Skip to main content
own2pwn

EASM

AI-Native Pentest (AI-PTaaS)

EASM's AI-native validation, an autonomous agent that tries to exploit your critical findings.

On a High or Critical finding from a verified domain, you trigger an autonomous agent that tries to confirm exploitability with real offensive tooling (sqlmap, nuclei and others), run inside an ephemeral container with filtered egress. Bounded, quota-limited, honest: it is AI, not a human pentester, and it does not promise zero false positives.

Free account, hosted in the EU, domain verification required
only the findings that matter, on a verified domain
High / Critical
strict guardrails, 150,000 tokens per finding
20 steps · 300 s
validations a month depending on the EASM plan
2 to unlimited

Features

What the agent attempts to confirm a flaw.

An autonomous agent that tries to exploit

Not a chatbot, not a second scan pass. On a critical finding, the agent reasons, chooses its actions and chains steps to prove the vulnerability is actually exploitable, not merely plausible from the banner. If it succeeds, the finding moves to confirmed; otherwise it stays at detected. You keep the triage, we lower the noise.

Real offensive tooling, not a simulation

The agent has the same tools a human operator would use: sqlmap for SQL injection, nuclei for exploitation templates, and the rest of the kit depending on the finding. It runs them for real against the affected asset. That is what separates a confirmation of exploitability from a CVE correlation: here we try, we don't guess.

Bounded and quota-limited by design

Every validation runs under strict guardrails: 20 steps maximum, 300 seconds, 150,000 tokens per finding. The agent doesn't spiral, doesn't roam beyond the targeted asset and stops dead at the limit. Volumes are quota-limited per month: 2 on Discovery, 30 on Pro, 100 on Business, unlimited on Enterprise. Nothing unlimited running behind your back.

AI-native pentest pricing.

Discovery

€0

  • AI-Native Pentest module included in the EASM offering
  • In plain terms: the perimeter of a single domain name, 25 exposed assets at most.
  • 10 scans / mo
  • Multi-source discovery + more than 240 detection modules
  • CVE correlation and prioritisation by real exploitability
  • 2 AI-native validations / mo
  • Email alerts, 1 user
  • Free, no time limit and no credit card
Start for free
Recommended

Pro

€99 / mo

  • In plain terms: 5 domain names, 250 tracked exposed assets, 5 people on the account.
  • 100 scans / mo
  • 30 AI-native validations / mo
  • HMAC-signed webhooks (Slack, Teams, Discord, PagerDuty)
  • Jira, GitHub, GitLab, Slack integrations
  • PDF and CSV exports, API access (5 keys)
Subscribe

For businesses only, a company identifier is asked at the next step.

Business

€299 / mo

  • In plain terms: 15 domain names, 1,000 tracked exposed assets, no cap on scans.
  • 100 AI-native validations / mo
  • SSO, RBAC and role management
  • SIEM connector, custom integrations
  • Email support, prioritised handling
Subscribe

For businesses only, a company identifier is asked at the next step.

Enterprise

On request

  • In plain terms: the perimeter you set in the contract, no cap on domains or validations.
  • SSO / SAML, SCIM provisioning
  • Enhanced AI validation (extended reasoning)
  • GDPR-compliant DPA, master agreement and NIS2 guidance
  • A single point of contact: the pentester who runs it
Talk to a pentester

VAT not applicable (art. 293 B of the French tax code)

How it works

From setup to the first alert.

  1. 01

    A critical finding on a verified domain

    Validation only opens on High and Critical findings, and only for a domain whose ownership you have proven. No magic button on any URL on the web: the scope stays yours. The rest of your surface keeps being mapped by the non-intrusive EASM scan, as usual.

  2. 02

    You trigger the validation, by hand

    Because it's active testing, nothing fires on its own. You pick the finding, you launch the validation from the interface. The action spends one credit of your monthly quota (2 on Discovery, 30 on Pro, 100 on Business, unlimited on Enterprise), shown in real time. You decide when and on what, not the other way around.

  3. 03

    The agent attempts exploitation in a sandbox

    An ephemeral container with filtered egress starts up. The agent reasons about the finding, picks its tooling (sqlmap, nuclei and others), runs it against the affected asset and observes the result to adjust the next step. All of it under guardrails: 20 steps, 300 seconds, 150,000 tokens. At the limit, it stops, whatever the progress.

