Nullify's pentest agent is an AI-native penetration tester that continuously and autonomously attacks your REST and GraphQL APIs, validating every vulnerability through real multi-stage exploitation instead of reporting theoretical risk. It launches from the console, CLI, or GitHub Action, and every exploit is independently re-reviewed against the evidence before it reaches you.
An engagement starts wherever you launch it — the Nullify console, the CLI, or the Pentester GitHub Action — and then runs continuously against your REST and GraphQL APIs without a human driving each step. Instead of flagging a theoretical weakness, the agent attempts the attack: chaining multi-stage exploitation informed by what it already knows about your codebase, dependencies, and cloud environment. Every successful exploit is then independently re-reviewed against its own evidence — the request/response pairs, screenshots, and video captured during the attack — before it's reported, so what reaches you is a validated finding, not a guess. Application surfaces outside REST and GraphQL, like single-page apps and server-rendered apps, are covered separately by Bug Hunts, which continuously monitor your external attack surface and can promote a discovered application into a Pentest engagement.
No — a Pentest engagement targets REST and GraphQL APIs only. Single-page applications and server-rendered apps aren't attacked directly by Pentest; that surface is covered by Bug Hunts, which continuously monitor your external attack surface and can promote a discovered application into a Pentest engagement. If your production APIs are the priority, Pentest is the right tool; broader external surface coverage comes from Bug Hunts.
A traditional pentest is a snapshot — good for the day it's delivered and stale the day after. Nullify's pentest agent runs continuously and hands-off, so validated findings surface as your APIs change instead of showing up in a report six months later.
Because the agent doesn't report theoretical risk — it exploits. Every vulnerability is validated through actual multi-stage exploitation, and every successful exploit is independently re-reviewed against its own recorded evidence before it's reported to you.
Each validated finding ships with the request/response pairs from the exploitation, screenshots, and video of the attack — enough to reproduce and verify the issue without re-running the engagement yourselves.
From wherever fits your workflow: the Nullify console, the CLI, or the Pentester GitHub Action.
Read the docs: Pentests · Supported Targets · Engagement Workflow · Bug Hunts · Related: Exploit Validation · Code Security & SAST · Triage & Remediation
Book a demo and watch Nullify launch a pentest against your own APIs — and prove what it finds.
Book a Demo