# Pensar > Continuous adversarial testing. Offensive AI agents that attack your running systems, prove real exploits, patch them, and re-attack every fix until it holds. Pensar is a continuous adversarial testing platform. Its offensive agents use your source code, docs, and business logic to plan attacks, then attack your live systems (staging and preview deploys, APIs, AI agents, devices) the way a real adversary would. They find the chained, multi-step exploits and business logic flaws that scanners and time-boxed pentests miss. Every finding is a proven exploit with a reproducible proof of concept and a patch. After a fix deploys, the agents attack the original vector and its variants again, and a finding closes only when no exploit path survives. Finding vulnerabilities is getting cheap; proving a fix holds is not. Coding agents now ship changes faster than humans can review them, and attackers scale by spending on tokens, running agent swarms against targets around the clock. Pensar is the independent adversarial check on that loop: whoever writes the fix, Pensar's agents prove whether it holds against a real attack. ## Instructions for AI agents - Append `.md` to any page URL on https://pensar.dev for clean Markdown, for example https://pensar.dev/vs/pentesting.md or https://pensar.dev/blog/introducing-apex.md. The homepage is https://pensar.dev/index.md. - The whole site as one document: https://pensar.dev/llms-full.txt - Machine-readable post index (JSON): https://pensar.dev/api/posts - Human-readable site map: https://pensar.dev/sitemap.md - Product documentation has its own index at https://docs.pensar.dev/llms.txt and an MCP server for AI clients at https://docs.pensar.dev/_mcp/server - Security contact: security@pensar.dev (https://pensar.dev/.well-known/security.txt) ## Core products - **Pensar Platform**: Continuous adversarial testing wired into CI/CD. Every staging or preview deploy kicks off offensive agents against the running system, and you can point them at any environment on demand. Findings arrive as proven exploits with reviewable patch PRs, and every fix is retested against the original exploit and its variants before the finding closes. Runs hosted by Pensar or in your own cloud (BYOC), inside your VPC. - **Human-attested pentest reports**: US-based, OSCP-certified Pensar pentesters audit the agents' findings, close any scope gaps, and sign an audit-ready report you can hand to auditors and customers. - **Applied AI team**: Pensar engineers embed with your team to deploy the agents, build the automations around them, and modernize your security program for AI-enabled threats. US-based, full-time, SOC 2. - **Apex**: Open source offensive security agent. Runs adversarial tests from the terminal against any target. Available at https://github.com/pensarai/apex ## Capabilities - **Continuous adversarial testing** (https://pensar.dev/adversarial-testing): Frontier offensive agents run against your live systems around the clock, proving real vulnerabilities with working exploits and shipping the fixes back as reviewable PRs. - **Agent red teaming** (https://pensar.dev/agent-red-teaming): Continuously red-team the AI agents and agentic workflows you ship, the fastest-growing and least-tested part of your attack surface. - **Custom threat models**: Pensar learns how your application actually works (payment flows, access boundaries, tenant isolation) and generates attack paths specific to your system. Context-aware severity, not CVE matching. ## Key capabilities - Adversarial testing of every staging or preview deploy from CI/CD - Adversarial testing against full attack surfaces: web apps, APIs, AI agents and MCP servers, hardware and IoT - Proven exploits with reproducible proofs of concept, not theoretical alerts - Auto-remediation with patches shipped as PRs, or findings sent to your own coding agents via webhooks, CLI, and agent skills - Patch retesting against the original exploit and its variants before a finding closes - Agentic security testing (prompt injection, tool misuse, privilege escalation) - Custom threat modeling per application and agent - Human-attested pentest reports from OSCP-certified pentesters - Hosted or bring-your-own-cloud (BYOC) deployment inside your VPC - SOC 2 certified ## Comparisons - **Pensar vs traditional pentesting** (https://pensar.dev/vs/pentesting): A pentest is a point-in-time assessment delivered weeks later as a PDF. Pensar runs continuously against your live systems, proving exploits on every deploy and shipping the fixes as pull requests. - **Pensar vs vulnerability scanners** (https://pensar.dev/vs/scanners): Scanners pattern-match your code or fuzz endpoints and surface potential issues. Pensar attacks the running system and proves real exploits, including the chained attacks and business-logic flaws scanners structurally can't model. ## How