Weeks on a waiting list
Conventional testing needs a named human to crawl, poke, and document everything by hand. Senior testers are scarce. Your release calendar is not.
AUTONOMOUS OFFENSIVE SECURITY · HUMAN-SIGNED
Augment runs autonomous, human-supervised penetration tests on your web apps and APIs — evidence-backed findings, senior-reviewed reports, and a retest. In days, not weeks.
// our operating floor — not our aspirations
01 / THE PROBLEM
You wait weeks for a tester to read your app. You pay for hours, not outcomes. You get a PDF of maybes — and remediation is still your problem. Meanwhile, your attack surface ships daily.
Conventional testing needs a named human to crawl, poke, and document everything by hand. Senior testers are scarce. Your release calendar is not.
Time-and-materials testing rewards duration. Findings arrive as prose and screenshots — not reproducible evidence your engineers can act on.
No retest loop, no verification that fixes actually landed, no machine-readable output for the tools your team already runs.
02 / THE PLATFORM
Frontier models plan and probe. Typed tools execute. Deterministic policy decides what is allowed. A senior security reviewer signs everything that reaches you. Software is the workforce — humans are the accountability layer.
Autonomous recon maps your authorized web apps and APIs inside the signed scope — endpoints, parameters, auth flows, tech fingerprints. Everything outside the signed policy is invisible to the platform. Default deny, enforced by network controls, not prompts.
Agent hypotheses are converted into proof — or discarded. Every candidate finding needs a baseline, an attack, and a control: three independent evidence captures before it can even queue for senior review. If we can't reproduce it, you never hear about it.
Approved findings ship with prioritized remediation guidance and hand off straight into your tracker. When your engineers mark a fix ready, a bounded retest re-runs the original evidence chain against the patched build — and the report shows exactly what closed, what didn't, and what remains.
03 / WATCH IT WORK
A sanitized view of a live engagement. Note what happens when anything drifts outside signed scope — the platform refuses, and logs the refusal.
04 / THE PROOF
median time from hypothesis to a complete, reproducible evidence chain
of scanner noise suppressed before a human ever spends a minute on it
more surface covered per engagement-hour than manual-only testing
retest included with every assessment — verified against the original evidence
// representative finding classes from pilot engagements — details under NDA
05 / THE MISSION
Offense compounds. Every engagement feeds the registry — playbooks, benchmarks, evidence templates — so the next customer's test starts smarter than the last. Autonomy expands only as fast as safety and proof allow.
// live threat topology — clusters are findings under verification
06 / WHO IT'S FOR
// for source-sensitive teams — the worker runs inside your environment, outbound-only. Your code and data never leave your perimeter. Evidence lands where you keep it.
// deployment pattern 3 of 3 — managed cloud, customer-hosted runner, air-gapped (roadmap)
07 / HOW IT WORKS
Tell us what runs your revenue. We tell you what we'd test first, what we'd decline, and what it costs. No deck, no discovery gauntlet.
MSA, SOW, authorization-to-test and rules of engagement — e-signed. We compile your exact assets, ports, rates and windows into a machine-readable policy bundle, signed. You acknowledge the effective scope.
The platform runs your authorized window: recon, deterministic checks, bounded validation. You watch status, not raw logs. Kill switches exist at every level — and we've never needed one.
Every finding arrives with its evidence chain — baseline, attack, control — independently reproduced and signed off by a senior offensive-security reviewer. Executive summary to SARIF, whichever audience you are.
Your team fixes. We re-run the original evidence chain against the patched build and publish the diff — what closed, what's open, what residual risk remains. On record. For your auditors.
Executive summaryp.3
Scope, dates & authorization refp.5
Findings matrix — 3 crit · 2 high · 4 medp.7
Reproducible evidence per findingp.9
Remediation priorities & guidancep.24
Coverage & exclusions statementp.31
Retest results & residual riskp.33
findings.json · findings.sarifattached
08 / WHAT YOU RECEIVE
Your board reads the summary. Your engineers read the evidence. Your auditors read the scope, the authorization reference, and the retest diff. Same document, signed.
09 / HARD LIMITS
Every engagement runs inside a signed policy bundle — exact assets, ports, rates, windows. Default deny. The model proposes; deterministic controls decide. Kill switches at global, engagement, worker and tool level, acknowledged in under five seconds.
These aren't settings. They're the architecture — enforced independently of the AI, by network controls the model cannot reach. // every engagement requires valid written authorization, exact scope, and rules of engagement. We decline what doesn't fit.
10 / ENGAGE
Pricing is per assessment — not per scanner seat, not per hour of a tester's afternoon. Every tier includes the retest and the evidence.
START HERE
from $4,900
One web app or API, tightly scoped, inside a fixed test window. The full accountable package.
MOST TEAMS
from $12,000/quarter
For teams that ship. Regression templates re-verify known findings every cycle; new surface gets fresh eyes.
PARTNERS
custom
Continuous safe validation, customer-hosted runners, and white-label delivery for agencies, vCISOs and MSSPs.
11 / QUESTIONS
We prefer a staging environment or a dedicated test tenant, and we say so in the SOW. Production is acceptable within signed rate limits and windows for specific check classes. Either way: default-deny policy, independent network egress enforcement, per-engagement ephemeral workers, and kill switches that acknowledge in under five seconds. The model cannot grant itself permission — it can only propose.
A named senior offensive-security reviewer signs every report. Findings are published only after independent reproduction and review. The AI does the repeatable work; a human carries the authority and the accountability. That separation is the product, not a caveat.
Scanners flag; they don't verify. Our pipeline converts hypotheses into proof — baseline, attack, and control evidence, re-verified by an independent critic before a human ever sees it. Business-logic flaws that scanners structurally can't find are exactly where the agent layer spends its time. You receive findings, not noise.
Written authorization from someone with authority over the assets, an exact asset list with environments, test accounts, an agreed window, and an emergency contact. If third parties (cloud vendor, MSP, subsidiary) must approve, we need that in writing too. We handle the paperwork pack — it's e-signed in a day.
No denial-of-service or stress testing, no destructive actions, no persistence or malware, no credential spraying, no exfiltration of real customer data, no phishing of your people, no testing of shared vendor infrastructure without separate authority, no lateral movement. If a provider promises all of that, ask for their insurance certificate.
Scoping call this week. Engagement runs within days of signed authorization and a passed preflight — the constraint is your authorization paperwork, not our calendar. Reports land within one business day of run completion for standard scope; the retest follows your fix cycle.
12 / START
Tell us what runs your revenue. We'll tell you what we'd test first — before you pay anything.
We'll reply within one business day with the scoping-call link and a preliminary view of what we'd test first. If it's urgent, email hello@augmentsecurity.com.
THE MISSION
keep scrolling
SAMPLE — CUSTOMER REPORT · REDACTED
EXECUTIVE SUMMARY
Three critical, two high, four medium findings. The criticals share a root cause: object-level authorization is enforced in the UI, not the API. One evening of engineering closes all three.
FINDINGS MATRIX
EVIDENCE CHAIN — FIND-0088
WHAT'S INSIDE THE FULL REPORT