// Platform

The machine behind the loop.

Rift is autonomous penetration testing that reasons from your source code. When you authorize a live target it confirms findings by firing real requests, so here's how it reasons, proves, and stays on the rails, and how it all wires into the way you already ship.

// Philosophy

One model, both sides of the wall

Rift's agents read your source to find the soft spot, then, when you authorize a running instance, drive it to prove the finding is reachable: static suspicion and runtime confirmation in one pass, not two disconnected tools. An agent only reports a finding once it survives an independent evidence review, so what reaches you is well-supported, not a maybe.

Explore, then verify

Separate agents discover and confirm. The one that finds a weakness isn't the one that decides it's real, so plausible-but-wrong findings don't survive.

Reasoning over pattern-matching

Agents build a model of your app and infrastructure and plan attacks against it, chaining steps the way a human operator would.

Evidence, always

Every finding carries the code path and evidence that proves it, plus the request, payload, and response where live confirmation is authorized. Every action is logged for full replay.

100%
Findings backed by evidence
0%
False-positive target
Every
Finding independently reviewed
Full
Replay log of every action

Target figures from internal testing, shown to illustrate the model. Verified customer benchmarks publish at launch.

// The loop

SAST, DAST, and pentesting in one cycle

The same model that reads your code can drive a running instance you authorize and fire the request that proves the bug, then re-check the fix on your next run. Hover a stage to explore it.

One loopON DEMAND1SAST2DAST3EXPLOIT4TRIAGE5REMEDIATE
Stage 1 / 5

Read the code

Agents ingest your source, infra-as-code, and CI config, building a white-box model of where untrusted input can reach sensitive sinks.

// Architecture

What's under the hood

Coordinator

Plans the engagement, allocates agents across your codebase, and keeps work within authorized scope.

Autonomous agents

Parallel reasoning and analysis agents that explore your code independently and hand off discoveries.

Attack runtime

An isolated, instrumented sandbox where exploit confirmations are built and fired safely against a target you authorize.

Validators

Independent review confirms a finding is well-supported before it reaches a human; where a live target is authorized, exploitability is confirmed directly.

Triage & dedupe

Findings scored on evidence, deduped against your last run, and stripped of noise.

Findings & intelligence

The report layer: evidence, reproduction, remediation guidance, and ticket routing.

// Guardrails

Autonomous, not reckless

01

Scope-locked by design

Agents physically cannot act outside the assets and domains you authorize. Every target is verified before a single packet flies.

02

Safe-by-default exploitation

Proof-of-impact without the damage: it confirms a SQLi exists without dumping your database or altering state.

03

Production-aware throttling

Rate-limits and quiet-hours respect live traffic, so a long-running scan never reads as a self-inflicted DoS.

// Integrations

Wired into how you ship

Findings land in GitHub as draft remediation pull requests, or export as SARIF. More integrations are planned.

GitHub AppGitLabSARIF exportMore planned

See the loop run on your own surface.

Get early access and we'll bring you on the moment Rift is ready.