Penetration testing,
fully autonomous.

AI agents that systematically test your web applications against OWASP standards. Launch a full-scope assessment with a single click. Now in private beta.

Request Early Access → See How it Works
app.runscarab.io
SCARAB assessment dashboard showing a completed penetration test with 77 findings across 904 endpoints

What is SCARAB?

SCARAB is an autonomous penetration testing platform that uses AI agents to systematically assess the security of your web applications and APIs. Instead of point-and-click scanners that check for known signatures, SCARAB deploys a team of specialized agents — each an expert in a different domain of security testing — that reason, adapt, and collaborate like a human penetration testing team.

Every assessment is grounded in industry-standard methodology with comprehensive coverage across reconnaissance, authentication, injection, authorization, configuration, business logic, and client-side testing. Results stream to your dashboard in real time, complete with evidence and remediation guidance. When testing is complete, generate formal PDF reports with AI-powered executive summaries, track finding remediation status, and get notified via Slack as vulnerabilities are discovered.

How it Works

01

Register Your Application

Add your target URL, configure scope rules, and provide credentials for authenticated testing. SCARAB validates connectivity and supports multi-role testing with separate user and admin accounts.

02

Configure & Launch

Choose a checklist preset — OWASP Top 10, API Top 10, or the full WSTG with 82 test cases. Pick your AI model, set agent iterations, and launch. Assessments run in isolated cloud containers or on your own infrastructure.

03

Monitor, Report & Remediate

Watch findings stream in real time with full HTTP evidence. Get Slack notifications as vulnerabilities are discovered. When complete, generate a formal PDF penetration testing report with an AI-powered executive summary.

Built for Real Security Testing

AI Agent Architecture

Six specialist agents coordinate through shared state. No fixed playbooks — agents reason about what to test and adapt to what they find, just like a human pentester would.

Real-Time Monitoring

Server-sent events stream every finding, endpoint, and checklist update to your browser as it happens. Full visibility into what each agent is doing and why.

Standards-Based Checklists

Choose from curated checklist presets — OWASP Top 10, API Top 10, or the full WSTG with 82 test cases. Track progress with per-item status and visual completion rings.

Full Evidence Chain

Every finding includes the complete HTTP request and response that triggered it. No false positives without proof — every vulnerability is demonstrated with reproducible evidence.

PDF Reports & Executive Summaries

Generate formal penetration testing reports ready for stakeholders. Each report includes an AI-powered executive summary, detailed findings, severity breakdowns, and remediation guidance.

Slack Integration

Connect your Slack workspace to receive real-time notifications as findings are discovered. Configure per-assessment channel overrides and get severity summaries delivered automatically.

Cloud or On-Premise

Run assessments in SCARAB’s managed cloud infrastructure on AWS, or deploy on-premise runners in your own environment. Customer-managed runners poll for work and report results back securely.

Teams & Workspaces

Collaborate with role-based access control across multiple workspaces. Invite team members as owners, admins, or members. Share findings, assessments, and applications across your organization.

Flexible AI Models

Bring your own Anthropic API key or use platform credits. Choose models per assessment, add a reviewer model for higher accuracy, and configure up to 400 agent iterations for deep testing.

What Gets Tested

Six specialist agents, each responsible for a different domain of security testing.

Recon

Server fingerprinting, endpoint discovery, technology mapping, API documentation analysis, and application route extraction.

Auth

Credential testing, session management, MFA bypass, password reset flaws, cookie security, session fixation, and cross-site request forgery.

Config

Platform configuration, HTTP methods, security headers, error handling, stack trace leakage, TLS/SSL scanning, and encryption verification.

Injection

Cross-site scripting, SQL injection, command injection, template injection, server-side request forgery, path traversal, and more.

Authz

Insecure direct object references, privilege escalation, authorization bypass, and cross-role comparison testing with multi-credential support.

Logic

Workflow bypass, race conditions, constraint violations, and application-specific logic flaws that traditional scanners miss entirely.

Pricing

SCARAB is currently in private beta. Pricing plans will be available at launch.

Individual
$0

Pay only for the tokens you use

  • Up to 5 assessments per month
  • Platform tokens (pay per use)
  • OWASP Top 10 checklist
  • Real-time streaming dashboard
  • PDF reports with executive summaries
  • Orchestrated scanning from SCARAB Cloud
Coming Soon
Enterprise

Tailored to your organization’s requirements

  • Everything in Organization, plus:
  • Dedicated tenant — on-premise, cloud, or VPC
  • Contractual data protection & sovereignty agreements
  • Custom checklists informed by your internal standards
  • Ingest client data to inform and guide testing
  • Dedicated support & onboarding
Coming Soon

Start testing today.

SCARAB is currently in private beta. Sign up below to get early access and be among the first to try autonomous penetration testing.