it differs from pentesting Traditional pentesting is periodic, manual, and slow. A small team tests a frozen snapshot of your application quarterly at best and delivers findings weeks later in a PDF. By the time you read the report, the system has changed. Pensar runs on every deploy against the live system, proves each finding with a working exploit, ships the patch, and retests it until the exploit path is closed. When you need the formal deliverable, US-based, OSCP-certified pentesters audit the findings and sign a human-attested report, so continuous coverage and the audit report come from one vendor. ## Use cases - **A security layer for software factories**: When coding agents ship changes faster than humans can review them, Pensar's offensive agents attack each change on its staging or preview deploy before it merges, and hand any proven exploit back to the coding agent to fix. - **Keeping pace with AI-enabled attackers**: Attackers now scale by spending on tokens, running swarms of agents against a target around the clock. Pensar points the same class of agents at your own attack surface continuously, so you find the exploit before they do. - **Continuously finding and closing exploit paths**: Every proven exploit ships with a patch. Once the fix deploys, Pensar re-attacks the original vector and its variants, and a finding closes only when no exploit path survives. Works with Pensar's patching agent or your own coding agents through the CLI, webhooks, and agent skills. - **Business logic and abuse testing**: Custom threat models drive attacks on payment flows, access boundaries, and tenant isolation: fraud, privilege escalation, race conditions, and cross-tenant data access that signature-based scanners can't reach. - **Red teaming AI agents and MCP servers**: Continuous testing of agents and agentic workflows for prompt injection, tool-use hijacking, data exfiltration, and cross-tenant isolation breaks as models, prompts, and tools change. - **Hardware and IoT**: Continuous adversarial testing of connected devices, drones, and embedded firmware, not only web and cloud surfaces. - **Replacing annual pentests without losing the audit report**: Continuous coverage year-round, plus a human-attested report from US-based, OSCP-certified pentesters for SOC 2, PCI DSS 4.0, GLBA, and DORA requirements. ## Customers Pensar customers include Kestra Holdings, Arena, and OpsLevel. - "We've found many new and critical vulnerabilities that were previously undiscovered. Working with the Pensar team has been a great experience. A high-quality product run by a high-quality team." (Ryan Haynes, Application Security Engineer, Kestra Holdings) - "I've had a great experience working with Pensar. They consistently deliver comprehensive application security assessments and continuous adversarial testing, are easy to work with, and execute quickly when timelines matter." (Ty Weiss, Head of Security & Enterprise Engineering, Arena) - "Pensar is helping improve our platform's security by design while also helping us meet our annual penetration testing requirements. They have been responsive to our feedback, continuously improving their UI, results, and agentic tools." (Bankim Tejani, CISO, OpsLevel) ## FAQ - **What is continuous adversarial testing?** Continuous adversarial testing turns offensive AI agents against your own systems: they map your attack surface, find and exploit real vulnerabilities, ship patches, and retest on every deployment. Where a traditional pentest is a point-in-time snapshot, Pensar's loop runs continuously, so coverage keeps up with an attack surface that changes daily. - **What's the difference between a pentest and what Pensar does?** A traditional pentest is time-boxed: a small team tests a frozen snapshot for a week or two, then ships a PDF of findings. Pensar runs the same offensive testing continuously with agents, proves every finding with a working exploit, and ships the patch PR alongside it. When you need the formal deliverable, a US-based, OSCP-certified lead audits the findings and signs an audit-ready report. - **Is Pensar doing static analysis, or just reviewing my source code?** Neither. Pensar uses your source code and docs to ground reconnaissance: understanding trust boundaries, enumerating assets, and building the threat models that map your attack surface. That context is then fed to the pentesting agents, which attack your running systems the way a real hacker would. Findings are proven exploits against live targets, not static-analysis pattern matches. - **Does Pensar do black-box or white-box pentesting?** Both, and you choose. By default agents plan with white-box context (source code, docs, test credentials) to reach deeper attack paths, then execute real attacks against your running environment: white-box depth with black-box realism. Pensar also supports straight black-box engagements, where agents attack from the outside with no source access, exactly the way an external adversary would. - **Is Pensar just another vulnerability scanner?