The machine behind the loop.
Rift is autonomous penetration testing that reasons from your source code. When you authorize a live target it confirms findings by firing real requests, so here's how it reasons, proves, and stays on the rails, and how it all wires into the way you already ship.
One model, both sides of the wall
Rift's agents read your source to find the soft spot, then, when you authorize a running instance, drive it to prove the finding is reachable: static suspicion and runtime confirmation in one pass, not two disconnected tools. An agent only reports a finding once it survives an independent evidence review, so what reaches you is well-supported, not a maybe.
Explore, then verify
Separate agents discover and confirm. The one that finds a weakness isn't the one that decides it's real, so plausible-but-wrong findings don't survive.
Reasoning over pattern-matching
Agents build a model of your app and infrastructure and plan attacks against it, chaining steps the way a human operator would.
Evidence, always
Every finding carries the code path and evidence that proves it, plus the request, payload, and response where live confirmation is authorized. Every action is logged for full replay.
Target figures from internal testing, shown to illustrate the model. Verified customer benchmarks publish at launch.
SAST, DAST, and pentesting in one cycle
The same model that reads your code can drive a running instance you authorize and fire the request that proves the bug, then re-check the fix on your next run. Hover a stage to explore it.
Read the code
Agents ingest your source, infra-as-code, and CI config, building a white-box model of where untrusted input can reach sensitive sinks.
What's under the hood
Coordinator
Plans the engagement, allocates agents across your codebase, and keeps work within authorized scope.
Autonomous agents
Parallel reasoning and analysis agents that explore your code independently and hand off discoveries.
Attack runtime
An isolated, instrumented sandbox where exploit confirmations are built and fired safely against a target you authorize.
Validators
Independent review confirms a finding is well-supported before it reaches a human; where a live target is authorized, exploitability is confirmed directly.
Triage & dedupe
Findings scored on evidence, deduped against your last run, and stripped of noise.
Findings & intelligence
The report layer: evidence, reproduction, remediation guidance, and ticket routing.
Autonomous, not reckless
Scope-locked by design
Agents physically cannot act outside the assets and domains you authorize. Every target is verified before a single packet flies.
Safe-by-default exploitation
Proof-of-impact without the damage: it confirms a SQLi exists without dumping your database or altering state.
Production-aware throttling
Rate-limits and quiet-hours respect live traffic, so a long-running scan never reads as a self-inflicted DoS.
Wired into how you ship
Findings land in GitHub as draft remediation pull requests, or export as SARIF. More integrations are planned.
See the loop run on your own surface.
Get early access and we'll bring you on the moment Rift is ready.