MSSP Partner Program

Stop scheduling pentests. Start shipping continuous offensive security.

Audn is an agentic red team that runs as a CI/CD gate, built for MSSP resale. Autonomous attackers hit every pull request across your entire client book, block critical vulnerabilities before merge, and generate the compliance evidence your customers get audited on.

Built for MSSPs, and for MSPs building a security practice.

Every PR
Attack cadence
< 5 min
Client onboarding
Zero
Unauthorized prod writes

The problem

Your clients are paying for security they only receive once a year.

364 days

The pentest gap

An annual pentest secures one day a year. Every deploy in the other 364 ships untested into production.

Same payloads, every time

DAST can't think

Signature scanners fire the same payload list forever. They never chain findings, abuse business logic, or escalate privileges.

Expires on signing

Compliance theater

A PDF report is accurate the day it's signed and stale the day after. Auditors want continuous evidence, not a snapshot from last quarter.

How it works

Five steps from repo to continuous red team.

  1. 01

    Install GitHub Action

    Drop a 12-line workflow into the client repo.

  2. 02

    Register targets

    Scope hosts and routes per client tenant with signed authorization.

  3. 03

    AI attacks every PR

    Autonomous agents recon, chain, and exploit like a real red team.

  4. 04

    Gate blocks critical vulns

    Criticals fail the check before the merge button lights up.

  5. 05

    Evidence auto-generated

    Every run writes a timestamped, auditor-ready attestation mapped to SOC 2 (CC7.1, CC8.1), ISO/IEC 27001:2022 (A.8.8, A.8.25, A.8.29), PCI DSS v4.0.1 (6.2.4, 6.3.1, 11.4.2) and NIST SSDF (PW.8.2, RV.1.1).

Step six: see it for yourself.

Read a sample run and launch Audn against one of our example repositories — no client tenant, no credentials, no call required.

audn.ai/whitebox

Guardrails

Your agents. Their production systems. Here's what stops them.

Autonomous doesn't mean unsupervised. Every action the agent can take is classified before the run starts and bounded in the action layer, not by asking the model nicely — and you hold three independent kill switches over your whole book of business.

Every figure in this section — the 60-minute fail-closed timeout, the 8 req/sec ceiling, the 25-record proof cap, the 30-second authorization lease, the 20% error-rate breaker — is a defended limit, not an aspiration. Verify each one yourself in the pilot on your own infrastructure before a client tenant exists.

T0

Autonomous

Read-only recon, fingerprinting, non-mutating probes.

Runs unattended. Logged, never paused.

T1

Autonomous + notify

State-changing requests confined to the designated test tenant: creating records, uploading benign files, toggling settings the agent owns.

Executes immediately, posts to the run feed and your Slack channel within 10s.

T2

Human approval required

Proving auth bypass against real tenant data, any write outside the test tenant, privilege escalation to an admin role, credential reuse across hosts.

Agent freezes and publishes the exact planned request for review. An approver on the client's authorization list clicks approve or deny. If no approver responds within 60 minutes, that specific action is dropped and never executes. The rest of the run continues without it. A timeout always resolves to no, never to yes.

T3

Never executed

Deletion or mutation of production records, DoS and resource-exhaustion, persistence or backdoors, password/MFA resets on real users, outbound mail or SMS, pivoting to any host outside signed scope.

Blocked in the action layer, not by prompt instruction. No approval path exists.

Abort run

Dashboard button or the CLI command audn abort <run-id>. In-flight HTTP connections are cancelled and the agent halts in under 5 seconds. Partial findings and the full request log are preserved.

Pause tenant / stop all

One switch halts every queued and running scan for a single client; the partner-level stop does the same across your entire book. Both survive restarts until you re-enable them.

Dead-man lease + circuit breaker

The agent re-validates its authorization lease every 30 seconds and self-terminates if the lease is revoked or unreachable, so a kill lands even if the agent stops responding. A separate breaker auto-pauses the run when the target's error rate exceeds 20% over 60 seconds or latency triples against the baseline.

Scope enforcement
Every target is registered and signed off per client tenant before a single request fires. An egress proxy drops any request to a host or path outside the signed authorization — the agent cannot reach it even if it decides to try.
Rate ceilings
8 requests/sec per host by default, configurable per client, with exponential backoff on any 5xx. Testing never becomes a denial-of-service event.
Destructive-action blocks
Data loss, deletion, and service-disruption actions are blocked by default, not opt-out. Cross-tenant access is proven with a 25-record cap; the rest is counted, never retrieved.
Audit trail
Every request, response, and agent decision is written to an append-only log, exportable as JSON or SARIF for the client's SOC.

Comparison

Three ways to test. One of them runs on every deploy.

CapabilityAudnAnnual pentestDAST
Tests every deployYesNo, 1x/yearYes
Chains findings / abuses business logicYesYes (manual)No
Generates continuous compliance evidenceYesNo, ages outNo
Built for MSSP resale (multi-tenant, white-label, per-client scope)YesN/AN/A

Built for MSSPs

Everything the resale motion needs, nothing it doesn't.

Per-client target scoping

Isolated scopes, credentials, and findings for every tenant you manage.

