Autonomous pentests with proof your team can ship
APVISO runs scoped, runner-controlled tests, validates exploitability, and returns evidence, remediation guidance, and retest status.
From scoped pentest to accepted security evidence.
APVISO coordinates the pentest engine end to end: scoped recon, authenticated exploration, specialist testing, safe exploit proof, report delivery, and targeted retests.
Before
Authorize
Scope, credentials, guardrails, and runner readiness.
During
Pentest
Recon, specialist agents, browser exploration, exploit proof.
After
Close
Reviewed findings, report delivery, remediation, and retests.
Runner
Job-scoped execution
Context
Auth, roles, flows
Testing
App, API, logic
Exploit proof
Safe impact evidence
Evidence
Proof and fix guidance
Handoff
Owner and retest
Proof gate
Unproven leads stay out of the report.
Signals are internal. Proof is what ships.
Traditional DAST hands your team an alert queue. APVISO runs a pentest workflow and keeps unproven leads out of the report, which is how shipped findings stay at 0% false positives.
0%
false-positive rate
Not 0% noise in the engine. 0% false positives in findings that make it into the report.
The rule is simple
If APVISO cannot reproduce impact and attach evidence, the lead stays internal.
Traditional DAST
Potential alerts
- Validation
- Your team confirms which alerts are real
- FP outcome
- False-positive cleanup is part of the workflow
APVISO pentest
Verified findings
- Validation
- The engine proves exploitability before reporting
- FP outcome
- 0% false-positive rate in shipped findings
Signal
Tool output, agent observations, and suspicious behavior stay internal.
Reproduce
The pentest engine tries to recreate the issue in scope.
Prove
Exploitability, impact, and safe evidence are captured.
Ship
Only confirmed findings become customer-facing report items.
APVISO can use scanner signals as inputs, but customer-facing findings require reproduction, exploit proof, and report-ready evidence.
Traditional DAST handoff
Review the alert list, remove false positives, then ask developers to reproduce what remains.
APVISO handoff
Open the report with proof, remediation guidance, owner handoff, and retest status already attached.
Findings land where work happens.
Route validated findings, retest status, and review evidence into the systems your engineering and security teams already use.
Built for security evidence that can be reviewed.
APVISO keeps the chain from scope to finding to retest visible, so teams can show what was tested, what was confirmed, and what changed after the fix.
Scoped authorization
Every run starts from explicit target scope, test intensity, and ownership confirmation.
Evidence trail
Findings carry reproduction steps, affected assets, screenshots, and retest history.
Customer-ready output
Reports are structured for engineering triage, security review, and audit requests.
Evidence your reviewers can follow.
APVISO turns verified penetration testing into evidence your team can use for vulnerability management, customer security reviews, procurement, and compliance conversations.
NIS2 Directive
EU 2022/2555
NIS2 requires essential and important entities to manage vulnerability handling, disclosure, and security risk. APVISO supports that program with repeatable technical testing, retest records, and evidence trails.
- Vulnerability handling and disclosure evidence (Art. 21.2e)
- On-demand security assessments with review-ready reports
- Evidence trails for risk and regulatory documentation
Review-Ready Reports
Every finding includes evidence, CWE mappings, reproduction steps, and remediation guidance for auditor, customer, and internal security review.
EU Data Residency
EU-hosted infrastructure and Enterprise deployment options help teams plan around data residency and procurement requirements.
OWASP APTS Conformance
v0.1.0 · self-assessedSelf-assessed conformance with the Autonomous Penetration Testing Standard — the governance standard for autonomous pentest platforms — at the tier you pick per engagement. Tier 1 Foundation by default; Tier 2 Verified and Tier 3 Comprehensive available via the Supervised and Advisory governance presets.
Self-serve for teams. Custom for partners.
License your self-hosted runners, targets, and concurrency. BYOK keeps model spend in your account; Partner and Enterprise handle wholesale, embedded, and custom deployment terms.
Billing cadence
Switch between monthly and annual plan pricing.
Pay per pentest · $19 per pentest
Fully refunded if a pentest finds nothing or errors out — you only pay for results. Or watch the demo replay before installing anything.
For early teams ready for teammates, automation, and no start cap.
Billed monthly
Includes
- Team members in one organization
- 3 runners and 3 concurrent pentests
- 10 active targets
- Scheduled recurring pentests
- Limited integrations
- No monthly pentest start cap
For growing teams that need more capacity and every integration.
Billed monthly
Includes
- 10 runners and 10 concurrent pentests
- 25 active targets
- Scheduled recurring pentests
- All integrations enabled
- APTS Tier 2 governance
- Priority email support
Need more than Team?
Partner and Enterprise are sales-managed for agencies, platforms, larger security teams, and custom volume.
Questions teams ask before the first review.
Short answers on how APVISO runs pentests, validates findings, prices usage, and handles evidence.
Built around proof
The answers below focus on what buyers need to trust an autonomous pentest workflow.
General
APVISO is a self-hosted autonomous penetration testing platform. Your runner executes the pentest in your own environment while APVISO coordinates jobs, streams findings, and produces reports through the dashboard.
Pricing
Security & Trust
Technical
Run an AI pentest for $19—refunded if it finds nothing.
Start a self-hosted pentest from your own runner. You only pay when a run surfaces a finding; if it finds nothing or errors out, the charge is fully refunded. Upgrade to Launch or Team for unlimited scans, schedules, and integrations.
Pay per pentest
No subscription. $19 per pentest.