Agentic pentesting,
finally governed.
Alpha Active Cyber tests your security continuously with AI agents supervised by experts: every action scoped to your rules, approved when it matters, and provable afterwards.
The platform
An elite team,
under your mandate.
The most disciplined offensive engine on the market: playbooks, payloads, evidence — orchestrated by your LLMs, on your infrastructure, under your governance.
Tested atomicities, input/output contracts, vulnerable/secure oracles.
Web, AD, AWS/Azure/GCP, API, mobile, K8s… each specialist can run on the model of your choice — Anthropic, OpenAI, Gemini, OpenRouter, local Ollama — with a budget cap.
Expected universe of 12 axes, hashed snapshot. “Not observed” stays a gap — never a cosmetic “0 vulnerabilities”.
Every claim bound to primary, timestamped, indexed evidence.
sha256: f92c…b41e
claims: [observed] IDOR doc-4482
One-click Burp Suite preset + any MCP server (nuclei, playwright…). Tools feed straight into the agent's loop.
Runs from your Kali VPS, resumes after interruption, traced handoff/retest/cleanup, MD/HTML/DOCX reports.
Native governance
The agent proposes.
You decide.
100% autonomous recon. Exploitation, password attacks, state changes: every intrusive action stops in front of you — exact command, model justification, risk level.
Double anti-drift lock
Production policy engine + runtime scope engine. Even an LLM hallucination cannot leave the contract.
Live operator questions
The agent asks you for clarifications (creds, fuzzy scope), waits for your answer, then resumes.
Full audit trail
Every decision — who, what, when, why — signed in the journal. Zero out-of-scope action.
Password spraying — Entra ID directory
Agent justification: “3 provided test accounts are valid; the contract allows spraying at 2 req/min; client lockout threshold: 5. I'm staying at 2.”
Audit journal — decisions
Why now
European regulation now demands continuous proof.
DORA, NIS2 and the CRA make the “annual pentest” insufficient: continuous validation, traceability and auditable deliverables are becoming the norm — exactly what the platform produces.
DORA applies
Operational resilience for financial entities; TLPT testing for designated entities.
NIS2 in force
Supervised cyber risk management for essential and important entities.
CRA — reporting
Notification of actively exploited vulnerabilities and severe incidents.
CRA — core obligations
Security of digital products across their entire lifecycle.
References: EUR-Lex — DORA (EU) 2022/2554, NIS2 (EU) 2022/2555, CRA (EU) 2024/2847. This is not legal advice.
Real-world results
Already validated on a demanding public program.
Four receivable, reproducible, normalized reports submitted to Mistral AI's bug bounty program — executed by the platform under authorized mandate, confirmed at triage.
Web Cache Deception
User data (Intercom fields) exposed through cache manipulation. CVSS 6.0 — confirmed at triage by the program team.
CSRF protection bypass (×3)
CSRF protection bypassable on three conversation-sharing endpoints (chat.shareCreate, tRPC).
Unvalidated CSRF cookies + oracle
Cookies issued but never validated; the endpoint serves as a user-ID enumeration oracle.
No rate limiting
50 shares created in 0.8 s on the sharing endpoint — no rate limit observed during the test.
Actions journaled
every action written to the signed journal — denominator: the journal itself
Out-of-scope action
detected across our tests — volume and period detailed under NDA
Receivable reports
submitted to Mistral AI's public program — including the P2 confirmed at triage (CVSS 6.0)
Positioning
Between human pentesting and scanners, the missing slot.
Neither a replacement for the expert nor yet another tool: the continuity of scanners, the depth of a pentest, the governance of an advisory firm.
| Human pentest | Scanner / BAS | Generalist AI | Alpha | |
|---|---|---|---|---|
| Coverage & frequency | point-in-time | continuous | on demand | continuous |
| Exploitation depth | high | limited | not tooled | controlled |
| Evidence & traceability | report | alerts | none | signed journal |
| Human governance | native | partial | user's responsibility | risk-tiered approvals |
| Sovereign deployment | n/a | vendor-dependent | external cloud | on-premise / air-gap |
Internal Alpha analysis, September 2026, based on public documentation — dated table, revised quarterly.
Business model
Three offers, one adoption path.
An adoption path: start small, prove, expand — with responsibilities written into each model.
Targeted “exposure” mission
A short mission on a delimited scope — the low-risk entry point.
- Targeted scope (application, external, AD)
- Co-delivered execution, report signed before handover
- Signatory: Alpha expert
Managed continuous validation
Recurring or on-demand campaigns, supervised by our experts.
- Post-remediation retests with measured delta
- Expert supervision and periodic reviews
- CISO / risk committee reporting
Sovereign platform
Alpha deployed in the client's environment — on-premise or air-gapped.
- Client teams operate; Alpha trains and supports
- Operating governance and model
- Signed updates over a documented channel
Distribution amplified through co-delivery with advisory partners (risk advisory, GRC): the partner owns advisory and client relationship; Alpha industrializes execution and proof — the client keeps the decision.
Team
10 specialists, one rule: the expert signs.
A senior team backed by a network of certified partner experts — AI, offensive security, cloud, OT and compliance.
Ali Karki
MANAGING DIRECTOR
Former head of digital innovation within the Thales group. Strong track record in AI-driven KYC architecture optimization (notably at Crédit Agricole CIB). Specialty: data and AI governance — banking, insurance, finance.
Pascal Decary
EXECUTIVE COMMITTEE MEMBER
Seasoned executive — strategic roles within major international groups (SNCF, Keolis, Veolia). Recognized expert in organizational transformation, procurement and large-scale performance, across Europe and internationally.
Next step
A guided demo, on your test data.
Live console, signed journal replayed in session, technical Q&A. The demonstration dataset can be replayed during the meeting.
Guided demo — 60 min
Live console, signed journal replayed in session, technical Q&A.
Scoped POC — 2 to 4 weeks
Delimited scope, signed rules of engagement, measured results.
Co-delivered pilot mission
Full engagement with an expert-signed report and end-of-mandate review.
Or directly: contact@alpha-active-conseil.com