Continuous AI penetration testing for web, API & cloud.
Real exploitation with reproducible proof of concept, from $69 per scan — with the evidence pack NIS2, DORA and ISO 27001 auditors ask for.
Annual pentests miss what ships on Tuesday.
A pentest signed off in January describes a system that no longer exists by March. Your team ships continuously. The attackers iterate continuously. The audit cadence is the only thing that hasn’t moved.
The result is a widening gap between what your last pentest verified and what is actually exposed to the internet today. That gap is where breaches are born — and where insurers, auditors and regulators are starting to look first.
AssurePort closes the gap by running the same depth of test your annual provider runs, but on every meaningful change — pull request, deploy, new endpoint, new cloud bucket, new domain.
A continuous penetration testing platform — not a scanner.
AssurePort is a continuous penetration testing platform that combines AI agents — trained against the OWASP, MITRE ATT&CK and CWE corpora — with deterministic security checks to find, prove and explain exploitable vulnerabilities across web applications, REST and GraphQL APIs, GitHub repositories and cloud configurations. It is operated from the European Union, with all data, scan logs and AI inference contained within EU-hosted infrastructure (Cloudflare EU + Fly Frankfurt + Anthropic EU endpoint).
AssurePort is not a vulnerability scanner with marketing on top. Scanners tell you what might be wrong. AssurePort proves what is exploitable, on your specific configuration, with a reproducible proof-of-concept attached to every critical finding.
Three steps to your first report.
No agents to install. No long onboarding. Sign up, point us at something, and read the report.
Connect
Point AssurePort at a domain, a Git repository or a cloud account. Connections are read-only by default and revocable in one click.
Test continuously
AI agents run authenticated scans, business-logic probes and controlled exploit attempts — every action mapped to OWASP, MITRE ATT&CK and CWE.
Get auditor-ready reports
Each finding ships with severity, a reproducible PoC, the suggested remediation and CWE/CVE references. Export to PDF or JSON.
14 Free Threat Intel Tools. Zero Sign-up.
Diagnose DNS, TLS posture, security headers, tech stack, and email security instantly from the edge.
4 featured below — all 14 are one click away in the full toolkit.
CryptoCheck Grader
Check cryptographic hygiene, TLS/HSTS configuration, and post-quantum readiness with a viral SVG badge.
Security Headers Grader
Score HTTP security headers (CSP, HSTS, CORS, SameSite) from A+ to F with actionable fixing advice.
DNSBL Blacklist Audit
Verify if your public mail server or domain IP is listed on major spam reputation blocklists.
Email Spoofing Check
Audit SPF, DMARC, and DKIM policies to prevent attackers from sending emails as your domain.
One platform. Every surface that matters.
Stop assembling six scanners, a consultancy and a Friday-night spreadsheet. AssurePort covers every surface your auditor will ask about.
Web applications LIVE
OWASP Top 10, business-logic abuse, broken authentication, IDOR — full proof-of-concept.
REST / GraphQL APIs LIVE
OWASP API Top 10 2023. Auth bypass, BOLA, mass assignment, injection.
GitHub / Supply chain LIVE
Leaked secrets, vulnerable dependencies, IaC misconfigurations.
Cloud posture LIVE
AWS, Azure, GCP, Kubernetes. CIS Benchmark aligned. IAM blast-radius, exposed buckets, K8s API surface.
Active Directory LIVE
Kerberoasting, ACL gaps, DC recon. Read-only, non-destructive AD security assessment.
SAP LIVE
NetWeaver / S/4HANA auth gaps, ABAP and RFC misuse. Read-only analysis.
Email Security LIVE
SPF/DKIM/DMARC validation, phishing-kit detection, passive mail infrastructure reconnaissance.
Network / Host LIVE
TCP port and service discovery, product fingerprinting, and no-authentication exposure detection (open Redis/Elasticsearch/MongoDB/Docker API, anonymous FTP, SMTP open-relay). Detection only — no exploitation.
OSINT / Recon LIVE
Passive and light-active external footprinting: WHOIS/RDAP, certificate-transparency subdomain enumeration, full DNS records, origin-IP discovery behind a CDN, live subdomain probing. Your public attack surface, mapped.
Scan Import LIVE
Import an existing Nessus, OpenVAS, Nmap, Burp, CSV or PDF report and get an AI-triaged summary mapped to GDPR/NIS2/ISO. Turns raw findings into prioritised insight.
PCI-DSS External Vuln Scan LIVE
Quarterly external vulnerability scan following PCI-DSS Requirement 11.3.2 (ASV-style methodology). Automatically calculates CVSS v3.1 compliance and generates auditor-ready readiness reports. AssurePort is not a PCI SSC Approved Scanning Vendor; this scan does not replace a scan by a listed ASV.
