AI penetration testing
AI pentesting tools: 14 platforms compared.
Every value comes from the provider's own page, with a source link and a date. Where a provider publishes nothing, the cell says “not published”. We do not rank, and we do not repeat speed or detection claims.
Go to the tableSources: the provider pages themselves · Matproof sits in the table on the same terms · Read on 8 and 15 September 2026
Short answer
7 of 14 tools publish a price. The real difference is who checks the findings.
Escape states no human in the loop. Terra Security states that human pentesters sign off findings. Horizon3.ai sells its autonomous NodeZero software and, separately, a compliance pentest run by people. Aikido Security, Ridge Security and Penligent describe your own team steering the agents. Strix is open source. Matproof uses AI agents plus a validator agent and no human tester. Decide which of those your auditor or customer will accept, then read across.
The table
14 AI penetration testing tools, every value sourced.
Rows are alphabetical after our own. The order is not a ranking. Each cell reflects pages on that provider's own website, and every source URL is listed further down.
| Tool | How it tests | Published price | Retest included | Frameworks named | Stated timing | Stated location |
|---|---|---|---|---|---|---|
| Matproofus | AI agent platform, self-serve | EUR 149 per run. EUR 299 per month for 3 scans. EUR 1,490 per month for 20 scans. Enterprise on quote. | Yes | SOC 2, ISO 27001, DORA, NIS2 mapping | not published | Platform hosted in Germany, at Hetzner |
| Aikido Security | AI agents, self-serve. The customer decides whether a test tries to escalate | USD 4,000 per typical pentest (the page also shows EUR 3,500 and GBP 3,000). Rightsized pentest from USD 50 to USD 30,000+. Continuous testing on quote. | Yes | SOC 2, ISO 27001, HIPAA | “a full audit-grade SOC2 or ISO27001 PDF report in a few hours” | European HQ: Keizer Karelstraat 15, 9000 Ghent, Belgium |
| Cobalt | PTaaS with a vetted tester pool | Autonomous Pentest USD 3,500 per test, stated as a limited time offer. Standard, Premium and Enterprise are quote-only. | Yes | not published | Findings in 24 hours for the autonomous test. Test start in 1 to 3 business days by tier. | not published |
| Escape | AI pentesting agents inside a DAST and attack surface platform, stated as no human in the loop | not published | Yes | PCI DSS, SOC 2, ISO 27001 | not published | 8 B Rue de l’Operne, 64200 Biarritz, France |
| Hadrian | Agentic AI pentesting platform; the page says no tester gets assigned | EUR 3,000 per test, bundles available | not published | SOC 2, ISO 27001, NIS2 | “validated findings within hours of test initiation” | Office at Leidseplein 1, 1017 PR Amsterdam, Netherlands; London, New York and Paris offices also listed |
| Horizon3.ai | Autonomous pentesting software (NodeZero). A separate compliance pentest service is run by human pentesters | not published | Yes | PCI DSS v4.0, SOC, DORA, GDPR, CIS, NIST, CMMC (named on its compliance service page) | “start your first NodeZero pentest in minutes” | Headquartered in San Francisco, CA |
| Intruder | AI pentesting agents for web applications, on demand | USD 3,500 per test. 4 pentest pack USD 12,000. | Yes | SOC 2, ISO 27001 | “Same day pentest reports” | 1 Mark Square, London, EC2A 4EG, United Kingdom |
| Penligent | AI pentest agent in a self-serve desktop tool, run under the user's control | Free plan USD 0. Pro USD 39.92 per month billed annually. Team and Enterprise on quote. | Yes | SOC 2 and ISO 27001 aligned reports | “Start your Pentest In 5 Minutes” | not published |
| Pentera | Software the customer runs itself | not published | not published | SOC 2, ISO/IEC 27001, ISO/IEC 42001, PCI DSS v4.0, NIST, CMMC, DORA, NIS2, GDPR, HIPAA, FedRAMP | not published | 200 Summit Drive, 3rd floor, Burlington, Massachusetts, 01803 |
| Ridge Security | Automated pentesting platform (RidgeBot), plus on-premises agentic red teaming directed by the customer's team (RidgeGen) | not published | Yes | OWASP Top 10, MITRE ATT&CK | not published | 1900 McCarthy Blvd., Suite 112, Milpitas, CA 95035 |
