.
Capability

AI Pentest Agent

Nullify's pentest agent is an AI-native penetration tester that continuously and autonomously attacks your REST and GraphQL APIs, validating every vulnerability through real multi-stage exploitation instead of reporting theoretical risk. It launches from the console, CLI, or GitHub Action, and every exploit is independently re-reviewed against the evidence before it reaches you.

What it does

  • Runs continuously, hands-off. Launch an engagement from the Nullify console, the CLI, or the Pentester GitHub Action, and it keeps attacking without an operator driving each step.
  • Exploits, not just reports. The agent validates vulnerabilities through active, multi-stage exploitation rather than reporting theoretical risk, informed by what Nullify already knows about your codebase, dependencies, and cloud environment.
  • Scoped to REST and GraphQL APIs. That's the honest boundary: single-page and server-rendered applications aren't attacked directly by a Pentest engagement — those surfaces are covered by Bug Hunts, which continuously monitor your external attack surface and can promote an application into a Pentest.
  • Ships evidence, not assertions. Every validated finding includes request/response pairs, screenshots, and video of the exploit — enough to reproduce and verify without re-running the engagement yourself.
  • Reviewed before it reaches you. Every exploit is independently re-reviewed against its own recorded evidence before it's reported, so a Pentest finding means Nullify actually reproduced the issue — not a guess.

How it works

An engagement starts wherever you launch it — the Nullify console, the CLI, or the Pentester GitHub Action — and then runs continuously against your REST and GraphQL APIs without a human driving each step. Instead of flagging a theoretical weakness, the agent attempts the attack: chaining multi-stage exploitation informed by what it already knows about your codebase, dependencies, and cloud environment. Every successful exploit is then independently re-reviewed against its own evidence — the request/response pairs, screenshots, and video captured during the attack — before it's reported, so what reaches you is a validated finding, not a guess. Application surfaces outside REST and GraphQL, like single-page apps and server-rendered apps, are covered separately by Bug Hunts, which continuously monitor your external attack surface and can promote a discovered application into a Pentest engagement.

Frequently asked questions

Does the pentest agent test our whole web application, including the frontend?+

No — a Pentest engagement targets REST and GraphQL APIs only. Single-page applications and server-rendered apps aren't attacked directly by Pentest; that surface is covered by Bug Hunts, which continuously monitor your external attack surface and can promote a discovered application into a Pentest engagement. If your production APIs are the priority, Pentest is the right tool; broader external surface coverage comes from Bug Hunts.

How is this different from an annual pentest we already buy?+

A traditional pentest is a snapshot — good for the day it's delivered and stale the day after. Nullify's pentest agent runs continuously and hands-off, so validated findings surface as your APIs change instead of showing up in a report six months later.

How do we know a finding is real and not a false positive?+

Because the agent doesn't report theoretical risk — it exploits. Every vulnerability is validated through actual multi-stage exploitation, and every successful exploit is independently re-reviewed against its own recorded evidence before it's reported to you.

What evidence do we actually get for a finding?+

Each validated finding ships with the request/response pairs from the exploitation, screenshots, and video of the attack — enough to reproduce and verify the issue without re-running the engagement yourselves.

How do we launch an engagement?+

From wherever fits your workflow: the Nullify console, the CLI, or the Pentester GitHub Action.

Read the docs: Pentests · Supported Targets · Engagement Workflow · Bug Hunts · Related: Exploit Validation · Code Security & SAST · Triage & Remediation

A Higher Order of Product Security

Book a demo and watch Nullify launch a pentest against your own APIs — and prove what it finds.

Book a Demo