Supervised autonomous pentesting

Coverage as deep as your scope—not just your hours.

RedDepth is an autonomous pentest copilot for independent security researchers and boutique offensive-security firms — specialized agents map and test an authorized scope you supervise, and a separate agent must independently reproduce a finding before it counts.

  • Human supervised
  • Independently validated
  • Evidence-linked
Authorized scope scope 042 testing
Scope control active

Illustrative operator console. Scope confirmed on a sample application; the surface is mapped; a candidate vulnerability is found and independently reproduced with evidence preserved; one upload path is held pending the human supervisor's sign-off.

Illustrative operator viewYou supervise every step

Built for the people who already do this work — not another dashboard to babysit

The actual problem

Your judgment doesn't scale.
Your hours shouldn't have to.

Manual coverage is bounded by attention, not skill. What doesn't get tested isn't what you chose to skip — it's what you ran out of time for.

01 / Coverage

Large surfaces outrun the hours you have to sweep them.

Every parameter, role, and state transition is a decision point. Most engagements end on the clock, not on coverage.

02 / Repetition

The systematic sweep eats the time your judgment is worth more than.

Varying method, identity, encoding, and timing across every endpoint should free up your attention, not consume it.

03 / Trust

An AI-generated finding nobody reproduced is a guess with better formatting.

Unverified AI output is why the security community distrusts "AI pentesting." This is built to answer that objection, not repeat it.

How it works

A controlled path
from scope to evidence.

Six steps, always in this order: authorize the scope, map the surface, test it systematically, independently reproduce every candidate, audit what's still untested, and hand you evidence-linked results.

03–04
03–04 — Test and validate

Testing agents vary method, identity, and state. A separate agent checks their work.

A candidate never comes from the same reasoning twice — a separate agent reproduces it independently, from evidence alone, before it counts.

05–06
05–06 — Audit and deliver

A separate pass challenges "done." Then you get evidence, not adjectives.

Before anything is called complete, an independent audit looks for what's still untested. What's left: a draft report where every claim links to raw evidence — yours to review, edit, or hold back.

Why not just—

Not a scanner.
Not an unsupervised agent, either.

"AI finds vulnerabilities" is a claim every tool in this category makes. What matters is what happens between a candidate and a confirmed finding — and who stays in control while it happens.

Comparison of RedDepth against vulnerability scanners, generic AI agents, and manual-only testing
  RedDepth Vuln scanners Generic AI agents Manual-only
Business-logic & authorization testing Yes — a methodology per surface Limited — signature-based Depends on the prompt Yes, bounded by tester hours
Independent validation before it counts A separate agent reproduces it from evidence alone No No Tester self-reviews
Coverage accountability A separate pass audits what's still untested Coverage = what the scanner supports Not tracked As thorough as time allows
Who controls scope and judgment Full — you supervise every session N/A Minimal oversight Full — the tester
Who it's for

Built to sit inside
the work you already do.

RedDepth doesn't replace your judgment or authorization — it takes the systematic sweep off your plate so your hours go to what only you can do.

For independent researchers

Cover more of the scope you already have access to.

  • Systematic sweeps you don't have hours for
  • Evidence organized as you go, not reconstructed afterward
  • Independent validation before you submit a finding
  • You stay the researcher of record, under your supervision
For boutique pentest teams

Take on larger scopes without adding headcount first.

  • Standardize coverage across junior and senior testers
  • Delegate the sweep, keep your team on judgment calls
  • An independent coverage audit before you call it done
  • Evidence-linked drafts your team edits, not writes from scratch
Trust and evidence

Credibility from mechanism.
Not adjectives.

Every item below is something the workflow does, not something you're asked to take on faith — reinforced by evidence you can inspect, not just a report that asserts it.

01

Human supervision, every session

You define scope and review every draft finding. Ambiguous authorization stops the work and asks — it doesn't guess.

02

Authorized scope required

RedDepth only acts on assets your written scope includes. Out-of-scope references are recorded, never followed or tested.

03

Independent finding validation

Nothing reaches you without a second, blind reproduction proving it's real — that's what makes a finding safe to submit or hand to a client.

04

Independent coverage auditing

A separate pass challenges whether testing is actually complete before anyone calls it done, including RedDepth.

Coverage ledgerDisposition
Authorization boundariesCross-identity and cross-rolevalidated
Recovery workflowState and replay behaviorrevisit
Upload trust boundaryContent and storage pathsin review
Unknown surfacesExplicitly accounted fortracked

Every raw request, response, and tool output is captured before any summary is written — a finding links to that evidence rather than replacing it. Known limitations: RedDepth needs an engaged human supervisor and doesn't run unattended, and today it covers web, API, network, identity/authorization, and business-logic surfaces — not mobile apps or cloud-configuration review.

Your scope, wherever it lives

Works with the program
you already have.

Bring a target you're independently authorized to test, or a company-managed program on an established bug bounty platform. Written scope and rules govern either way.

Platform names and marks belong to their respective owners; inclusion indicates ecosystem support, not endorsement. Some programs restrict AI-assisted submissions — confirm your program's current rules before submitting.

The initial offer

RedDepth Pilot

A paid, limited-scope engagement against one target you're already authorized to test — how you'd try RedDepth on a real engagement, not a sandbox demo.

  • ScopeOne authorized target, agreed with you before testing starts
  • ExecutionHuman-supervised surface mapping and systematic testing
  • ValidationIndependent reproduction of every candidate finding
  • CoverageA dedicated audit pass before the engagement is called complete
  • DeliverableAn evidence-linked report you can hand to a client or submit yourself
  • DurationA fixed window, agreed up front — not open-ended scope creep

Pilot engagements start at $1,500

Final price depends on scope and is confirmed before you commit. Pilots with clear coverage gains have a defined path to an ongoing plan.

Apply for a Pilot
Questions

What researchers and teams
ask before they apply.

RedDepth is built for authorized assessments run by whoever holds the authorization. These cover scope, validation, and what you receive.

What does RedDepth actually test?

Web apps, APIs, identity and authorization boundaries, workflows and business logic, and network- or host-level surfaces — whatever your scope includes, tested systematically rather than by signature.

Is RedDepth fully autonomous?

No. A human supervisor defines and authorizes scope, orients every session, and reviews every draft finding. Ambiguous authorization stops the work and asks — it doesn't guess.

How do you keep findings from being false positives?

A separate agent independently reproduces every candidate before it counts — see how it works for the full sequence. A coverage audit also checks whether testing is actually complete.

What does the final report include?

Each validated finding links the affected asset, preconditions, reproduction steps, evidence, impact and CWE classification, remediation direction, and what the coverage audit left open.

Can I run RedDepth against my existing bug bounty program?

Yes, within your program's rules of engagement — you're responsible for confirming your platform's current AI-submission policy before submitting anything RedDepth helped produce.

What happens during the Pilot?

One authorized target, scope agreed up front, human-supervised execution, independent validation, a coverage-audit pass, and an evidence-linked report.

Bring your next authorized assessment

Apply for a
RedDepth Pilot.

Tell us about the engagement you already have access to. We'll confirm fit and scope by email; sensitive access details move through a private channel, never this form.

Sensitive access details move through a private channel after we confirm fit — never through this form.

Signal replayed