Skip to content

AI-powered penetration testing

Attackers now
come in hordes.
So do we.

Horda unleashes a swarm of AI agents against your perimeter, inside a scope you authorize, and hands you validated findings in 72 hours. Then it keeps testing, every month.

AI-DRIVEN. HUMAN-VALIDATED. Meet Horda
HORDA / SIEGE 001
BUILT FOR TEAMS THAT CANNOT AFFORD A BREACH Agent swarmAuthorized scope onlyHuman-validated findingsLGPD-ready reports

01 /A horde on your side

THOUSANDS OF AGENTS.
ONE SCOPE.

Not a scan.
A siege.

Horda is an AI-powered penetration testing platform. Instead of one consultant with a checklist, you get a coordinated swarm of autonomous agents that map your attack surface, chain weaknesses the way a real adversary would, and record evidence for every step. Senior pentesters review each finding before it reaches you.

A security operations room at night: one analyst in front of a wall display mapping an infrastructure with thousands of red probe markers
EVERY GATE. EVERY TOWER.01 — RECON

Scope-bound by design

Relentless.
Never reckless.

Every agent action runs inside a consent-gated, rate-limited scope you authorize. Destructive actions are blocked at the tool boundary. Nothing crosses the walls you set.

  • Authorized scope only, enforced at runtime
  • Evidence encrypted at rest, every access audited
  • Reports in English and Portuguese (LGPD / ANPD / BACEN)
Book a call

02 /From first contact to final report

72 HOURS. FOUR MOVEMENTS.

Seventy-two hours.
Zero guesswork.

A Horda engagement follows the same four movements a real intrusion does. You watch every one of them in the console, as it happens.

Horda console dashboard showing active agents, coverage and task status with demo data
DEMO DATA
PHASE 1 / RECONNAISSANCE

The swarm maps every wall.

Agents enumerate domains, services, APIs and identities across your authorized scope and build a shared exploration graph of your attack surface.

Book a call
Your scopeHorda swarmValidated report

Threat landscape / 2026

The attackers
got a horde first.

In late September 2026 an unknown, financially motivated actor used an open-source agentic penetration-testing tool to breach multiple South Korean financial institutions within days, running on off-the-shelf LLMs. One operator. Many intrusions. No team. Read CrowdStrike's analysis

Line chart titled Cyber Risk Goes Parabolic: critical and high severity CVEs per month from 2022 to 2026, flat around 200 then rising past 2,200 in 2026
2,300+critical and high CVEs in a single month of 2026
Critical and high severity vulnerabilities, monthly. Source: Epoch.ai, via a16z (9/3/26).
Combined bar and line chart titled Zero-Days-To-Exploit, Almost 90% Of The Time: the share of exploited CVEs exploited on or before disclosure rises from 18.7% in 2018 to 86.7% in 2026
86.7%of exploited CVEs in 2026 were exploited on or before disclosure day
Exploited CVEs where exploitation occurred before or on the day of disclosure. Source: Zerodayclock.com, via a16z (9/1/26).
  • The patch window is gone.

    When almost nine in ten exploited vulnerabilities are hit on day zero, waiting for a CVE to appear is waiting for the breach.

  • An annual pentest covers one month.

    Your perimeter changes every sprint. A yearly report describes a fortress that no longer exists.

  • One operator is now a horde.

    Agentic tooling lets a single actor run many intrusions in parallel. Defense has to scale the same way.

03 /Where the horde strikes

Every wall,
every gate.

Web applications and APIs, cloud and infrastructure, internal networks and mobile backends. If it is in scope, the swarm probes it the way an adversary would, and documents what it finds.

A developer's hands on a laptop in a dim office after hours, an API console on the screen with one line highlighted in red GATEHOUSE / WEB & API

Web apps & APIs

Authentication flows, business logic, injection, access control and API abuse, chained end to end.

A data center corridor at night, rows of server racks with blue status lights and one rack glowing red RAMPARTS / CLOUD & INFRA

Cloud & infrastructure

Misconfigurations, exposed services, identity and privilege paths across AWS, GCP and Azure.

An empty office floor after hours, one laptop still lit on a desk and a red badge-reader light on a glass door in the background THE KEEP / INTERNAL & MOBILE

Internal & mobile

Lateral movement, internal services, mobile backends and the paths an insider would take.

A senior penetration tester in a dark office at night, a screen with an attack graph and one red node behind her
HORDA / HUMAN REVIEW Agents attack.
Humans sign.
Illustrative image generated with AI

04 /Validated, not just generated

The swarm finds.
A human
confirms.

AI finds more, faster. It also hallucinates. Every Horda finding is reproduced and attested by a senior pentester before it enters your report, with evidence attached.

Reports come in English and Brazilian Portuguese, structured for LGPD, ANPD and BACEN requirements, with one fail-closed rule: nothing partial gets published.

Senior reviewer attestationEvidence encrypted at restLGPD / ANPD / BACEN-ready
Book a call

Plans / Two ways to stay ahead

One siege.
Or a standing army.

Start with a full 72-hour pentest. Keep the swarm on your walls with monthly validation on a yearly plan.

Pentest 72h

A complete AI-driven penetration test of your scope, with human-validated findings in 72 hours.

US$ 5,990 / engagement

R$ 29.990 for companies in Brazil

72 hours of continuous swarm testing

What you get

Full report in 72 hours

Executive summary, technical findings with reproduction steps, evidence, remediation guidance and a retest window.

  • Web, API, cloud and internal scope
  • Senior pentester review on every finding
  • Report in English and Portuguese
  • Retest of fixed findings
Book a call

Monthly Validation

Continuous validation against new threats and zero-days: 24 hours of swarm testing every month, on a yearly plan.

US$ 599 / month

R$ 2.990 / month for companies in Brazil

24 hours of swarm testing per month

What you get

Zero-day re-checks

Every month the swarm re-runs your scope against newly disclosed CVEs and attack techniques, re-validates fixed findings and flags drift.

  • Monthly validation report
  • New CVE and zero-day re-checks
  • Drift and regression alerts
  • Priority scheduling for retests
Book a call

Prices in USD; BRL prices apply to companies in Brazil. Monthly Validation is a 12-month plan billed yearly. Taxes not included. Scope is confirmed on the call.

Before the siege

Good question.
Here goes.

What teams ask us
before the first engagement.

Is it safe to run against production?

Yes, when you want it to be. Every agent action is bound to the scope you authorize and runs under rate limits, blast-radius limits and a destructive-action block enforced at the tool boundary. Many customers start on staging and move to production once they trust the limits.

What do I need to provide?

A written scope (domains, IPs, applications, cloud accounts), a signed authorization and a point of contact. Credentials for authenticated testing are optional and make the engagement deeper.

How is this different from a vulnerability scanner?

A scanner lists known CVEs. Horda chains weaknesses into real attack paths, exercises business logic and access control, and every finding is reproduced by a human before it reaches you.

Who validates the findings?

Senior penetration testers. Each finding carries a reviewer attestation and an evidence trail, and the report refuses to publish anything that was not confirmed.

Do you deliver reports for LGPD, ANPD or BACEN?

Yes. Reports are available in English and Brazilian Portuguese and structured so your compliance team can map findings to LGPD, ANPD guidance and BACEN requirements.

How fast can we start?

Book a 30-minute call. We confirm scope and authorization, and the 72-hour clock usually starts within a week.

The siege starts when you say so

Fortify
before they arrive.

Thirty minutes with our team.
We map your scope and schedule the swarm.

Book a 30-min call