SEE MATPROOF ON YOUR STACK — BOOK A 30-MINUTE DEMO

AI penetration testing

AI pentesting tools: 14 platforms compared.

Every value comes from the provider's own page, with a source link and a date. Where a provider publishes nothing, the cell says “not published”. We do not rank, and we do not repeat speed or detection claims.

Go to the table

Sources: the provider pages themselves · Matproof sits in the table on the same terms · Read on 8 and 15 September 2026

Short answer

7 of 14 tools publish a price. The real difference is who checks the findings.

Escape states no human in the loop. Terra Security states that human pentesters sign off findings. Horizon3.ai sells its autonomous NodeZero software and, separately, a compliance pentest run by people. Aikido Security, Ridge Security and Penligent describe your own team steering the agents. Strix is open source. Matproof uses AI agents plus a validator agent and no human tester. Decide which of those your auditor or customer will accept, then read across.

The table

14 AI penetration testing tools, every value sourced.

Rows are alphabetical after our own. The order is not a ranking. Each cell reflects pages on that provider's own website, and every source URL is listed further down.

ToolHow it testsPublished priceRetest includedFrameworks namedStated timingStated location
MatproofusAI agent platform, self-serveEUR 149 per run. EUR 299 per month for 3 scans. EUR 1,490 per month for 20 scans. Enterprise on quote.YesSOC 2, ISO 27001, DORA, NIS2 mappingnot publishedPlatform hosted in Germany, at Hetzner
Aikido SecurityAI agents, self-serve. The customer decides whether a test tries to escalateUSD 4,000 per typical pentest (the page also shows EUR 3,500 and GBP 3,000). Rightsized pentest from USD 50 to USD 30,000+. Continuous testing on quote.YesSOC 2, ISO 27001, HIPAA“a full audit-grade SOC2 or ISO27001 PDF report in a few hours”European HQ: Keizer Karelstraat 15, 9000 Ghent, Belgium
CobaltPTaaS with a vetted tester poolAutonomous Pentest USD 3,500 per test, stated as a limited time offer. Standard, Premium and Enterprise are quote-only.Yesnot publishedFindings in 24 hours for the autonomous test. Test start in 1 to 3 business days by tier.not published
EscapeAI pentesting agents inside a DAST and attack surface platform, stated as no human in the loopnot publishedYesPCI DSS, SOC 2, ISO 27001not published8 B Rue de l’Operne, 64200 Biarritz, France
HadrianAgentic AI pentesting platform; the page says no tester gets assignedEUR 3,000 per test, bundles availablenot publishedSOC 2, ISO 27001, NIS2“validated findings within hours of test initiation”Office at Leidseplein 1, 1017 PR Amsterdam, Netherlands; London, New York and Paris offices also listed
Horizon3.aiAutonomous pentesting software (NodeZero). A separate compliance pentest service is run by human pentestersnot publishedYesPCI DSS v4.0, SOC, DORA, GDPR, CIS, NIST, CMMC (named on its compliance service page)“start your first NodeZero pentest in minutes”Headquartered in San Francisco, CA
IntruderAI pentesting agents for web applications, on demandUSD 3,500 per test. 4 pentest pack USD 12,000.YesSOC 2, ISO 27001“Same day pentest reports”1 Mark Square, London, EC2A 4EG, United Kingdom
PenligentAI pentest agent in a self-serve desktop tool, run under the user's controlFree plan USD 0. Pro USD 39.92 per month billed annually. Team and Enterprise on quote.YesSOC 2 and ISO 27001 aligned reports“Start your Pentest In 5 Minutes”not published
PenteraSoftware the customer runs itselfnot publishednot publishedSOC 2, ISO/IEC 27001, ISO/IEC 42001, PCI DSS v4.0, NIST, CMMC, DORA, NIS2, GDPR, HIPAA, FedRAMPnot published200 Summit Drive, 3rd floor, Burlington, Massachusetts, 01803
Ridge SecurityAutomated pentesting platform (RidgeBot), plus on-premises agentic red teaming directed by the customer's team (RidgeGen)not publishedYesOWASP Top 10, MITRE ATT&CKnot published1900 McCarthy Blvd., Suite 112, Milpitas, CA 95035
RunSybilA system of AI agents, continuous, black, grey or white boxnot publishedYesSOC 2 Type II, ISO 27001 (named as audits customers passed)“Engagements start the same day you onboard.” Large applications “take up to 24 hours”.Hubs in San Francisco and New York City
StrixOpen-source AI agents you host yourself, plus a paid cloud platformOpen source under Apache License 2.0. Pro USD 29 per seat per month, pentests billed separately.YesSOC 2, ISO 27001, PCI DSS (Enterprise tier, per its GitHub README)“Get penetration tests done in hours, not weeks”OmniSecure, Inc., Newark, Delaware, as stated in its privacy policy
Terra SecurityAI agents with human pentesters who sign off findings, continuousnot publishedYesSOC 2 Type II, ISO 27001, PCI DSS, HIPAA“Initial findings arrive within one to two weeks of kickoff”131 Oliver Street, 3rd Floor, Boston, Massachusetts, 02108
XBOWAutonomous AI agents with automated validators, sold by quotenot publishednot publishednot publishednot publishedMailing address in Seattle, Washington, stated in its privacy policy

