// SOVEREIGN AUTONOMOUS PENTESTING

The autonomous pentester that never leaves your perimeter.

Self-hosted offensive security for teams of every size — from solo consultants to MSSPs. Confirms exploits with reproducible PoC, maps attack chains, and certifies fixes. Your attack data stays in your infrastructure.

  • Self-hosted
  • PoC on every CONFIRMED
  • Attack chains
  • MSSP white-label
1.0
precision@confirmed on 29-case anti-FP corpus (BENCH-REAL)
42
attack phases per scan
3,054
tests in regression suite (Jul 2026)
2-signal
required for CONFIRMED
// raptor-scan · live output

Illustrative confidence funnel — see public benchmarks for reproducible runs.

47
raw signals
9
confirmed findings
Detect47
Re-probe23
Confirm9
CRITICALSQL injection — auth bypassCONFIRMED · PoC
Compliance-ready:OWASP Top 10MITRE ATT&CKPCI-DSSGDPRISO 27001CWECompliance mapping · not certified

// THE PROBLEM

Scanners cry wolf.

Legacy scanners report everything — and prove nothing. Security teams waste thousands of hours chasing false positives. Vex Raptor only reports what it can confirm.

1.0

precision@confirmed on the 29-case BENCH-REAL anti-FP corpus — verifiable

2-signal

independent confirmation before CONFIRMED — not single-reflection noise

// HOW IT WORKS

A 42-phase engine that thinks like the adversary.

Every scan runs four independent engines. Their outputs merge through a confidence pipeline that discards noise before anything reaches your report.

// 01Recon
// 02Web Attack
// 03API Fuzzing
// 04Network
//Confidence Pipeline
//Active Cross-Validation
//Enterprise Report
Native engineArsenal engineAI agent (Gemini ReAct)Vex API intel

// CAPABILITIES

Five pillars a senior pentester would reach for.

Confidence pipeline

Two independent signals plus a double-check re-probe before anything is CONFIRMED. Every finding scored HIGH/MEDIUM/LOW, guarded by a 3,000+ test anti-false-positive corpus (3,054 passed, Jul 2026). Includes real DOM-XSS detection via a headless browser.

Autonomous AI agent

A Gemini ReAct agent runs 42 attack phases without manual steering — with scope-lock and prompt-injection tripwires so targets cannot steer it off-engagement. Recall varies by app surface (see public benchmarks); it probes LLM, RAG, and agent/tool endpoints too (OWASP LLM + MITRE ATLAS).

Attack chains

Correlates related findings into board-ready narratives (IDOR + mass assignment → privilege escalation), mapped to MITRE ATT&CK — detection, not automated exploitation.

Verified remediation

We re-attack the same vector after your fix and certify it CLOSED or still-OPEN, with fresh evidence — proof the fix worked, not just a suggestion.

MSSP & compliance

White-label reports under your own brand, mapping to SOC 2 / PCI-DSS / ISO / GDPR controls (mapping only — not certification), and CI/CD build gating — turn pentesting into recurring revenue across your client book.

// CONFIDENCE PIPELINE

47 alerts detected. 9 confirmed.

Illustrative confidence funnel — see public benchmarks for reproducible runs.

The other 38 never reached your report as CONFIRMED.

CONFIRMED requires independent signals plus double-check re-probes — not a single reflection. HIGH/MEDIUM/UNCONFIRMED stay honestly labeled. precision@confirmed = 1.0 on our 29-case anti-FP corpus (BENCH-REAL); we engineer for very low false positives, not marketing absolutes.

See public benchmarks (BENCH-01 + multi-lab) →
01Detect

Multi-engine scanning generates raw signals from four parallel attack engines.

02Re-probe

Each signal triggers a targeted, safe active re-test — and a second independent signal for CONFIRMED.

03Confirm

Only findings that pass re-verification and the confidence pipeline are elevated to CONFIRMED. The rest are downgraded or discarded.

RAW SIGNALS47

raw signals

confidence pipeline
CONFIRMED FINDINGS9
SQL Injection / Auth BypassCRITICAL
IDOR — User data exposureHIGH
JWT alg:none acceptedHIGH
Rate limit bypass — /loginMEDIUM
+ 5 more...

confirmed findings

// FINDING REPORT
CRITICALCONFIRMED

SQL Injection — Authentication Bypass

CWE-89MITRE T1190
CVSS v3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8
Auto-applicable fix:
# Use parameterized queries
cursor.execute(
  'SELECT * FROM users WHERE email = %s',
  (email,)
)

// ENTERPRISE REPORTING

Reports a CISO can take to the board.

CVSS v3.1 vectors, CWE classification, MITRE ATT&CK techniques, reproducible PoC evidence, and ready-to-apply remediation — in HTML, PDF, or JSON.