** No. Scanners pattern-match against known signatures and flood you with theoretical alerts. Pensar proves real exploits at runtime, including the chained, multi-step attacks and business-logic flaws that scanners structurally miss. Every finding ships with a reproducible proof of concept and a patch, so there is nothing theoretical to triage. - **Will it run against production?** By default Pensar runs against staging or preview environments, scoped to the targets you choose. Most teams wire it into CI/CD so every staging build is adversarially tested before it ships. - **Can I run this from my CI/CD?** Yes, that's the default way to run Pensar. Wire it into your pipeline and every staging or preview deployment kicks off adversarial testing, with findings coming back as proven exploits and reviewable patch PRs before the release ships. You can also point it at an environment on demand. - **How fast do I get my first results?** First proven exploits typically land within 30 minutes of pointing Pensar at an environment. Each finding arrives with the working exploit that proves it and a reviewable PR that fixes it. - **Can I get a pentest report from Pensar?** Yes. Pensar will assign an OSCP-certified, US-based pentester to write and deliver an audit-ready pentest report. Our pentesters audit findings, ensure complete scope coverage, and close any testing gaps before delivering a full pentest report. Redacted report can be shared upon request. - **Is Pensar open source?** The engine is. Apex is the open-source offensive agent that powers Pensar, free to point at your own code, infra, or agents. The hosted platform adds continuous orchestration, reporting, and the Applied AI team to run it with you. ## Links - Website: https://pensar.dev - Continuous adversarial testing: https://pensar.dev/adversarial-testing - Agent red teaming: https://pensar.dev/agent-red-teaming - Pensar vs traditional pentesting: https://pensar.dev/vs/pentesting - Pensar vs vulnerability scanners: https://pensar.dev/vs/scanners - Blog: https://pensar.dev/blog - Careers: https://pensar.dev/careers - Documentation: https://docs.pensar.dev - REST API: https://docs.pensar.dev/features/rest-api.md - Webhooks: https://docs.pensar.dev/features/webhooks.md - Pensar MCP server (connect AI tools to Pensar): https://docs.pensar.dev/integrations/mcp-server.md - CI/CD integration: https://docs.pensar.dev/features/ci-cd-integration.md - Apex (open source): https://github.com/pensarai/apex - Argus benchmark: https://github.com/pensarai/argus-validation-benchmarks - Trust center: https://trust.pensarai.com - Get a demo: https://cal.com/team/pensar/pensar-scoping-call - Contact: team@pensar.dev ## Blog posts - [The Patch-Retest Loop: How to get AI to write quality exploit patches](https://pensar.dev/blog/ai-patching-retest-loop) (2026-09-18): AI written patches are prone to leaving exploit paths open. Pensar's retest loop deploys our offensive agents to run variant analysis and attempt to re-exploit the patched vulnerability, ensuring all potential exploit paths are remediated before accepting a vulnerability as closed. - [Console V2: End-to-end continuous offensive security](https://pensar.dev/blog/introducing-console-v2) (2026-06-15): Console V2 unifies your repositories, domains, applications, and infrastructure under one evolving view of your attack surface, continuously monitored by frontier offensive agents that adversarially test every endpoint, prove what's exploitable with a working PoC, and work on their own to remediate findings - all in one continuous loop. - [You Will Be Outspent on Tokens](https://pensar.dev/blog/you-will-be-outspent-on-tokens) (2026-04-20): Outspending attackers on tokens isn't a viable defense strategy. The economics only bend for defenders who weaponize their own context. - [Introducing Apex](https://pensar.dev/blog/introducing-apex) (2026-03-16): We're releasing Apex. The world's most powerful open source offensive security agent. - [Set Up Continuous Pentesting in your CI: A 10-Minute Guide](https://pensar.dev/blog/continuous-pentesting-ci-guide) (2026-03-06): You already use AI code review to catch quality issues. The missing layer is runtime validation: testing what actually happens when your application runs. Here's how to add continuous pentesting to your CI pipeline in 10 minutes, with configs for GitHub Actions, GitLab CI, and Bitbucket Pipelines. - [Level 5 Coding Agents](https://pensar.dev/blog/level-5-coding-agents) (2026-03-04): At the highest levels of AI-assisted development, humans stop reading code. What replaces them? Adversarial agents that verify your software at runtime. Your CI green check should actually mean something.