| RunSybil | A system of AI agents, continuous, black, grey or white box | not published | Yes | SOC 2 Type II, ISO 27001 (named as audits customers passed) | “Engagements start the same day you onboard.” Large applications “take up to 24 hours”. | Hubs in San Francisco and New York City |
| Strix | Open-source AI agents you host yourself, plus a paid cloud platform | Open source under Apache License 2.0. Pro USD 29 per seat per month, pentests billed separately. | Yes | SOC 2, ISO 27001, PCI DSS (Enterprise tier, per its GitHub README) | “Get penetration tests done in hours, not weeks” | OmniSecure, Inc., Newark, Delaware, as stated in its privacy policy |
| Terra Security | AI agents with human pentesters who sign off findings, continuous | not published | Yes | SOC 2 Type II, ISO 27001, PCI DSS, HIPAA | “Initial findings arrive within one to two weeks of kickoff” | 131 Oliver Street, 3rd Floor, Boston, Massachusetts, 02108 |
| XBOW | Autonomous AI agents with automated validators, sold by quote | not published | not published | not published | not published | Mailing address in Seattle, Washington, stated in its privacy policy |
The Matproof, Cobalt and Pentera rows were read on 8 September 2026; all other rows on 15 September 2026, each from the provider's own website. “Not published” means the pages we read carry no such value; it is not a criticism and not a “no”. “Frameworks named” records which frameworks a provider names on the page we read. It is not a statement that the provider holds a certification or an accreditation, or that its report is accepted by any auditor. “Stated location” is whatever the provider states and is not normalised. Speed and detection-rate claims on provider pages are left out on purpose. Row order carries no judgement.
- Matproof: “3 full Sentinel pentests per month … Remediation-diff metric across re-tests” https://matproof.com/pricing
- Aikido Security: “Re-test findings from the initial pentest for up to 6 months to validate your fixes.” https://www.aikido.dev/attack/aipentest
- Cobalt: “unlimited on-demand retesting throughout your contract term” https://www.cobalt.io/pricing
- Escape: “Run continuous AI-powered pentesting that learns your business, proves exploitability, and delivers reports that both auditors and engineers can act on.” https://escape.tech/product/ai-pentesting
- Hadrian: “Hadrian delivers validated findings within hours of test initiation, at the same depth and quality every single time.” https://hadrian.io/pricing
- Horizon3.ai: “Horizon3’s NodeZero® autonomously executes real attack techniques, without agents or disruption.” https://horizon3.ai/nodezero/
- Intruder: “Get a comprehensive pentest report within hours that can be used as evidence for security compliance frameworks including SOC 2 and ISO 27001.” https://www.intruder.io/pentest-pricing
- Penligent: “Penligent turns verified security findings into SOC 2 and ISO 27001 aligned reports, with editable content and export-ready formats for customer delivery, audits, and internal remediation workflows.” https://www.penligent.ai/pricing
- Pentera: “run safely in production environments using customer-controlled guardrails” https://pentera.io/platform/
- Ridge Security: “RidgeBot® is fully auto nomous penetration testing that runs continuously every day, week, or month.” https://ridgesecurity.ai/ridgebot/
- RunSybil: “Sybil is the offensive security team you don't have: a system of AI agents that finds, exploits, and validates real vulnerabilities in your application, continuously.” https://www.runsybil.com/platform
- Strix: “Strix are autonomous AI penetration testing agents that act just like real hackers - they run your code dynamically, find vulnerabilities, and validate them through actual proofs-of-concept.” https://www.strix.ai/pricing
- Terra Security: “Terra combines AI agents with human pentesters for oversight, validating and signing off on findings before they're reported.” https://www.terra.security/use-cases/replace-legacy-pentests
- XBOW: “XBOW runs the entire pentest autonomously and continuously, from the context you give it to a confirmed, working exploit, every time your applications change.” https://xbow.com/platform
Fit
Who each tool is the right answer for.