  4. 04

    Confirmed with proof, or left at detected

    If exploitation succeeds, the finding moves to confirmed and carries a redacted proof (secrets masked) you can review and share. Otherwise it stays at detected: the agent didn't prove exploitability, which doesn't mean it's impossible. We don't overread a failure into a false positive, and we never promise zero false positives.

Benefits

What proof of exploitability changes for your teams.

01

Lower the noise on your critical findings

A scanner hands you a list of probable vulnerabilities, correlated to the banner and version. Useful, but you don't know which ones actually lead somewhere. AI-native validation takes your High and Critical findings and actually attempts exploitation: what is confirmed surfaces with its proof, the rest stays at detected. You handle what is proven exploitable first, not what looks bad on paper. We don't promise zero false positives; we save you the most expensive triage.

02

It's bounded AI, and we own what it is

Let's be clear: this agent is artificial intelligence, not a human pentester. It doesn't replace the judgement of an OSWE-certified operator on a complex exploitation chain, a business authentication bypass or twisted application logic. It does one thing and it does it under guardrails: confirm, or not, that a critical finding is exploitable with standard tooling. Thorough human verification is our pentests, a separate offering. We'd rather draw the line than blur it.

03

Active validation, hosted in the EU

Unlike the EASM scan, which is non-intrusive by design, validation is active testing: it runs real tooling against the live asset, which can change its state. That's why it is manual, reserved for critical findings on a domain you have verified, and quota-limited. The models run in a European region via Vertex AI, with no training on your data, and your proofs stay isolated per account under European law. The test is real, the frame is explicit.

Overview

The platform in pictures.

Finding detail with the Validate with an AI agent panel, Evidence output and parametersThe Validate with an AI agent panel on a finding: the agent attempts exploitation, keeps the proof in Evidence, with its parameters. It is AI, not a pentester, and no zero false positives promised.
The prioritised finding (CVE, KEV and EPSS) on which AI validation can be triggeredThe finding prioritised by CVE, by KEV (confirmed exploitation in the wild) and by EPSS (probability of exploitation) you launch validation from. It's on cases like this, and only on a verified domain, that the agent runs.
The findings list you select a critical case to validate fromThe findings list sorted by severity: you pick the critical case to hand to the agent.

Why own2pwn

Why an agent, and where its abilities stop.

It is AI, not a human pentester

We say it in plain words because the market loves to blur the line. This agent confirms the exploitability of critical findings with standard tooling, under guardrails. It doesn't do twisted business logic, no creative exploitation chain, no human judgement on context. For that, there are our pentests, run by an OSWE-certified operator. Two offerings, two scopes, no confusion maintained.

Active testing owned, not a scan in disguise

The EASM scan is non-intrusive and runs on production without taking it down. Validation, on the other hand, executes real exploits against the live asset and can change its state. We don't hide that difference behind reassuring vocabulary: it is manual, reserved for critical findings on a verified domain, quota-limited, isolated in a sandbox. You know exactly what you trigger.

Real guardrails, not decorative ones

20 steps, 300 seconds, 150,000 tokens per finding, network egress filtered to the target's public IPs, container destroyed after use. These bounds aren't a brochure argument: they are the hard limits the agent operates within. An autonomous agent without guardrails is a risk; here the frame comes before the demonstration.

Hosted in the European Union

Anthropic's Claude models are called through Google Cloud Vertex AI in a European region, under standard contractual clauses, with no training on your data. Your findings, your proofs and the rest of your inventory stay under European law, isolated per account. Handing an exploitability proof to a US vendor exposes it to extraterritorial access requests; ours stays hosted in the EU.

Frequently asked questions

Your questions about AI-native pentesting.

Is AI validation intrusive?

Yes, and we own it. Let's separate two things. EASM discovery and scanning are non-intrusive by design: no exploitation, no destructive payload, redirects disabled, per-host rate capped, three-layer anti-SSRF guard. AI validation, on the other hand, is active testing: it runs real tooling (sqlmap, nuclei and others) against the live asset, which can change its state. The sandbox isolates the tooling (ephemeral container, egress filtered to the target's public IPs only), not your asset. That's why it is manual, reserved for critical findings on a domain you have verified, and quota-limited. We'd rather say it than hide it.

How is this different from a human pentester?

A difference in kind. The agent is AI: it confirms, or not, that a High or Critical finding is exploitable with standard tooling, under strict guardrails (20 steps, 300 seconds, 150,000 tokens). It doesn't do twisted business logic, no creative exploitation chain, no human judgement on your application's context. An OSWE-certified pentester chains weak vulnerabilities into full compromise, understands your business and thinks like a determined attacker. The two are complementary: AI validation lowers the noise at scale, the pentest brings thorough human verification. They are two separate offerings, and we don't pretend one replaces the other.