White-label ready

Your logo, your domain, your report cover. Audn stays invisible.

Multi-tenant dashboard

One pane of glass across the whole book of business.

SARIF output

Findings land natively in GitHub code scanning and your SOC pipeline.

5-min setup

First client live before the kickoff call ends.

Partner pricing

Margin-friendly tiers, annual invoiced.

Evidence mapping

Each run maps to named controls, not to the word “compliance.”

Attestations cite the control reference and the run ID, so an auditor can trace a requirement to the exact attack attempt, timestamp, and result. Mapping is a control cross-reference, not a certification — the client's auditor still signs off.

EU financial-sector scope: we do not currently publish a DORA (2022/2554) or NIS2 (2022/2555) mapping. DORA's threat-led penetration testing regime carries binding requirements on tester independence, scope and cadence, and we will not hand a partner a mapping their regulated client could rely on until it has been reviewed by EU financial-services compliance counsel. Ask us on the call where that review stands.

SOC 2 (TSC 2017)

CC7.1, CC8.1

Per-PR run records evidence vulnerability detection and that changes were tested before deployment.

ISO/IEC 27001:2022

A.8.8, A.8.25, A.8.29

Technical vulnerability management, secure development lifecycle, and security testing in development and acceptance.

PCI DSS v4.0.1

6.2.4, 6.3.1, 11.4.2

Attacks on software addressed during development, vulnerability identification, and internal penetration testing after significant change.

NIST SSDF (SP 800-218)

PW.8.2, RV.1.1

Dynamic testing of executable code and continuous monitoring for newly discovered vulnerabilities.

Verify before you resell

We are an early program. No logo wall — a diligence pack instead.

You are being asked to put your brand on autonomous exploitation of your clients' systems. We will not paper over that with borrowed credibility. Everything below is something you can inspect yourself, on your own assets, before a single client tenant is created.

Where we actually are today

4
Pilots in progress
20+
GitHub repos tested
6,000
Security researchers

The agent has been run against 20+ GitHub repositories and hardened against adversarial testing by a community of 6,000 security researchers. Four pilots are in progress:

  • D2C brand · United Kingdom
  • Insurer · United Kingdom
  • Car dealership group · Turkey
  • Bank · Netherlands

These are pilots, not paying customers, and they are unnamed because none has agreed to be a reference yet. We are saying so rather than dressing four POCs up as a customer list. Ask on the call which of these sectors most resembles your book and what the runs actually found.

Pilot on your own infrastructure first

The first tenant we create is yours, not a client's. Run the full agent against your own staging and production estate under the same guardrails a client would get, and read the run log line by line before you resell anything.

Sample artifacts up front

Ask on the call for a real SARIF file, a full evidence bundle, and an append-only audit log from a live run. You evaluate the actual output format your analysts and your clients' auditors will receive — not a screenshot.

Authorization framework and MSA in review

The reseller MSA, the per-target authorization framework, and the T0–T3 action policy are shared before signature so your counsel and your technical lead can red-line the blast-radius terms.

Exit without lock-in

Findings export as SARIF, evidence exports as signed bundles. If you stop reselling, your clients keep their history in formats other tooling reads. No proprietary hostage format.

Who is accountable if a guardrail fails

The T0–T3 policy answers what stops the agent. This answers what happens on the day it gets one wrong.

Who built the classifier
The T0–T3 action policy and the egress enforcement layer are the work of the founding offensive-security engineering team. Named bios, prior engagements and references are provided on the partner call and in the diligence pack — we do not ask you to resell an anonymous product.
If the classifier misjudges an action
A misclassification that causes damage is our failure, not yours. The reseller MSA sets out the liability cap, the indemnification we carry for your client-facing exposure, and our insurance position in writing before you sign. Ask for those clauses on the first call, not the last.
Recourse and disclosure
Incident notification to you and the affected tenant, the full append-only request log for the run, a written root cause, and the remediation to the action layer — on a contractual clock, with your right to trigger the partner-level stop at any point.

Partner pricing

Margin-friendly tiers, annual invoiced.

Partner rates are quoted per portfolio size and branding requirements. All tiers are billed annually in advance with net-30 invoicing.

Starter

For MSSPs launching their first offensive security line.

Contact us

Annual invoiced

  • Up to 5 client tenants
  • Unlimited PR-triggered scans
  • SARIF + PDF evidence export
  • Email support, 1 business day
Book Partner Call

Growth

Most partners

For established MSSPs scaling recurring security revenue.

Contact us

Annual invoiced

  • Up to 40 client tenants
  • Full white-label branding
  • Multi-tenant dashboard + RBAC
  • Co-marketing kit & partner margin tiers
  • Shared Slack channel
Book Partner Call

Enterprise

For national providers with regulated portfolios.

Contact us

Annual invoiced

  • Unlimited tenants
  • Private deployment region
  • Custom attack policy & SSO/SCIM
  • Named solutions architect
  • Contractual SLAs
Book Partner Call

Add continuous offensive security to your service catalog.

Thirty minutes with our partnerships team is enough to scope margins, branding, and your first three client tenants.

Book Partner Call