One line per tool, written from what the provider publishes about its own product.
| Tool | The right answer when |
|---|---|
| Matproof | Teams that need a repeatable report for an ISO 27001 or SOC 2 audit and want the price published before they talk to anyone. |
| Aikido Security | Teams that want a self-serve AI pentest of one web application and its APIs at a published per-assessment price. |
| Cobalt | Buyers who want a named human tester pool and can accept a quote for everything above the entry test. |
| Escape | AppSec teams that want AI pentesting, business-logic DAST and attack surface management in one platform. |
| Hadrian | Security teams that want on-demand agentic pentests of their external attack surface alongside asset discovery. |
| Horizon3.ai | Organisations that want to run autonomous internal, external and cloud pentests on a schedule, with a human-delivered compliance pentest as an option. |
| Intruder | Companies that need an on-demand web application pentest report as SOC 2 or ISO 27001 evidence at a published per-test price. |
| Penligent | Security engineers and pentesters who want an AI pentest tool with a free plan and a low monthly price. |
| Pentera | Security teams that want to run validation themselves on their own schedule, not buy a report. |
| Ridge Security | Enterprises that want automated pentesting on a daily, weekly or monthly cadence, with an on-premises red-team option. |
| RunSybil | Software teams that want continuous AI testing of web apps and APIs on every deployment, with retests after fixes. |
| Strix | Developers who want AI pentesting in CI and pull requests, free and self-hosted or as a per-seat cloud platform. |
| Terra Security | Enterprises that want continuous agentic pentesting with findings signed off by human pentesters. |
| XBOW | Security teams that want autonomous, continuous testing of web applications and APIs, priced by quote. |
Method
How we compared.
For every tool we read its own website: the product page, the pricing page where one exists, and the contact, company or legal page for the location. For an open-source project we also read its official repository.
A script compared every quoted value against the saved text of the page it came from before the value went into the table. We used no review sites, no analyst reports and nothing from memory.
We left out every comparative claim, such as how many weeks a tool saves or how many more vulnerabilities it finds than a rival. Those are marketing statements we cannot test.
Matproof publishes this page and sells one of the products in it. Our row carries sources like every other row, and it says what does not flatter us: there is no human tester and we publish no turnaround time.
All sources
- Matproof
https://matproof.com/pricinghttps://matproof.com/trust - Aikido Security
https://www.aikido.dev/attack/aipentesthttps://www.aikido.dev/contact - Cobalt
https://www.cobalt.io/pricing - Escape
https://escape.tech/product/ai-pentestinghttps://escape.tech/terms - Hadrian
https://hadrian.io/pricinghttps://hadrian.io/solutions/agentic-penetration-testinghttps://hadrian.io/contact - Horizon3.ai
https://horizon3.ai/nodezero/https://horizon3.ai/https://horizon3.ai/compliance/https://horizon3.ai/about-us/ - Intruder
https://www.intruder.io/pentest-pricinghttps://www.intruder.io/contact - Penligent
https://www.penligent.ai/pricinghttps://www.penligent.ai/ai-pentest - Pentera
https://pentera.io/platform/https://pentera.io/contact-us/ - Ridge Security
https://ridgesecurity.ai/ridgebot/https://ridgesecurity.ai/ridgegen/https://ridgesecurity.ai/company/ - RunSybil
https://www.runsybil.com/platformhttps://www.runsybil.com/company - Strix
https://www.strix.ai/pricinghttps://www.strix.ai/https://github.com/usestrix/strixhttps://www.strix.ai/privacy-policy - Terra Security
https://www.terra.security/use-cases/replace-legacy-pentestshttps://www.terra.security/terra-platform/web-app-testinghttps://www.terra.security/contact-us - XBOW
https://xbow.com/platformhttps://xbow.com/privacy-policy
What we could not source, and how to read some cells
- XBOW names compliance frameworks on its platform page next to its own deployment controls, not as report formats, so the frameworks cell says “not published”. Its only address on the pages we read is a mailing address in its privacy policy.
