AI penetration testing
that brings receipts.
Rift reads your source code, reasons from code to a real vulnerability, and confirms it against a running instance when you authorize one. Every finding is backed by concrete evidence and diffed against your last run.
Built to break things before an attacker does, for security teams across
Target figures from internal testing, shown to illustrate the model. Verified customer benchmarks publish at launch.
Web apps, tested from your source code.
Rift reasons from your source to a real, evidence-backed vulnerability, then confirms it against a running instance when you authorize one. Run it once for a compliance tick, or re-run on a cadence you control. External network testing is on the roadmap.
Web App Pentesting
Hand Rift your source and it reasons from code to a real vulnerability, mapping every route and auth flow and chaining bugs the way an attacker would. Authorize a running instance and it confirms them live.
- White-box, from your sourceRift reads your code for taint-aware depth. Point it at a running instance to confirm findings live.
- Business-logic, not just signaturesReasons about checkout, RBAC, and multi-step flows to find IDOR, auth bypass, and abuse.
- Every finding comes with evidenceEach finding ships with the exact code path, plus a working request and payload where live confirmation is authorized.
Network Pentesting
Not available yet. The plan: autonomous agents take your external perimeter the way an outsider would, enumerating the surface and proving the path in. Web application testing is what ships today.
- External perimeter, agent-drivenPlanned: enumerate subdomains, exposed services, and TLS posture from a seed, then pressure-test what's reachable.
- Attack-path proofPlanned: chain a low-severity exposure into demonstrated impact and hand you the path.
- External first, internal nextPlanned build order. Get on the early list and we'll bring you in as each lands.
A sample of what the loop surfaces, each backed by code evidence
Where SAST, DAST & pentesting
stop being separate tools.
Static scanners find suspects. Dynamic scanners make noise. Pentesters prove impact, once a year. Rift fuses all three into a single agentic loop you re-run whenever your code changes, so each run is measured against the last.
Read the code
Agents ingest your source, infra-as-code, and CI config, building a white-box model of where untrusted input can reach sensitive sinks.
Verified findings, every run.
Scanners flag suspects and flood you with noise. A yearly pentest proves impact, then goes stale by the next sprint. Rift reads the code, confirms what it can against a running instance, and ships only what's backed by evidence.
◐ partial / depends on tooling · ✓ native / built-in· swipe table →
Wired into how you already ship.
Rift respects your existing process instead of replacing it. It slots in beside your CI, your ticketing, and your humans.
Connect & scope
Connect a repo via our GitHub App or a GitLab token, set authorized scope and guardrails, and point live confirmation at a running instance you own. No agents to install.
Agents go to work
Rift reasons from your code and proposes findings; an independent review confirms each is well-supported before it reaches you. Where you authorize a live target, it fires a real request to confirm.
Route, fix, re-run
Verified findings flow to GitHub as draft remediation pull requests with reproduction steps. Re-run any time and Rift diffs against the last run, auto-resolving fixed findings and flagging new ones.
Priced by what you test.
Web app testing is scoped by application size. Pick a cadence: a one-off, an annual test for compliance, or a re-run subscription. Drag the sliders for an indicative estimate.
- ✓Evidence-backed findings
- ✓Low-noise, evidence-gated
- ✓SAST + DAST fusion
- ✓JSON, Markdown & SARIF reports
Indicative only. We'll confirm final scope with you directly.
Autonomous, not reckless.
An AI that writes real exploits needs real guardrails. Rift operates strictly inside authorized scope, throttles itself against production, and records every action it takes for full replay.
Scope-locked by design
Agents physically cannot act outside the assets and domains you authorize. Every target is verified before a single packet flies.
Safe-by-default exploitation
Proof-of-impact without the damage. It confirms a SQLi exists without dumping your database or altering state.
Full action replay
Every request, decision, and payload is logged. Hand your auditors a complete, reproducible trail of what ran and why.
Production-aware throttling
Rate-limits and quiet-hours respect live traffic, so a long-running scan never reads as a self-inflicted DoS.
The fine print, up front.
Your call. Run a single point-in-time engagement when you need a fast answer, run it on an annual cadence for compliance, or re-run on a cadence you control. Each run diffs against the last, auto-resolving fixed findings and flagging new ones. Automated deploy-triggered re-testing is on the roadmap.
Rift produces a verified-findings report (JSON, Markdown, or SARIF) plus a replayable action log of exactly what ran, which you can attach as the pentest evidence in a SOC 2, ISO 27001, or questionnaire process. It does not generate a signed attestation letter or a framework-mapped report today.
White-box. Rift reasons from your source code, so a repository (git URL or archive) is required to run. You can additionally point it at a running instance you own so it confirms findings live. Black-box testing from a URL alone is on the roadmap.
Web app testing is scoped by application size (routes and auth surface). Cadence (one-off, annual, or a re-run subscription) sets the multiplier, and the calculator above gives an indicative estimate. Network pentesting is on the roadmap and not yet priced.
Live confirmation is opt-in and off by default. When you enable it against a running instance you authorize, Rift is scope-locked to that target, exploits safely (proving a SQLi exists without dumping your database), and throttles itself against live traffic with quiet-hours so a long-running scan never reads as a self-inflicted DoS.
Scanners pattern-match and hand you a pile of maybes. Rift reasons from your code and gates every finding on concrete evidence and an independent review before it reaches you. Where you authorize a running instance, it fires a real request to confirm impact directly. What reaches you is evidence-backed and deduped, not a backlog of false positives.
Find your next breach
before someone else does.
Be first to point Rift at your codebase and your running app. Join early access and we'll bring you on the moment it's live.
Early access · No commitment · We'll reach out when it's ready