The Matproof, Cobalt and Pentera rows were read on 8 September 2026; all other rows on 15 September 2026, each from the provider's own website. “Not published” means the pages we read carry no such value; it is not a criticism and not a “no”. “Frameworks named” records which frameworks a provider names on the page we read. It is not a statement that the provider holds a certification or an accreditation, or that its report is accepted by any auditor. “Stated location” is whatever the provider states and is not normalised. Speed and detection-rate claims on provider pages are left out on purpose. Row order carries no judgement.

  • Matproof: “3 full Sentinel pentests per month … Remediation-diff metric across re-tests” https://matproof.com/pricing
  • Aikido Security: “Re-test findings from the initial pentest for up to 6 months to validate your fixes.” https://www.aikido.dev/attack/aipentest
  • Cobalt: “unlimited on-demand retesting throughout your contract term” https://www.cobalt.io/pricing
  • Escape: “Run continuous AI-powered pentesting that learns your business, proves exploitability, and delivers reports that both auditors and engineers can act on.” https://escape.tech/product/ai-pentesting
  • Hadrian: “Hadrian delivers validated findings within hours of test initiation, at the same depth and quality every single time.” https://hadrian.io/pricing
  • Horizon3.ai: “Horizon3’s NodeZero® autonomously executes real attack techniques, without agents or disruption.” https://horizon3.ai/nodezero/
  • Intruder: “Get a comprehensive pentest report within hours that can be used as evidence for security compliance frameworks including SOC 2 and ISO 27001.” https://www.intruder.io/pentest-pricing
  • Penligent: “Penligent turns verified security findings into SOC 2 and ISO 27001 aligned reports, with editable content and export-ready formats for customer delivery, audits, and internal remediation workflows.” https://www.penligent.ai/pricing
  • Pentera: “run safely in production environments using customer-controlled guardrails” https://pentera.io/platform/
  • Ridge Security: “RidgeBot® is fully auto nomous penetration testing that runs continuously every day, week, or month.” https://ridgesecurity.ai/ridgebot/
  • RunSybil: “Sybil is the offensive security team you don't have: a system of AI agents that finds, exploits, and validates real vulnerabilities in your application, continuously.” https://www.runsybil.com/platform
  • Strix: “Strix are autonomous AI penetration testing agents that act just like real hackers - they run your code dynamically, find vulnerabilities, and validate them through actual proofs-of-concept.” https://www.strix.ai/pricing
  • Terra Security: “Terra combines AI agents with human pentesters for oversight, validating and signing off on findings before they're reported.” https://www.terra.security/use-cases/replace-legacy-pentests
  • XBOW: “XBOW runs the entire pentest autonomously and continuously, from the context you give it to a confirmed, working exploit, every time your applications change.” https://xbow.com/platform

Fit

Who each tool is the right answer for.

One line per tool, written from what the provider publishes about its own product.

ToolThe right answer when
MatproofTeams that need a repeatable report for an ISO 27001 or SOC 2 audit and want the price published before they talk to anyone.
Aikido SecurityTeams that want a self-serve AI pentest of one web application and its APIs at a published per-assessment price.
CobaltBuyers who want a named human tester pool and can accept a quote for everything above the entry test.
EscapeAppSec teams that want AI pentesting, business-logic DAST and attack surface management in one platform.
HadrianSecurity teams that want on-demand agentic pentests of their external attack surface alongside asset discovery.
Horizon3.aiOrganisations that want to run autonomous internal, external and cloud pentests on a schedule, with a human-delivered compliance pentest as an option.
IntruderCompanies that need an on-demand web application pentest report as SOC 2 or ISO 27001 evidence at a published per-test price.
PenligentSecurity engineers and pentesters who want an AI pentest tool with a free plan and a low monthly price.
PenteraSecurity teams that want to run validation themselves on their own schedule, not buy a report.
Ridge SecurityEnterprises that want automated pentesting on a daily, weekly or monthly cadence, with an on-premises red-team option.
RunSybilSoftware teams that want continuous AI testing of web apps and APIs on every deployment, with retests after fixes.
StrixDevelopers who want AI pentesting in CI and pull requests, free and self-hosted or as a per-seat cloud platform.
Terra SecurityEnterprises that want continuous agentic pentesting with findings signed off by human pentesters.
XBOWSecurity teams that want autonomous, continuous testing of web applications and APIs, priced by quote.