Where do the AI models run, and on what data?

Validation calls Anthropic's Claude models through Google Cloud Vertex AI, in a European region, under standard contractual clauses. No training on your data, no retention to improve a third-party model. Your findings, the exploitability proofs and the rest of your inventory stay under European law, isolated per account, with secrets masked before they are written. Handing an exploitability proof to a US vendor exposes it to extraterritorial access requests, at odds with GDPR and NIS2: we keep hosting in the EU.

Does it promise zero false positives?

No, and be wary of anyone who does. Validation confirms a finding when the agent manages to actually exploit it: that case, you can believe, proof in hand. But a validation failure doesn't mean the finding is a false positive: the agent didn't prove exploitability with its tooling and within its bounds, that's all. We don't overread failure, we don't turn absence of proof into certainty. What validation saves you is the most expensive triage: telling what is proven exploitable apart from what still needs investigating.

What tools does the agent actually use?

The same offensive tooling a human operator would use: sqlmap for SQL injection, nuclei for exploitation templates, and the rest of the kit depending on the finding type. The agent picks its tools based on the vulnerability and runs them for real in the sandbox. It's not another scan pass nor a finer CVE correlation: it's an exploitation attempt, with real tools, against the affected asset.

How is a validation triggered, and on what?

Manually, from the interface, only on a High or Critical finding from a domain whose ownership you have proven. Nothing fires automatically, because it's active testing. Each validation spends one credit of your monthly quota, shown in real time. You choose the finding and the moment; the scope stays strictly yours.

What are the validation quotas per plan?

2 validations a month on Discovery, 30 on Pro, 100 on Business, unlimited on Enterprise. Credits are counted per calendar month and reset on the 1st. AI-native validation is included in every EASM tier, with growing quotas: it's not a module sold separately, it's a facet of the platform.

What happens if the agent hits one of its limits?

It stops, cleanly. The guardrails are hard: 20 steps, 300 seconds or 150,000 tokens, the first limit reached ends the validation. The ephemeral container is destroyed, and the finding stays at detected if exploitation didn't succeed within the allotted frame. An autonomous agent without limits would be a risk; here the bound comes before the demonstration.

Is there a minimum term, and how do I cancel?

No minimum term. The subscription is monthly or annual (annual works out at ten months paid), renewed tacitly at each due date, and you cancel it at any time, with no justification to give: either you do it yourself from your billing area, or you write to contact@own2pwn.fr and the answer comes within 24 hours. No notice period to serve: cancellation takes effect at the end of the current billing period, and you keep access until then. In return, that period is not refunded pro rata. That is not a sales promise, it is article 7 of the terms of sale.

Do I need a credit card for the free plan?

No. The Discovery plan opens from the sign-up form, with no payment method: no card to enter, no counter starting after fourteen days. It is not a trial but a free plan with no time limit and its own quotas (1 domain, 25 tracked assets, 10 scans per month). The AI-Native Pentest module is included in it, not sold separately. A card only comes into play if you move to a paid plan, and payment happens on own2pwn.fr, by card only.

How long between payment and actual access?

Access opens immediately after the payment is validated. In practice: as soon as the payment is confirmed, the subscription is attached to your account and the plan quotas apply, with no manual step in between. If you subscribe without an own2pwn account yet, the payment creates one and you get an email to set your password: access is live as soon as that is done. If anything gets stuck, write to contact@own2pwn.fr, the answer comes within 24 hours.

Can I change plan mid-subscription?

Yes, and without starting over: the account, the domains you declared and the scan history stay in place, only the quotas change. Modules are never billed separately: AI-Native Pentest comes with the EASM subscription, so changing plan moves the quotas of every module at once. You request the change by email to contact@own2pwn.fr, stating the plan you want and the date it should take effect; the answer comes within 24 hours. What is settled on the billing side is that the period already paid for is not refunded pro rata (article 7 of the terms of sale); the exact amount and the effective date of the new plan are confirmed to you in writing before anything is validated.

What is kept as evidence after a validation?

When the agent confirms, it keeps a trace: request, response, path taken. The proof is redacted before it is written (secrets and tokens masked), so you can review it, show it to a team or attach it to a ticket without copying sensitive data. A confirmed finding arrives with something to believe, not just a green label.

Proof rather than an alert?

The agent works on a verified domain, within a monthly quota. For a human pentest, a reply lands within 24 hours.