuse.
  • Every finding comes with evidence
    Each finding ships with the exact code path, plus a working request and payload where live confirmation is authorized.
White-boxSource-firstLive-verifiedSAST+DAST
Pricing model
Scoped by application size
Explore Web
route coverage · acme-app214 mapped
GET/clean
POST/api/auth/loginhigh
GET/api/orders/{id}high
POST/api/checkoutclean
GET/admin/userscrit
PUT/api/profilemed
POST/trackcrit
GET/api/searchclean
2
critical
2
high
0
false pos.
P-02Network Pentesting · Roadmap

Network Pentesting

Not available yet. The plan: autonomous agents take your external perimeter the way an outsider would, enumerating the surface and proving the path in. Web application testing is what ships today.

  • External perimeter, agent-driven
    Planned: enumerate subdomains, exposed services, and TLS posture from a seed, then pressure-test what's reachable.
  • Attack-path proof
    Planned: chain a low-severity exposure into demonstrated impact and hand you the path.
  • External first, internal next
    Planned build order. Get on the early list and we'll bring you in as each lands.
RoadmapExternal firstInternal next
Pricing model
On the roadmap
Explore Network
external surface · 38 assetsprobing
vpn.acme-corp.com:443TLS 1.0, weak
mail.acme-corp.com:25open relay test
legacy.acme-corp.com:8080exposed admin
38
assets
1
critical
2
high
$90
/ asset

A sample of what the loop surfaces, each backed by code evidence

critCWE-89Blind SQLi → full DB read
highCWE-639IDOR exposes 1.2M records
highCWE-918SSRF to cloud metadata
medCWE-79Stored XSS in support inbox
critCWE-502Insecure deser → RCE
highCWE-287Auth bypass via JWT alg
medCWE-200Verbose errors leak stack
highCWE-352CSRF on funds transfer
critCWE-78OS command injection
medCWE-16Missing HSTS on api edge
critCWE-89Blind SQLi → full DB read
highCWE-639IDOR exposes 1.2M records
highCWE-918SSRF to cloud metadata
medCWE-79Stored XSS in support inbox
critCWE-502Insecure deser → RCE
highCWE-287Auth bypass via JWT alg
medCWE-200Verbose errors leak stack
highCWE-352CSRF on funds transfer
critCWE-78OS command injection
medCWE-16Missing HSTS on api edge
// 02: The Rift Loop

Where SAST, DAST & pentesting
stop being separate tools.

Static scanners find suspects. Dynamic scanners make noise. Pentesters prove impact, once a year. Rift fuses all three into a single agentic loop you re-run whenever your code changes, so each run is measured against the last.

One loopON DEMAND1SAST2DAST3EXPLOIT4TRIAGE5REMEDIATE
Stage 1 / 5

Read the code

Agents ingest your source, infra-as-code, and CI config, building a white-box model of where untrusted input can reach sensitive sinks.

// 03: Why it's different

Verified findings, every run.

Scanners flag suspects and flood you with noise. A yearly pentest proves impact, then goes stale by the next sprint. Rift reads the code, confirms what it can against a running instance, and ships only what's backed by evidence.

Capability
Legacy SAST
Legacy DAST
Annual pentest
Rift
Reads your source code
·
Tests the running app
·
Fires real exploits (opt-in)
·
·
Proof, not just a 'possible'
·
·
Evidence-gated findings
·
·
Business-logic & chained bugs
·
Diffs findings vs your last run
·
·
·
Re-verifies the fix
·
·
·
Routes into your workflow
·
Cost scales with what you test
·
·
·

◐ partial / depends on tooling · ✓ native / built-in· swipe table →

// 04: How it works

Wired into how you already ship.

Rift respects your existing process instead of replacing it. It slots in beside your CI, your ticketing, and your humans.

01Onboard

Connect & scope

Connect a repo via our GitHub App or a GitLab token, set authorized scope and guardrails, and point live confirmation at a running instance you own. No agents to install.

02Execute

Agents go to work

Rift reasons from your code and proposes findings; an independent review confirms each is well-supported before it reaches you. Where you authorize a live target, it fires a real request to confirm.

03Operate

Route, fix, re-run

Verified findings flow to GitHub as draft remediation pull requests with reproduction steps. Re-run any time and Rift diffs against the last run, auto-resolving fixed findings and flagging new ones.

GitHub AppGitLabSARIF exportMore planned
// 05: Pricing

Priced by what you test.

Web app testing is scoped by application size. Pick a cadence: a one-off, an annual test for compliance, or a re-run subscription. Drag the sliders for an indicative estimate.

Web AppNetwork · roadmap
Standard SaaS app
~120 routes3 auth flows
Est. engagement
$17,600
/ yr
  • Evidence-backed findings
  • Low-noise, evidence-gated
  • SAST + DAST fusion
  • JSON, Markdown & SARIF reports
Get early access

Indicative only. We'll confirm final scope with you directly.

Volume & portfolio discounts availableVerified-findings reports and a replayable action log on every planNeed enterprise scoping? Get early access
// 06: Trust & safety

Autonomous, not reckless.

An AI that writes real exploits needs real guardrails. Rift operates strictly inside authorized scope, throttles itself against production, and records every action it takes for full replay.

SOC 2 Type IIin progress
ISO 27001in progress
GDPRin progress

Scope-locked by design

Agents physically cannot act outside the assets and domains you authorize. Every target is verified before a single packet flies.

Safe-by-default exploitation

Proof-of-impact without the damage. It confirms a SQLi exists without dumping your database or altering state.

Full action replay

Every request, decision, and payload is logged. Hand your auditors a complete, reproducible trail of what ran and why.

Production-aware throttling

Rate-limits and quiet-hours respect live traffic, so a long-running scan never reads as a self-inflicted DoS.

// 07: Questions

The fine print, up front.

Your call. Run a single point-in-time engagement when you need a fast answer, run it on an annual cadence for compliance, or re-run on a cadence you control. Each run diffs against the last, auto-resolving fixed findings and flagging new ones. Automated deploy-triggered re-testing is on the roadmap.

Rift produces a verified-findings report (JSON, Markdown, or SARIF) plus a replayable action log of exactly what ran, which you can attach as the pentest evidence in a SOC 2, ISO 27001, or questionnaire process. It does not generate a signed attestation letter or a framework-mapped report today.

White-box. Rift reasons from your source code, so a repository (git URL or archive) is required to run. You can additionally point it at a running instance you own so it confirms findings live. Black-box testing from a URL alone is on the roadmap.

Web app testing is scoped by application size (routes and auth surface). Cadence (one-off, annual, or a re-run subscription) sets the multiplier, and the calculator above gives an indicative estimate. Network pentesting is on the roadmap and not yet priced.

Live confirmation is opt-in and off by default. When you enable it against a running instance you authorize, Rift is scope-locked to that target, exploits safely (proving a SQLi exists without dumping your database), and throttles itself against live traffic with quiet-hours so a long-running scan never reads as a self-inflicted DoS.

Scanners pattern-match and hand you a pile of maybes. Rift reasons from your code and gates every finding on concrete evidence and an independent review before it reaches you. Where you authorize a running instance, it fires a real request to confirm impact directly. What reaches you is evidence-backed and deduped, not a backlog of false positives.

Find your next breach
before someone else does.

Be first to point Rift at your codebase and your running app. Join early access and we'll bring you on the moment it's live.

Early access · No commitment · We'll reach out when it's ready