Method

How we compared.

For every tool we read its own website: the product page, the pricing page where one exists, and the contact, company or legal page for the location. For an open-source project we also read its official repository.

A script compared every quoted value against the saved text of the page it came from before the value went into the table. We used no review sites, no analyst reports and nothing from memory.

We left out every comparative claim, such as how many weeks a tool saves or how many more vulnerabilities it finds than a rival. Those are marketing statements we cannot test.

Matproof publishes this page and sells one of the products in it. Our row carries sources like every other row, and it says what does not flatter us: there is no human tester and we publish no turnaround time.

All sources

What we could not source, and how to read some cells

  • XBOW names compliance frameworks on its platform page next to its own deployment controls, not as report formats, so the frameworks cell says “not published”. Its only address on the pages we read is a mailing address in its privacy policy.
  • Horizon3.ai: the frameworks come from its compliance pentest service page. The NodeZero product page names none.
  • Hadrian: its pricing and agentic pentest pages do not mention a retest after remediation, so that cell says “not published”.
  • Escape: “retest included” means findings become automated regression tests that run on every build, not a one-off manual retest.
  • Ridge Security: the retest and customer-directed testing come from its RidgeGen page, not the RidgeBot page.
  • Aikido Security: two of its pages give different US office addresses, so we print the Ghent European HQ that both pages state. Its page shows the typical pentest price in several currencies; we copied them and converted nothing.
  • Strix: the address is the one its privacy policy gives for the operating company. The report frameworks are stated for the Enterprise tier in its GitHub README.
  • Penligent and XBOW publish no street address on the pages we read. RunSybil and Horizon3.ai name cities only. Hadrian lists offices and names no headquarters.
  • Price is unpublished for Escape, Horizon3.ai, Pentera, Ridge Security, RunSybil, Terra Security and XBOW. Ask for it in writing, including what a retest costs.

FAQ

Common questions about AI penetration testing tools

What is AI penetration testing?

It is a penetration test where software agents plan and run the attack steps a human tester would run: map the target, try an exploit, confirm it worked, and write it up. The products in this table differ in three ways that matter to a buyer. Some run with no human in the loop (Escape says so on its page). Some have human pentesters sign off each finding (Terra Security says so). Some let your own team direct the agents (Ridge Security's RidgeGen, Aikido Security and Penligent describe it that way). Matproof runs AI agents and a second AI agent that re-runs each finding, with no human tester.

How much does an AI pentest cost?

Of the 14 tools here, 7 publish a price on their own site: Matproof, Aikido Security, Cobalt, Hadrian, Intruder, Penligent and Strix. The published figures range from a free plan (Penligent) and an open-source edition (Strix) to USD 3,500 per test (Intruder, and Cobalt's autonomous test as a limited time offer) and USD 4,000 for a typical Aikido Security pentest. Matproof publishes EUR 149 per run and EUR 299 per month for three scans. The others quote after a call.

Will an auditor accept an AI pentest for SOC 2 or ISO 27001?

That is your auditor's decision, and no provider can promise it. Neither SOC 2 nor ISO/IEC 27001 names a penetration test as a mandatory control; both ask you to find and manage technical vulnerabilities, and a dated test report is common evidence. Terra Security's own compliance page gives the honest version: acceptance can vary by engagement, so confirm scope with your auditor. Ask before you rely on any report, ours included.

Does an AI pentest satisfy PCI DSS requirement 11.4?

Ask your QSA. PCI DSS v4.0 requirement 11.4 asks for testing by a qualified internal resource or qualified external third party, with organizational independence of the tester, at least once every 12 months and after significant change. It names no certification and does not say whether software counts as the tester. Whether an AI-run test meets 11.4 for your environment is your QSA's call.

What does AI pentesting not cover?

Social engineering, physical entry and most deep business-logic abuse still need people. The providers here say as much in different ways: Horizon3.ai sells a separate compliance pentest run by human pentesters, and Terra Security puts human pentesters on the findings. Matproof covers web applications, APIs and external infrastructure with AI agents only and holds no pentest accreditation. If a contract names a human-led or accredited test, buy that.

Is there a free or open-source AI pentesting tool?

Yes, two in this table. Strix publishes an open-source edition under the Apache License 2.0 that you host yourself with your own model key. Penligent publishes a free plan. Matproof runs a free external scan without an account at matproof.com/tools/pentest-scan, which is a scan of your public surface and not a full pentest.

Next step

See your own attack surface first.

The free scan checks your public surface without an account and returns a report you can take to any tool above, including the ones that are not us.

Run the free scan

Read next