Large surfaces outrun the hours you have to sweep them.
Every parameter, role, and state transition is a decision point. Most engagements end on the clock, not on coverage.
RedDepth is an autonomous pentest copilot for independent security researchers and boutique offensive-security firms — specialized agents map and test an authorized scope you supervise, and a separate agent must independently reproduce a finding before it counts.
Illustrative operator console. Scope confirmed on a sample application; the surface is mapped; a candidate vulnerability is found and independently reproduced with evidence preserved; one upload path is held pending the human supervisor's sign-off.
Built for the people who already do this work — not another dashboard to babysit
Manual coverage is bounded by attention, not skill. What doesn't get tested isn't what you chose to skip — it's what you ran out of time for.
Every parameter, role, and state transition is a decision point. Most engagements end on the clock, not on coverage.
Varying method, identity, encoding, and timing across every endpoint should free up your attention, not consume it.
Unverified AI output is why the security community distrusts "AI pentesting." This is built to answer that objection, not repeat it.
Six steps, always in this order: authorize the scope, map the surface, test it systematically, independently reproduce every candidate, audit what's still untested, and hand you evidence-linked results.
You define assets, identities, methods, exclusions, and limits before anything runs. Dedicated agents then map endpoints, parameters, roles, and workflows.
A candidate never comes from the same reasoning twice — a separate agent reproduces it independently, from evidence alone, before it counts.
Before anything is called complete, an independent audit looks for what's still untested. What's left: a draft report where every claim links to raw evidence — yours to review, edit, or hold back.
"AI finds vulnerabilities" is a claim every tool in this category makes. What matters is what happens between a candidate and a confirmed finding — and who stays in control while it happens.
| RedDepth | Vuln scanners | Generic AI agents | Manual-only | |
|---|---|---|---|---|
| Business-logic & authorization testing | Yes — a methodology per surface | Limited — signature-based | Depends on the prompt | Yes, bounded by tester hours |
| Independent validation before it counts | A separate agent reproduces it from evidence alone | No | No | Tester self-reviews |
| Coverage accountability | A separate pass audits what's still untested | Coverage = what the scanner supports | Not tracked | As thorough as time allows |
| Who controls scope and judgment | Full — you supervise every session | N/A | Minimal oversight | Full — the tester |
RedDepth doesn't replace your judgment or authorization — it takes the systematic sweep off your plate so your hours go to what only you can do.
Every item below is something the workflow does, not something you're asked to take on faith — reinforced by evidence you can inspect, not just a report that asserts it.
You define scope and review every draft finding. Ambiguous authorization stops the work and asks — it doesn't guess.
RedDepth only acts on assets your written scope includes. Out-of-scope references are recorded, never followed or tested.
Nothing reaches you without a second, blind reproduction proving it's real — that's what makes a finding safe to submit or hand to a client.
A separate pass challenges whether testing is actually complete before anyone calls it done, including RedDepth.
Every raw request, response, and tool output is captured before any summary is written — a finding links to that evidence rather than replacing it. Known limitations: RedDepth needs an engaged human supervisor and doesn't run unattended, and today it covers web, API, network, identity/authorization, and business-logic surfaces — not mobile apps or cloud-configuration review.
Bring a target you're independently authorized to test, or a company-managed program on an established bug bounty platform. Written scope and rules govern either way.
Platform names and marks belong to their respective owners; inclusion indicates ecosystem support, not endorsement. Some programs restrict AI-assisted submissions — confirm your program's current rules before submitting.
A paid, limited-scope engagement against one target you're already authorized to test — how you'd try RedDepth on a real engagement, not a sandbox demo.
Pilot engagements start at $1,500
Final price depends on scope and is confirmed before you commit. Pilots with clear coverage gains have a defined path to an ongoing plan.
Apply for a PilotThese pages explain the mechanism, the people it is built for, and the limits it keeps visible. Start with the question closest to your work.
How supervised autonomy differs from a scanner, an unattended agent, and a managed service.
02 / MechanismWhy a candidate finding needs a blind reproduction from evidence before it becomes a confirmed finding.
03 / MethodThe six-step path from authorized scope to evidence-linked results, including what remains out of scope.
04 / For researchersUse systematic coverage to spend more of your limited engagement time on judgment and verification.
05 / For firmsExtend delivery capacity while keeping scope control, review, and client-facing evidence with the team.
RedDepth is built for authorized assessments run by whoever holds the authorization. These cover scope, validation, and what you receive.
Web apps, APIs, identity and authorization boundaries, workflows and business logic, and network- or host-level surfaces — whatever your scope includes, tested systematically rather than by signature.
No. A human supervisor defines and authorizes scope, orients every session, and reviews every draft finding. Ambiguous authorization stops the work and asks — it doesn't guess.
A separate agent independently reproduces every candidate before it counts — see how it works for the full sequence. A coverage audit also checks whether testing is actually complete.
Each validated finding links the affected asset, preconditions, reproduction steps, evidence, impact and CWE classification, remediation direction, and what the coverage audit left open.
Yes, within your program's rules of engagement — you're responsible for confirming your platform's current AI-submission policy before submitting anything RedDepth helped produce.
One authorized target, scope agreed up front, human-supervised execution, independent validation, a coverage-audit pass, and an evidence-linked report.
Tell us about the engagement you already have access to. We'll confirm fit and scope by email; sensitive access details move through a private channel, never this form.
Signal replayed