Download sample report (HTML)

Anonymized lab scan — same layout as production deliverables.

CVSS v3.1 Full base, temporal, and environmental vector
MITRE ATT&CK Technique IDs with tactic context
CWE Classification Root cause weakness category
Reproducible PoC Exact request/response, safe to share
Output formats HTML · PDF · JSON — all from one scan

// DEPLOYMENT

Self-hosted. API-first. CI/CD-native.

Self-hosted

Deploy on your own infrastructure. No data leaves your perimeter. Docker-compose up in minutes.

API-first

Every capability exposed via REST. Integrate Raptor scans into any security workflow or SIEM.

CI/CD native

GitHub Actions, GitLab, any pipeline. Webhook scan on every deploy with pass/fail gating. Pentest as code.

Docker-ready

Multi-stage image with Postgres 16 + Redis 7 + Raptor. Full stack in a single compose file.

# docker-compose.yml
services:
  postgres:
    image: postgres:16-alpine
  redis:
    image: redis:7-alpine
  vex-raptor:
    image: vex-raptor:latest
    ports: ["8000:8000"]
  worker:
    image: vex-raptor:latest
    command: arq src.arq_worker.WorkerSettings

// VS THE MARKET

Built for what other tools can't do

Partial (—) = requires add-on, manual setup, or limited coverage

CapabilityVex RaptorBurp SuiteTenablePentera
Runs without manual operation (operator sets scope)
Confidence pipeline + double-check for CONFIRMED
DOM-based XSS detection (headless browser)
DAST crawler + injection point extraction
Active cross-validation per finding
Verified Remediation (re-attack + cert)
OODA memory (learns across scans)
Compliance mapping (SOC2/PCI/ISO/GDPR)
Self-hosted (data stays in perimeter)
CI/CD webhook + build gating
White-label for MSSPs
Published pricing without hidden seat modules

Based on publicly documented capabilities as of Q3 2026. We correct inaccuracies when reported.

// PRICING

From pilot to sovereign. Same engine, honest limits.

A manual pentest costs ~$18,000 and expires the day it is delivered. Vex Raptor gives you that same depth continuously — at a fraction of what autonomous enterprise vendors charge, without giving up data sovereignty.

Eval

Free

Evaluate the full pentest engine against one real target. No seed pack, no commitment.

  • 1 target · 1 full-depth scan
  • Hosted Eval console — not self-hosted
  • Full pentest stream — all attack phases
  • HTML + JSON reports
  • Community support

Pilot

$3,800

Flat · 90 days · non-recurring

If we don't find a single verified High or Critical finding, you don't pay.

Validate the engine against your own targets, with human review, no annual commitment.

  • Up to 5 targets
  • FULL depth on every scan
  • Self-hosted on your infrastructure
  • 1 live report walkthrough with the Vex team
  • PDF reports · compliance mapping
  • Email support

Essential

$7,800/year

Annual prepay · ≤3 targets

Continuous pentest for small attack surfaces — self-hosted from day one.

  • Up to 3 targets
  • FULL depth on every scan
  • Scheduled scans
  • PDF reports · compliance mapping
  • Self-hosted — your attack data never leaves your perimeter
  • Email support
Most popular

Professional

$19,500/year

Base ≤10 targets · +$1,300/extra target

A manual pentest, but continuous all year — verified remediation included.

  • Unlimited scheduled scans
  • Up to 10 targets (base)
  • Verified remediation — post-fix re-attack with evidence
  • Self-hosted — your attack data never leaves your perimeter
  • SSO/OIDC · RBAC
  • Priority support

Enterprise

From $43,500/year

MSSPs, regulated industries, sovereign deploys.

  • MSSP Partner path — multi-org white-label, partner resells with margin
  • Fully self-hosted · optional air-gap · BYO-LLM
  • Custom compliance mapping (SOC2/PCI-DSS/ISO/GDPR)
  • SLA + dedicated onboarding
  • 24/7 priority support

// PRICING MODEL

Value-metric: targets under management, not seats or a daily quota

A manual pentest costs ~$18,000 and expires the day it is delivered — a single snapshot. Vex Raptor charges for targets under management and continuity, not headcount or an arbitrary daily scan quota, because the AI agent does the work.

  • Per-seat pricing is legacy for AI security — value scales with targets under management
  • Enterprise autonomous vendors typically charge significantly more, often without full data sovereignty
  • Truly self-hosted: your attack data never leaves your perimeter
  • MSSP Partner resells with channel margin, with no added headcount on your side

// FAQ

Questions we hear often

If yours isn't here, email us at [email protected]

// READY?

See Vex Raptor attack your stack.

Book a live demo and watch the platform find, confirm, and remediate real vulnerabilities in your environment.