AI Pentesting
How Barrion's AI pentest works, what it costs, and what you get back.
An AI pentest tests your web app or API the way a real attacker would. It maps the attack surface, chains requests to confirm what is genuinely exploitable, and replays findings against your live app before they reach your report. A finding that fails its replay is dropped. A finding that can't be replayed is kept as a lower-confidence lead and is never marked confirmed. It is the active counterpart to passive scanning, which never logs in and never sends payloads.
Starting a pentest
Go to Pentesting in your dashboard and start a new run. The setup wizard walks you through:
- Application. What you are pentesting: a web app or an API. One target per run, in any environment you control and authorize; staging is the safer choice for a first run.
- Scope. Where to test, and the paths to leave alone. The agent tests thoroughly inside the scope and stays quiet outside it.
- Credentials. Optional. With test accounts for one or more user roles, the agent tests behind the login too, including access control between roles and tenants.
- Docs and context. Optional links and notes that help the agent understand your app.
- Summary. Pick a level and see the credits it reserves, prove you control the domain, and launch.
You can watch the run live in the dashboard. Most runs finish within hours; the level sets the cap. Findings are released together with the report.
Levels
| Level | Credits | Time cap | Expert review | For |
|---|---|---|---|---|
| Light | 400 | 2 h | -- | A quick read between deeper runs |
| Standard | 1,000 | 4 h | 1 h | A full pentest on a regular cadence |
| Deep | 4,000 | 8 h | 2 h | Larger apps, or the one test you run all year |
| Extended | 10,000 | 12 h | 4 h | Large products with many roles and tenants |
| Maximum | 20,000 | 16 h | 8 h | Everything we have, on one target |
Every level runs the same test classes, and every report maps its results to all 97 OWASP WSTG v4.2 cases, with a status for each. A deeper level puts more agents, more attack waves and more user roles on the same target, so it digs further.
Paying for a run
Pentests are paid in credits before the run starts. The run holds its level's credits, is charged for what it actually used when it finishes (minimum 100), and returns the rest. A failed run costs nothing. See Credits.
Expert review
At Standard and deeper levels, a Barrion security engineer reviews the results before the report is released, removing duplicates and false positives and checking how each finding is rated. You're emailed when the report is released. A Light run releases its report as soon as it finishes.
The report
The report is included with every run. It contains every confirmed finding with severity, the reproducible request and response, the affected surface, the mapped WSTG and CWE references, and remediation steps, plus a full WSTG coverage matrix. Download it as PDF, XLSX and JSON.
Retest
Once you have shipped fixes, rerun the same pentest as a retest. It reuses the original scope and credentials, checks each finding again, and marks it fixed, not fixed or inconclusive. A retest holds no credits. Test credentials are wiped 30 days after a run, so retest within that window or enter them again.
Scheduled pentests
On the Business plan (and AppSumo lifetime tiers 1 to 3), a saved pentest can rerun on a schedule: daily, weekly, monthly, quarterly, half-yearly, yearly or a custom interval. For each schedule you choose whether it runs every time or only when your app has changed. Each scheduled run labels its findings new, still open, fixed or regressed against the last run, and new or regressed findings are emailed to you.
Safety
Probes are rate-limited, stay inside the scope you approved and are non-destructive: no destructive payloads, no denial of service, no persistence. A test may change data to prove a finding (for example a mass-assignment or password-reset issue). The agent is instructed to undo that change and says so in the finding. Staging is supported if you'd rather test there.
Larger estates
For several apps, agreed rules of engagement, or a scoped engagement with a fixed price and timeline, contact sales.