- Horizon3.ai: the frameworks come from its compliance pentest service page. The NodeZero product page names none.
- Hadrian: its pricing and agentic pentest pages do not mention a retest after remediation, so that cell says “not published”.
- Escape: “retest included” means findings become automated regression tests that run on every build, not a one-off manual retest.
- Ridge Security: the retest and customer-directed testing come from its RidgeGen page, not the RidgeBot page.
- Aikido Security: two of its pages give different US office addresses, so we print the Ghent European HQ that both pages state. Its page shows the typical pentest price in several currencies; we copied them and converted nothing.
- Strix: the address is the one its privacy policy gives for the operating company. The report frameworks are stated for the Enterprise tier in its GitHub README.
- Penligent and XBOW publish no street address on the pages we read. RunSybil and Horizon3.ai name cities only. Hadrian lists offices and names no headquarters.
- Price is unpublished for Escape, Horizon3.ai, Pentera, Ridge Security, RunSybil, Terra Security and XBOW. Ask for it in writing, including what a retest costs.
FAQ
Common questions about AI penetration testing tools
What is AI penetration testing?
It is a penetration test where software agents plan and run the attack steps a human tester would run: map the target, try an exploit, confirm it worked, and write it up. The products in this table differ in three ways that matter to a buyer. Some run with no human in the loop (Escape says so on its page). Some have human pentesters sign off each finding (Terra Security says so). Some let your own team direct the agents (Ridge Security's RidgeGen, Aikido Security and Penligent describe it that way). Matproof runs AI agents and a second AI agent that re-runs each finding, with no human tester.
How much does an AI pentest cost?
Of the 14 tools here, 7 publish a price on their own site: Matproof, Aikido Security, Cobalt, Hadrian, Intruder, Penligent and Strix. The published figures range from a free plan (Penligent) and an open-source edition (Strix) to USD 3,500 per test (Intruder, and Cobalt's autonomous test as a limited time offer) and USD 4,000 for a typical Aikido Security pentest. Matproof publishes EUR 149 per run and EUR 299 per month for three scans. The others quote after a call.
Will an auditor accept an AI pentest for SOC 2 or ISO 27001?
That is your auditor's decision, and no provider can promise it. Neither SOC 2 nor ISO/IEC 27001 names a penetration test as a mandatory control; both ask you to find and manage technical vulnerabilities, and a dated test report is common evidence. Terra Security's own compliance page gives the honest version: acceptance can vary by engagement, so confirm scope with your auditor. Ask before you rely on any report, ours included.
Does an AI pentest satisfy PCI DSS requirement 11.4?
Ask your QSA. PCI DSS v4.0 requirement 11.4 asks for testing by a qualified internal resource or qualified external third party, with organizational independence of the tester, at least once every 12 months and after significant change. It names no certification and does not say whether software counts as the tester. Whether an AI-run test meets 11.4 for your environment is your QSA's call.
What does AI pentesting not cover?
Social engineering, physical entry and most deep business-logic abuse still need people. The providers here say as much in different ways: Horizon3.ai sells a separate compliance pentest run by human pentesters, and Terra Security puts human pentesters on the findings. Matproof covers web applications, APIs and external infrastructure with AI agents only and holds no pentest accreditation. If a contract names a human-led or accredited test, buy that.
Is there a free or open-source AI pentesting tool?
Yes, two in this table. Strix publishes an open-source edition under the Apache License 2.0 that you host yourself with your own model key. Penligent publishes a free plan. Matproof runs a free external scan without an account at matproof.com/tools/pentest-scan, which is a scan of your public surface and not a full pentest.
Next step
See your own attack surface first.
The free scan checks your public surface without an account and returns a report you can take to any tool above, including the ones that are not us.
Run the free scan