Skip to content

Autonomous external pentesting · backed by proof

Enter an HTTPS URL. See what is actually exploitable.

SpectrAI tests the exact HTTPS URL you control, tries the authorized attack scenarios and turns every demonstrated result into reproducible evidence, an attack path and an actionable report.

Before any test runs, you prove through DNS that its domain is yours.

Verified HTTPS URL · bounded exploitation · final report

Are you a security firm or an MSP?

Real result · authorized lab

One complete Assessment, from scope to report.

Result obtained on our authorized lab.

  • 2demonstrated findingsEach demonstrated and published with its proof
  • 2reproducible proofsPoC and supporting material for each finding
  • 2attack pathsRelations derived from the evidence
  • 1final reportFrozen, exportable version

Who it is for

For your company, or for your clients.

  • You are a company

    Have a web application you control tested: you verify its domain, frame the test, follow the agents and receive the report.

    Get started
  • You are a security firm or an MSP

    Offer autonomous pentests to your clients under your brand: one isolated space per client, a console to run them and reports in your name.

    Explore the white label

How it works

From URL to report.

One URL, one Guidance, then agents that attack like a pentester and publish only what they proved. In the app, each test is called an Assessment and each demonstrated flaw a finding. Pick a chapter to jump straight to it.

Video · 30 seconds

What you receive

Results ready to use.

Every deliverable is linked to the Assessment and its persisted proof.

Demonstrated finding

Endpoint, method, impact and recommendation to prioritize the next move.

Reproducible proof

Steps, requests, responses and artifacts needed to verify the result.

Attack paths

Relations between findings, derived from the proofs, with their provenance.

Final report

Scope, findings, attack paths and NIS2 references in a frozen report, exportable as PDF.

Commitments

What SpectrAI does. And what it does not.

No promise the product does not keep today.

What SpectrAI does

  • Tests only HTTPS URLs whose domain you proved you control through DNS.
  • Publishes only demonstrated findings, each with its proof.
  • Treats “0 demonstrated findings” as a valid result, documented in the report.
  • Shows the agents, requests, tools and cost live.

What SpectrAI does not do

  • Invent a risk score or a theoretical flaw.
  • Replay its validations independently: the proof is the agent’s, provided so you can verify it.
  • Cover anything but verified HTTPS URLs: no internal infrastructure, no mobile app.
  • Attest NIS2 compliance: it documents what is useful for your file.
  • Isolate the agents’ outbound traffic at network level yet: keep it to domains you own.
  • Traditional scanner
    An alert to triage
    SpectrAI
    A controlled exploitation attempt
  • Traditional scanner
    A theoretical score
    SpectrAI
    Demonstrated impact with a PoC
  • Traditional scanner
    A raw export
    SpectrAI
    A finding, its proof, path and report

The Spectr suite

See the whole surface. Then prove what is exploitable.

SpectrASM shows everything you expose. SpectrAI demonstrates what is exploitable. Two products, one standard: proof.

spectr/asm

See the whole surface

Domains, subdomains, services, applications and certificates, mapped and kept up to date within your authorized scope.

Animation: SpectrAI agents test a fictitious application
spectr/aiYou are here

Prove what is exploitable

Autonomous agents test a URL you control and publish only the flaws they demonstrated, with their proof.

Start with a URL

Your next pentest starts here.

Enter an HTTPS URL, verify its domain, frame the test and get a result your team can actually use.