Your data is the product you are protecting. We treat it that way.
We built AssurePort with the assumption that the security teams using it would read our architecture diagram, our independent pentest report and our DPA before granting access. They do. Here is what they read.
Your data never trains our models.
All scan inputs, code excerpts, screenshots and findings are processed inside isolated, tenant-scoped containers. Nothing you give us — not a line of source code, not a screenshot, not a URL — is used to train AssurePort’s models or any third-party model. Contractually binding in our DPA. Anthropic EU endpoint enforces this at the infrastructure level.
EU-only infrastructure.
AssurePort is hosted exclusively on European infrastructure — Cloudflare Workers (EU edge regions), Fly.io (Frankfurt), Cloudflare R2 (EU jurisdiction), Resend (EU). Anthropic AI inference is routed to the EU endpoint. Data, logs, AI inference and backups never leave the EU.
AI you can audit.
Every action an AssurePort agent takes is logged with the model used, the prompt, the tool call and the resulting output. You can replay any scan minute-by-minute and export the full trace for forensic review. 7-year retention, aligned with GDPR Article 32.
Read-only by default.
AssurePort never writes to your production systems, never executes destructive payloads, and never persists credentials beyond the lifetime of an authenticated scan. Domain Control Verification (DCV) and Rules of Engagement (RoE) validation are enforced as hard gates before any Advanced Mode scan proceeds.
Every finding ships with a reproducible PoC.
We refuse to ship a critical-severity finding without a proof-of-concept you can rerun in your own environment. If we cannot reproduce it deterministically, we do not call it critical. Period. Findings without a working PoC are automatically downgraded to unconfirmed.
We pentest AssurePort, too.
Our own platform is pentested before every release. The latest self-pentest report (May 2026: 5 findings, all remediated; SSRF + path-traversal + info-disclosure) is published on our Trust Center. External CREST-accredited audit is on our roadmap for Q4 2026 — Q2 2027 alongside ISO 27001 certification.
No model training. No data leaving the EU. Every action audit-logged.
The honest comparison.
| Annual pentest | DIY scanners | AssurePort | |
|---|---|---|---|
| Frequency | Once a year | On-demand, manual | Continuous, on every change |
| Surfaces covered | What you pay for | One per tool | 11 engines live today |
| Time to first report | 4–8 weeks | Hours of setup | Minutes, not weeks |
| Proof-of-concept per finding | Sometimes | No | Always (reproducible) |
| Auditor-acceptable | Yes | No (raw output) | Yes (CWE/CVE/OWASP mapped) |
| Remediation guidance | Rarely | No | Yes, per finding |
| Annual cost (mid-size org) | €40k–€120k | €15k+ in licences | From $69 one-time / $199 monthly |
We publish what we actually do.
No fabricated case studies. No anonymous metrics. We make claims we can back with a link.
Latest self-pentest
10 August 2026, Web engine, our own platform: no vulnerabilities confirmed. The previous run (May 2026) found 5 — SSRF, path-traversal and info-disclosure — all closed before release. The PDF includes what the assessment could not cover.
Read the full report →Public security disclosure
RFC 9116 security.txt with PGP-signed contact. Responsible disclosure policy. Researcher reports processed within 5 business days.
View security.txt →Open certification roadmap
ISO 27001 + external CREST audit targeted Q4 2026 — Q2 2027. Public commitment, tracked monthly on our Trust Center.
View roadmap →“We chose ‘continuous AI pentest’ as a category because the alternative — annual pentest + quarterly scanner reports — was demonstrably failing the customers we talked to. We publish our own findings. We publish our own roadmap. We publish our own architecture. That’s the bar.”AssurePort engineering team — May 2026
What we are building next.
We build in public. Here is a transparent look at our upcoming capabilities and release schedule.
Alternative Domain Verification
Verify domain control quickly using automated administrative email codes (security@, admin@) or placing a meta-tag in the homepage header, bypassing DNS delays.
Slack & Teams Notifications
Get instant, real-time vulnerability alerts and scan completion reports delivered directly to your engineering channels with action links.
Agent-to-Agent Threat Feeds
Connect multiple isolated scanning agents together to dynamically share OSINT indicators and coordinate passive external threat intelligence.
Frequently asked questions
Is AI penetration testing actually reliable?
unconfirmed rather than published as critical.Will my code or data be used to train AI models?
Where is my data stored?
How is AssurePort different from a vulnerability scanner like Nessus or Burp Suite?
Does AssurePort replace human penetration testers?
What compliance frameworks does AssurePort support?
How quickly can I run my first scan?
How much does AssurePort cost?
Run your first scan in the next ten minutes.
No sales call. Creating an account is free — you only pay when you run a scan. Not ready? The free surface scan above needs no signup at all.