Logotype Alpha AlphaActive CyberPRO

Agentic pentesting,
finally governed.

Alpha Active Cyber tests your security continuously with AI agents supervised by experts: every action scoped to your rules, approved when it matters, and provable afterwards.

12coverage axes 0out-of-scope action 60specialist agents 100 %audited decisions

The platform

An elite team,
under your mandate.

The most disciplined offensive engine on the market: playbooks, payloads, evidence — orchestrated by your LLMs, on your infrastructure, under your governance.

Playbooks & payloads

Tested atomicities, input/output contracts, vulnerable/secure oracles.

7 750
+ 2,754 payloads · 800 attack chains · living base, continuously updated
60 specialist agents, your LLMs

Web, AD, AWS/Azure/GCP, API, mobile, K8s… each specialist can run on the model of your choice — Anthropic, OpenAI, Gemini, OpenRouter, local Ollama — with a budget cap.

web-appactive-directoryaws azureapikubernetes entra-m365mobilegraphql credentials
Proven coverage

Expected universe of 12 axes, hashed snapshot. “Not observed” stays a gap — never a cosmetic “0 vulnerabilities”.

routes 86%
inputs 79%
identities 74%
OWASP 81%
Tamper-proof evidence

Every claim bound to primary, timestamped, indexed evidence.

evidence/req-0912.http
sha256: f92c…b41e
claims: [observed] IDOR doc-4482
● Integrity verified
Native Burp & MCP

One-click Burp Suite preset + any MCP server (nuclei, playwright…). Tools feed straight into the agent's loop.

burp-repeaterproxy-historynuclei-scan
Resilient self-hosting

Runs from your Kali VPS, resumes after interruption, traced handoff/retest/cleanup, MD/HTML/DOCX reports.

0
byte that leaves your perimeter

Native governance

The agent proposes.
You decide.

100% autonomous recon. Exploitation, password attacks, state changes: every intrusive action stops in front of you — exact command, model justification, risk level.

Double anti-drift lock

Production policy engine + runtime scope engine. Even an LLM hallucination cannot leave the contract.

Live operator questions

The agent asks you for clarifications (creds, fuzzy scope), waits for your answer, then resumes.

Full audit trail

Every decision — who, what, when, why — signed in the journal. Zero out-of-scope action.

● High risk Awaiting operator · exp. 12:00

Password spraying — Entra ID directory

pentest-skill playbook run CRED-SPRAY-0042 --target login.acme.test --rate 2/m

Agent justification: “3 provided test accounts are valid; the contract allows spraying at 2 req/min; client lockout threshold: 5. I'm staying at 2.”

» The agent asks you “Does the staging.acme.test subdomain fall within scope? It hosts the same API as portal.acme.test.”
→ Your answer: “No, out of scope. Adding staging to the exclusions.” — the agent resumes.
Audit journal — decisions
09:41:03 tool.call nuclei scope-scan policy → auto
09:41:14 approval.requested CRED-SPRAY-0042 risk=high
09:44:52 approval.decided by c.marchand → approved
09:45:01 tool.call hashcat --show policy → auto

Why now

European regulation now demands continuous proof.

DORA, NIS2 and the CRA make the “annual pentest” insufficient: continuous validation, traceability and auditable deliverables are becoming the norm — exactly what the platform produces.

17 janv. 2025

DORA applies

Operational resilience for financial entities; TLPT testing for designated entities.

2026

NIS2 in force

Supervised cyber risk management for essential and important entities.

11 sept. 2026

CRA — reporting

Notification of actively exploited vulnerabilities and severe incidents.

Dec 11, 2027

CRA — core obligations

Security of digital products across their entire lifecycle.

References: EUR-Lex — DORA (EU) 2022/2554, NIS2 (EU) 2022/2555, CRA (EU) 2024/2847. This is not legal advice.

Real-world results

Already validated on a demanding public program.

Four receivable, reproducible, normalized reports submitted to Mistral AI's bug bounty program — executed by the platform under authorized mandate, confirmed at triage.

P2 — TRIAGED

Web Cache Deception

User data (Intercom fields) exposed through cache manipulation. CVSS 6.0 — confirmed at triage by the program team.

P3 — TRIAGED

CSRF protection bypass (×3)

CSRF protection bypassable on three conversation-sharing endpoints (chat.shareCreate, tRPC).

P4

Unvalidated CSRF cookies + oracle

Cookies issued but never validated; the endpoint serves as a user-ID enumeration oracle.

P5

No rate limiting

50 shares created in 0.8 s on the sharing endpoint — no rate limit observed during the test.

