AI-powered penetration testing
Attackers now
come in hordes.
So do we.
Horda unleashes a swarm of AI agents against your perimeter, inside a scope you authorize, and hands you validated findings in 72 hours. Then it keeps testing, every month.
01 /A horde on your side
THOUSANDS OF AGENTS.ONE SCOPE.
Not a scan.
A siege.
Horda is an AI-powered penetration testing platform. Instead of one consultant with a checklist, you get a coordinated swarm of autonomous agents that map your attack surface, chain weaknesses the way a real adversary would, and record evidence for every step. Senior pentesters review each finding before it reaches you.
Scope-bound by design
Relentless.
Never reckless.
Every agent action runs inside a consent-gated, rate-limited scope you authorize. Destructive actions are blocked at the tool boundary. Nothing crosses the walls you set.
- Authorized scope only, enforced at runtime
- Evidence encrypted at rest, every access audited
- Reports in English and Portuguese (LGPD / ANPD / BACEN)
02 /From first contact to final report
72 HOURS. FOUR MOVEMENTS.Seventy-two hours.
Zero guesswork.
A Horda engagement follows the same four movements a real intrusion does. You watch every one of them in the console, as it happens.
The swarm maps every wall.
Agents enumerate domains, services, APIs and identities across your authorized scope and build a shared exploration graph of your attack surface.
Book a call
Weaknesses get chained, not listed.
Agents plan and execute attack paths the way an adversary would: credential paths, logic flaws, misconfigurations and privilege chains, under rate and blast-radius limits.
Book a call
A senior pentester signs each finding.
Every finding is reproduced, rated and attested by a human reviewer, with the evidence trail attached. Unconfirmed results never reach your report.
Book a call
A report you can act on and audit.
Executive summary, technical detail, reproduction steps and remediation guidance in English and Portuguese, followed by a retest of what you fixed.
Book a callThreat landscape / 2026
The attackers
got a horde first.
In late September 2026 an unknown, financially motivated actor used an open-source agentic penetration-testing tool to breach multiple South Korean financial institutions within days, running on off-the-shelf LLMs. One operator. Many intrusions. No team. Read CrowdStrike's analysis
The patch window is gone.
When almost nine in ten exploited vulnerabilities are hit on day zero, waiting for a CVE to appear is waiting for the breach.
An annual pentest covers one month.
Your perimeter changes every sprint. A yearly report describes a fortress that no longer exists.
One operator is now a horde.
Agentic tooling lets a single actor run many intrusions in parallel. Defense has to scale the same way.
03 /Where the horde strikes
Every wall,
every gate.
Web applications and APIs, cloud and infrastructure, internal networks and mobile backends. If it is in scope, the swarm probes it the way an adversary would, and documents what it finds.
GATEHOUSE / WEB & API
Web apps & APIs
Authentication flows, business logic, injection, access control and API abuse, chained end to end.
RAMPARTS / CLOUD & INFRA
Cloud & infrastructure
Misconfigurations, exposed services, identity and privilege paths across AWS, GCP and Azure.
THE KEEP / INTERNAL & MOBILE
Internal & mobile
Lateral movement, internal services, mobile backends and the paths an insider would take.
Humans sign. Illustrative image generated with AI
04 /Validated, not just generated
The swarm finds.
A human
confirms.
AI finds more, faster. It also hallucinates. Every Horda finding is reproduced and attested by a senior pentester before it enters your report, with evidence attached.
Reports come in English and Brazilian Portuguese, structured for LGPD, ANPD and BACEN requirements, with one fail-closed rule: nothing partial gets published.
Plans / Two ways to stay ahead
One siege.
Or a standing army.
Start with a full 72-hour pentest. Keep the swarm on your walls with monthly validation on a yearly plan.
Pentest 72h
A complete AI-driven penetration test of your scope, with human-validated findings in 72 hours.
US$ 5,990 / engagement
R$ 29.990 for companies in Brazil
72 hours of continuous swarm testing
Full report in 72 hours
Executive summary, technical findings with reproduction steps, evidence, remediation guidance and a retest window.
- Web, API, cloud and internal scope
- Senior pentester review on every finding
- Report in English and Portuguese
- Retest of fixed findings
Monthly Validation
Continuous validation against new threats and zero-days: 24 hours of swarm testing every month, on a yearly plan.
US$ 599 / month
R$ 2.990 / month for companies in Brazil
24 hours of swarm testing per month
Zero-day re-checks
Every month the swarm re-runs your scope against newly disclosed CVEs and attack techniques, re-validates fixed findings and flags drift.
- Monthly validation report
- New CVE and zero-day re-checks
- Drift and regression alerts
- Priority scheduling for retests
Prices in USD; BRL prices apply to companies in Brazil. Monthly Validation is a 12-month plan billed yearly. Taxes not included. Scope is confirmed on the call.
Before the siege
Good question.
Here goes.
What teams ask us
before the first engagement.
Is it safe to run against production?
Yes, when you want it to be. Every agent action is bound to the scope you authorize and runs under rate limits, blast-radius limits and a destructive-action block enforced at the tool boundary. Many customers start on staging and move to production once they trust the limits.
What do I need to provide?
A written scope (domains, IPs, applications, cloud accounts), a signed authorization and a point of contact. Credentials for authenticated testing are optional and make the engagement deeper.
How is this different from a vulnerability scanner?
A scanner lists known CVEs. Horda chains weaknesses into real attack paths, exercises business logic and access control, and every finding is reproduced by a human before it reaches you.
Who validates the findings?
Senior penetration testers. Each finding carries a reviewer attestation and an evidence trail, and the report refuses to publish anything that was not confirmed.
Do you deliver reports for LGPD, ANPD or BACEN?
Yes. Reports are available in English and Brazilian Portuguese and structured so your compliance team can map findings to LGPD, ANPD guidance and BACEN requirements.
How fast can we start?
Book a 30-minute call. We confirm scope and authorization, and the 72-hour clock usually starts within a week.