Continuous AI penetration testing, reviewed by certified testers

Continuous AI penetration testing.
Certified testers review and sign the findings.

Flagent Attest tests your infrastructure on a recurring schedule, confirms which findings are actually exploitable, and produces a signed report from an independent, certified tester. It's for teams that need ongoing testing and documentation they can hand to someone else.

  • CREST/OSCP-certified reviewers
  • Findings confirmed before reporting
  • Reproducible proof-of-concept
  • Retests available by agreement
Example signed report
Flagent Attest Signed
Penetration Test Report
Framework: SOC 2 Type IIReport № AT-2026-0917
  • Critical Tenant authz bypass via IDOR on /v2/account Retested & fixed
  • High JWT algorithm confusion on API gateway Verified fixed
  • Medium SSRF via webhook URL parameter Open · fix in progress
Weekly
default testing cycle
Every finding
reviewed by a certified tester before reporting
Named signer
the tester accountable for the report
Retests
available by agreement
Action log
a record of what was tested and when

The problem

Most teams buy two tools and still have gaps

Scanners are inexpensive and run often, but they only catch known patterns. A human pentest finds more, including issues that depend on context, but happens once a year. Most companies end up with both, and coverage still drops between tests.

Buying both is normal

Continuous scanners and annual pentests cover different needs, so teams often pay for both. Neither one covers the other's gap.

Coverage drops after each test

A test reflects a point in time. Anything shipped afterwards isn't covered until the next engagement.

Findings without evidence

Scanner output and one-off model results are hard to reproduce or pass on. Reproducible evidence matters when a finding is questioned.

How it works

From scope agreement to signed report

  1. 1

    Agree the scope

    We define the external, cloud, or internal assets in scope, along with testing windows and rules of engagement.

  2. 2

    AI tests on a schedule

    Recurring discovery and safe proof-of-exploitability checks, with additional runs when you deploy or a relevant CVE lands. Each run follows the agreed rules of engagement and writes an action log.

  3. 3

    Certified testers review

    A qualified reviewer confirms, rejects, or escalates each AI-drafted finding. Anything higher-risk is authorised explicitly within the agreed window.

  4. 4

    Sign, export, retest

    A named tester signs the report and evidence pack. You can share it, export structured evidence, and request a retest of the recorded attack chain after remediation.

Automation and review

AI does the repetitive work.
Certified testers decide what goes in the report.

Continuous AI coverage

  • Recurring attack-surface discovery and draft exploitation chains
  • Runs triggered by deploys, new assets, and critical CVEs
  • LLM application testing (OWASP LLM Top 10, EU AI Act Art. 55)
  • Recon, mapping, and first-pass triage that would otherwise be billed hourly

Independent human review

  • Business-logic, authorization, and chained issues that scanners miss
  • Findings reviewed against supporting proof-of-concept evidence
  • A named tester signs and is accountable for the report
  • Four-eyes review on critical findings; independence declared per engagement
  • Retests countersigned as verified fixed

Automated scanning covers known patterns. It misses business-logic and authorization flaws that only make sense in context, which is where testers spend their time. The signed report is written by a certified tester who is accountable for it.

Evidence and compliance

Mapped to the frameworks you report on

SOC 2 Type II

Human sign-off

A signed report from an independent, certified tester, with testing that runs through the reporting period rather than on a single date. Confirm scope and expectations with your auditor.

PCI DSS 4.0
11.3 / 11.4

Human-led

PCI guidance expects human-led testing, with automation in support. A named, qualified tester performs the manual portion, and segmentation testing is available as its own engagement.

ISO 27001

A.8.8

Map testing evidence to control A.8.8. What's required depends on your risk assessment and certification scope.

EU AI Act

Art. 55

Testing for LLM application risks such as prompt injection, data disclosure, and excessive agency. Whether it applies depends on your system and use case.

Cyber insurance underwriting

Evidence

Underwriting and security questionnaires often ask for evidence of independent testing. A signed report and a remediation trail help you answer; requirements vary by carrier.

GRC integration

Vanta · Drata

Exports are built for the GRC tools teams already use, including Vanta and Drata. Confirm available integrations during onboarding.

The report

What's in the evidence pack

Every finding is confirmed before it's written up. The PDF is one view of the pack; the rest is structured for review.

  • Statement of work, scope, and rules of engagement
  • Methodology: PTES, NIST SP 800-115, OWASP ASVS/WSTG
  • Named tester and certifications; independence declaration
  • Findings with reproducible proof-of-concept and remediation status
  • Countersigned retest confirmations and the AI action log
  • Verifiable signature and scope hash; OSCAL export
Request a scoping call
Auditor portal read-only, time-boxed
Attestation status
as of 2026-09-21
Provided frameworks
SOC 2 · PCI DSS · ISO 27001
Evidence pack
7 files
Tester of record
J. Alvarez · OSCP+ · CREST
Export OSCALVerify signatureScope hash

Pricing

Coverage, and signed reports.

A monthly subscription for continuous coverage, with signed reports scoped separately. Retest terms are agreed before the engagement, and final pricing depends on your scope.

Continuous coverage

Recurring testing between signed reports.

  • Recurring AI-assisted security testing
  • Additional runs on change, where configured
  • Attack-surface view and run history
  • LLM application testing available

Monthly subscription, scoped to your environment

Launch cohort

For teams onboarding now.

  • Scope and engagement terms agreed before testing
  • Input on framework coverage and report format
  • Start with a scoping call
  • Pricing confirmed before work begins

Contact us for availability

FAQ

Common questions

Aren't automated scanners enough?

No. Scanners are good at known patterns, such as outdated components, missing patches, and common misconfigurations. They miss business-logic flaws, authorization gaps, and issues that only appear when several problems are chained together, because those need someone who understands the application. Our AI handles the repetitive discovery and testers judge the rest.

How is this different from Pentera or NodeZero?

Those products are run by your own team for continuous validation. Flagent adds an independent human review and a signed report. Whether you need signed third-party testing depends on your audit and risk requirements.

Can this serve as our independent penetration test?

It depends on your framework, scope, and auditor. Flagent is built around independent human review and a named tester of record, with documented scope, rules of engagement, methodology, findings, and supporting evidence. It's worth agreeing the requirements with your auditor or QSA before testing. No provider can guarantee acceptance.

How does the AI stay in scope?

Before testing we document targets, permitted techniques, testing windows, escalation contacts, and prohibited actions. The scope allowlist is enforced at the tool-call boundary, each run is logged, and either side can stop testing. Production safety controls are confirmed during onboarding.

What happens between the annual reports?

Between reports the AI keeps testing on the agreed schedule and on change events. The cadence and report schedule are agreed per engagement, and the signed report states the scope and period it covers.

How do retests work?

Retest terms are agreed as part of the engagement. A retest replays the recorded attack chain after remediation, and the result is reviewed by a tester and added to the evidence.

How does the pricing work?

You pay a monthly subscription for coverage, plus a fee per signed report. Final numbers depend on scope and test type, and we confirm them before work begins.

Request a scoping call

Tell us what you need tested. We'll confirm scope, timing, and terms before any testing begins.

We confirm scope and rules of engagement before testing starts.