« Status changed to Triaged — we shared your report with the appropriate team. » official response from the Mistral AI program — final decision pending
100 %

Actions journaled

every action written to the signed journal — denominator: the journal itself

0

Out-of-scope action

detected across our tests — volume and period detailed under NDA

4/4

Receivable reports

submitted to Mistral AI's public program — including the P2 confirmed at triage (CVSS 6.0)

Positioning

Between human pentesting and scanners, the missing slot.

Neither a replacement for the expert nor yet another tool: the continuity of scanners, the depth of a pentest, the governance of an advisory firm.

Human pentestScanner / BASGeneralist AIAlpha
Coverage & frequencypoint-in-timecontinuouson demandcontinuous
Exploitation depthhighlimitednot tooledcontrolled
Evidence & traceabilityreportalertsnonesigned journal
Human governancenativepartialuser's responsibilityrisk-tiered approvals
Sovereign deploymentn/avendor-dependentexternal cloudon-premise / air-gap

Internal Alpha analysis, September 2026, based on public documentation — dated table, revised quarterly.

Business model

Three offers, one adoption path.

An adoption path: start small, prove, expand — with responsibilities written into each model.

01 — MISSION

Targeted “exposure” mission

A short mission on a delimited scope — the low-risk entry point.

  • Targeted scope (application, external, AD)
  • Co-delivered execution, report signed before handover
  • Signatory: Alpha expert
Revenue modelMission fees
02 — SUBSCRIPTION

Managed continuous validation

Recurring or on-demand campaigns, supervised by our experts.

  • Post-remediation retests with measured delta
  • Expert supervision and periodic reviews
  • CISO / risk committee reporting
Revenue modelARR — subscription + recurring services
03 — LICENSE

Sovereign platform

Alpha deployed in the client's environment — on-premise or air-gapped.

  • Client teams operate; Alpha trains and supports
  • Operating governance and model
  • Signed updates over a documented channel
Revenue modelLicense + integration + support

Distribution amplified through co-delivery with advisory partners (risk advisory, GRC): the partner owns advisory and client relationship; Alpha industrializes execution and proof — the client keeps the decision.

Team

10 specialists, one rule: the expert signs.

A senior team backed by a network of certified partner experts — AI, offensive security, cloud, OT and compliance.

Ali Karki

MANAGING DIRECTOR

Former head of digital innovation within the Thales group. Strong track record in AI-driven KYC architecture optimization (notably at Crédit Agricole CIB). Specialty: data and AI governance — banking, insurance, finance.

Pascal Decary

EXECUTIVE COMMITTEE MEMBER

Seasoned executive — strategic roles within major international groups (SNCF, Keolis, Veolia). Recognized expert in organizational transformation, procurement and large-scale performance, across Europe and internationally.

AI / LLM Research Engineer Offensive Security Lead Senior Pentester — Web & API Red Team Operator — AD ICS / OT Security Specialist Cloud Security Engineer Platform / Backend Engineer Frontend Engineer DevSecOps Engineer Compliance & Governance Officer

Next step

A guided demo, on your test data.

Live console, signed journal replayed in session, technical Q&A. The demonstration dataset can be replayed during the meeting.

n.1

Guided demo — 60 min

Live console, signed journal replayed in session, technical Q&A.

n.2

Scoped POC — 2 to 4 weeks

Delimited scope, signed rules of engagement, measured results.

n.3

Co-delivered pilot mission

Full engagement with an expert-signed report and end-of-mandate review.

Request a demo ↗

Or directly: contact@alpha-active-conseil.com

Offensive security

Frequently asked questions

What is agentic pentesting?

Agentic pentesting is penetration testing carried out by specialised AI agents, orchestrated and validated by human pentesters. Every action is scoped by your rules of engagement, approved when sensitive, and documented with actionable evidence.

How is automated pentesting different from a vulnerability scanner?

A scanner matches known signatures. AI-driven automated penetration testing chains reconnaissance, controlled exploitation and post-exploitation like a real attacker, then has every finding signed off by an expert: fewer false positives, concrete proof of impact.

What is continuous pentesting (PTaaS)?

Pentest as a Service replaces the one-off annual audit with continuous penetration testing: your attack surface is reassessed permanently, on every release, with remediation tracking and an evidence trail — the approach NIS2 and DORA expect.

Which scopes do you cover?

Web and API penetration tests, Active Directory, AWS, Azure and GCP cloud, mobile, Kubernetes, and internal or external infrastructure. Each specialist can run on the AI model of your choice, with a hard budget cap.

Does AI pentesting meet regulatory requirements?

Yes. Every campaign produces a time-stamped audit trail and defensible test evidence, aligned with the continuous-assurance requirements of NIS2, DORA and ISO 27001.