364 days
The pentest gap
An annual pentest secures one day a year. Every deploy in the other 364 ships untested into production.
Audn is an agentic red team that runs as a CI/CD gate, built for MSSP resale. Autonomous attackers hit every pull request across your entire client book, block critical vulnerabilities before merge, and generate the compliance evidence your customers get audited on.
Built for MSSPs, and for MSPs building a security practice.
The problem
364 days
An annual pentest secures one day a year. Every deploy in the other 364 ships untested into production.
Same payloads, every time
Signature scanners fire the same payload list forever. They never chain findings, abuse business logic, or escalate privileges.
Expires on signing
A PDF report is accurate the day it's signed and stale the day after. Auditors want continuous evidence, not a snapshot from last quarter.
How it works
Drop a 12-line workflow into the client repo.
Scope hosts and routes per client tenant with signed authorization.
Autonomous agents recon, chain, and exploit like a real red team.
Criticals fail the check before the merge button lights up.
Every run writes a timestamped, auditor-ready attestation mapped to SOC 2 (CC7.1, CC8.1), ISO/IEC 27001:2022 (A.8.8, A.8.25, A.8.29), PCI DSS v4.0.1 (6.2.4, 6.3.1, 11.4.2) and NIST SSDF (PW.8.2, RV.1.1).
Read a sample run and launch Audn against one of our example repositories — no client tenant, no credentials, no call required.
Guardrails
Autonomous doesn't mean unsupervised. Every action the agent can take is classified before the run starts and bounded in the action layer, not by asking the model nicely — and you hold three independent kill switches over your whole book of business.
Every figure in this section — the 60-minute fail-closed timeout, the 8 req/sec ceiling, the 25-record proof cap, the 30-second authorization lease, the 20% error-rate breaker — is a defended limit, not an aspiration. Verify each one yourself in the pilot on your own infrastructure before a client tenant exists.
Read-only recon, fingerprinting, non-mutating probes.
Runs unattended. Logged, never paused.
State-changing requests confined to the designated test tenant: creating records, uploading benign files, toggling settings the agent owns.
Executes immediately, posts to the run feed and your Slack channel within 10s.
Proving auth bypass against real tenant data, any write outside the test tenant, privilege escalation to an admin role, credential reuse across hosts.
Agent freezes and publishes the exact planned request for review. An approver on the client's authorization list clicks approve or deny. If no approver responds within 60 minutes, that specific action is dropped and never executes. The rest of the run continues without it. A timeout always resolves to no, never to yes.
Deletion or mutation of production records, DoS and resource-exhaustion, persistence or backdoors, password/MFA resets on real users, outbound mail or SMS, pivoting to any host outside signed scope.
Blocked in the action layer, not by prompt instruction. No approval path exists.
Dashboard button or the CLI command audn abort <run-id>. In-flight HTTP connections are cancelled and the agent halts in under 5 seconds. Partial findings and the full request log are preserved.
One switch halts every queued and running scan for a single client; the partner-level stop does the same across your entire book. Both survive restarts until you re-enable them.
The agent re-validates its authorization lease every 30 seconds and self-terminates if the lease is revoked or unreachable, so a kill lands even if the agent stops responding. A separate breaker auto-pauses the run when the target's error rate exceeds 20% over 60 seconds or latency triples against the baseline.
Comparison
| Capability | Audn | Annual pentest | DAST |
|---|---|---|---|
| Tests every deploy | Yes | No, 1x/year | Yes |
| Chains findings / abuses business logic | Yes | Yes (manual) | No |
| Generates continuous compliance evidence | Yes | No, ages out | No |
| Built for MSSP resale (multi-tenant, white-label, per-client scope) | Yes | N/A | N/A |
Built for MSSPs
Isolated scopes, credentials, and findings for every tenant you manage.
Your logo, your domain, your report cover. Audn stays invisible.
One pane of glass across the whole book of business.
Findings land natively in GitHub code scanning and your SOC pipeline.
First client live before the kickoff call ends.
Margin-friendly tiers, annual invoiced.
Evidence mapping
Attestations cite the control reference and the run ID, so an auditor can trace a requirement to the exact attack attempt, timestamp, and result. Mapping is a control cross-reference, not a certification — the client's auditor still signs off.
EU financial-sector scope: we do not currently publish a DORA (2022/2554) or NIS2 (2022/2555) mapping. DORA's threat-led penetration testing regime carries binding requirements on tester independence, scope and cadence, and we will not hand a partner a mapping their regulated client could rely on until it has been reviewed by EU financial-services compliance counsel. Ask us on the call where that review stands.
CC7.1, CC8.1
Per-PR run records evidence vulnerability detection and that changes were tested before deployment.
A.8.8, A.8.25, A.8.29
Technical vulnerability management, secure development lifecycle, and security testing in development and acceptance.
6.2.4, 6.3.1, 11.4.2
Attacks on software addressed during development, vulnerability identification, and internal penetration testing after significant change.
PW.8.2, RV.1.1
Dynamic testing of executable code and continuous monitoring for newly discovered vulnerabilities.
Verify before you resell
You are being asked to put your brand on autonomous exploitation of your clients' systems. We will not paper over that with borrowed credibility. Everything below is something you can inspect yourself, on your own assets, before a single client tenant is created.
The agent has been run against 20+ GitHub repositories and hardened against adversarial testing by a community of 6,000 security researchers. Four pilots are in progress:
These are pilots, not paying customers, and they are unnamed because none has agreed to be a reference yet. We are saying so rather than dressing four POCs up as a customer list. Ask on the call which of these sectors most resembles your book and what the runs actually found.
The first tenant we create is yours, not a client's. Run the full agent against your own staging and production estate under the same guardrails a client would get, and read the run log line by line before you resell anything.
Ask on the call for a real SARIF file, a full evidence bundle, and an append-only audit log from a live run. You evaluate the actual output format your analysts and your clients' auditors will receive — not a screenshot.
The reseller MSA, the per-target authorization framework, and the T0–T3 action policy are shared before signature so your counsel and your technical lead can red-line the blast-radius terms.
Findings export as SARIF, evidence exports as signed bundles. If you stop reselling, your clients keep their history in formats other tooling reads. No proprietary hostage format.
The T0–T3 policy answers what stops the agent. This answers what happens on the day it gets one wrong.
Partner pricing
Partner rates are quoted per portfolio size and branding requirements. All tiers are billed annually in advance with net-30 invoicing.
For MSSPs launching their first offensive security line.
Contact us
Annual invoiced
For established MSSPs scaling recurring security revenue.
Contact us
Annual invoiced
For national providers with regulated portfolios.
Contact us
Annual invoiced
Thirty minutes with our partnerships team is enough to scope margins, branding, and your first three client tenants.
Book Partner Call