Buying both is normal
Continuous scanners and annual pentests cover different needs, so teams often pay for both. Neither one covers the other's gap.
Continuous AI penetration testing, reviewed by certified testers
Flagent Attest tests your infrastructure on a recurring schedule, confirms which findings are actually exploitable, and produces a signed report from an independent, certified tester. It's for teams that need ongoing testing and documentation they can hand to someone else.
The problem
Scanners are inexpensive and run often, but they only catch known patterns. A human pentest finds more, including issues that depend on context, but happens once a year. Most companies end up with both, and coverage still drops between tests.
Continuous scanners and annual pentests cover different needs, so teams often pay for both. Neither one covers the other's gap.
A test reflects a point in time. Anything shipped afterwards isn't covered until the next engagement.
Scanner output and one-off model results are hard to reproduce or pass on. Reproducible evidence matters when a finding is questioned.
How it works
We define the external, cloud, or internal assets in scope, along with testing windows and rules of engagement.
Recurring discovery and safe proof-of-exploitability checks, with additional runs when you deploy or a relevant CVE lands. Each run follows the agreed rules of engagement and writes an action log.
A qualified reviewer confirms, rejects, or escalates each AI-drafted finding. Anything higher-risk is authorised explicitly within the agreed window.
A named tester signs the report and evidence pack. You can share it, export structured evidence, and request a retest of the recorded attack chain after remediation.
Automation and review
Automated scanning covers known patterns. It misses business-logic and authorization flaws that only make sense in context, which is where testers spend their time. The signed report is written by a certified tester who is accountable for it.
Evidence and compliance
A signed report from an independent, certified tester, with testing that runs through the reporting period rather than on a single date. Confirm scope and expectations with your auditor.
PCI guidance expects human-led testing, with automation in support. A named, qualified tester performs the manual portion, and segmentation testing is available as its own engagement.
Map testing evidence to control A.8.8. What's required depends on your risk assessment and certification scope.
Testing for LLM application risks such as prompt injection, data disclosure, and excessive agency. Whether it applies depends on your system and use case.
Underwriting and security questionnaires often ask for evidence of independent testing. A signed report and a remediation trail help you answer; requirements vary by carrier.
Exports are built for the GRC tools teams already use, including Vanta and Drata. Confirm available integrations during onboarding.
The report
Every finding is confirmed before it's written up. The PDF is one view of the pack; the rest is structured for review.
Pricing
A monthly subscription for continuous coverage, with signed reports scoped separately. Retest terms are agreed before the engagement, and final pricing depends on your scope.
Recurring testing between signed reports.
Monthly subscription, scoped to your environment
A signed deliverable, scoped to your testing requirements.
Scoped quote, confirmed before testing starts
For teams onboarding now.
Contact us for availability
FAQ
No. Scanners are good at known patterns, such as outdated components, missing patches, and common misconfigurations. They miss business-logic flaws, authorization gaps, and issues that only appear when several problems are chained together, because those need someone who understands the application. Our AI handles the repetitive discovery and testers judge the rest.
Those products are run by your own team for continuous validation. Flagent adds an independent human review and a signed report. Whether you need signed third-party testing depends on your audit and risk requirements.
It depends on your framework, scope, and auditor. Flagent is built around independent human review and a named tester of record, with documented scope, rules of engagement, methodology, findings, and supporting evidence. It's worth agreeing the requirements with your auditor or QSA before testing. No provider can guarantee acceptance.
Before testing we document targets, permitted techniques, testing windows, escalation contacts, and prohibited actions. The scope allowlist is enforced at the tool-call boundary, each run is logged, and either side can stop testing. Production safety controls are confirmed during onboarding.
Between reports the AI keeps testing on the agreed schedule and on change events. The cadence and report schedule are agreed per engagement, and the signed report states the scope and period it covers.
Retest terms are agreed as part of the engagement. A retest replays the recorded attack chain after remediation, and the result is reviewed by a tester and added to the evidence.
You pay a monthly subscription for coverage, plus a fee per signed report. Final numbers depend on scope and test type, and we confirm them before work begins.
Tell us what you need tested. We'll confirm scope, timing, and terms before any testing begins.
We confirm scope and rules of engagement before testing starts.