// page

AI Brain — penetration testing that never sleeps and gets smarter every day

A closed team of ten AI models hunts vulnerabilities around the clock, cross-checks each other’s findings and gets sharper every day.

AI Brain is a closed platform for automated, AI-driven penetration testing in which a target is worked by a team of frontier AI models at once, not a single tool. It is autonomous penetration testing kept under human control — automated penetration testing that runs continuously, not a one-off scan. The models run under an operator, share one memory and cross-verify each other’s findings. The platform never stands still: its skill library grows every day, and the system itself — local models included — keeps fine-tuning on every engagement.

Why a team of models beats a single one

A lone AI model on a long task loses context, repeats what it has already tried and reports guesses without proof. A signature scanner is limited to known patterns and never reasons about business logic. No single analyst can hold dozens of parallel hypotheses across a large target at once. AI Brain removes that ceiling: several models work different vectors in parallel, shared memory stops them duplicating effort, and every finding is independently reproduced by a different model.

That is how you surface chains that look harmless in isolation yet add up to full compromise. Below is a real scenario from our lab: six weak signals a scanner would close as “not critical”, chained by the team all the way to infrastructure takeover.

AI Brain kill-chain: open redirect, SSRF to cloud metadata, temporary AWS keys and access to a private S3 bucket chained into one critical scenario
Six separate low/medium findings the team chained into one critical scenario. No single model and no analyst held every link at once — the shared memory assembled the chain.

How the orchestration works

At the core is a design we call Man-in-the-Middle, a deliberate play on the classic “man in the middle” attack. The control seat is taken either by a conductor model or by the human operator, and both intercept the team’s flow and steer it. The conductor reads the shared memory, finds the gaps and hands out one mission per executor, prioritising unverified findings and uncovered vectors. The human steps in as pentest lead at any moment: a note to any model, roles changed on the fly, the team re-pointed, the final findings validated. Executors run in parallel, each in an isolated headless CLI, under strict read-only rules. On long runs the team switches to autopilot, and even then the operator stays in the loop.

AI Brain orchestration: Man-in-the-Middle control (conductor model or human operator), parallel executors and a shared memory of claims, probes, findings and verifications
The conductor hands out missions, executors work in parallel, the shared memory logs every probe, and a different model re-verifies each finding.

Why our findings are trustworthy

A lead is not a finding. There are five to twenty false signals per confirmed vulnerability, and AI Brain filters them out before the report. Self-verification is banned: the model that files an issue never confirms it — a different model reproduces it and runs a negative control. A vector is not closed until all ten depth classes are covered. Every probe stays in the ledger with its method, URL, status code and verdict, so your auditor gets the full trail, not a black box.

AI Brain dashboard: six models led by GPT-5, an SSRF via open redirect to cloud metadata with evidence and a negative control
A confirmed finding: SSRF via open redirect to cloud metadata. Evidence, negative control and a CONFIRMED verdict are recorded in the ledger.

Skills updated daily, continuous self-learning

Every confirmed report is distilled into a reusable skill: what worked, where the dead end was, what comes next. The skill library is closed and grows every day, so on a new engagement the team starts with accumulated experience rather than from zero. Local models deployed inside a client’s environment fine-tune on that client’s stack and past audits: the testing never leaves the perimeter and gets sharper with every run.

AI Brain skill library, the self-learning loop from reports, and local model fine-tuning on the client stack
A report becomes a skill; a skill becomes an edge on the next engagement. Local models fine-tune to a specific client stack.

The features that matter

Man-in-the-Middle control
The control seat is held by a conductor model or the human operator. Both intercept the team’s flow: dispatch missions, send findings for re-checking, change roles on the fly. Autopilot never takes the human out of the loop.
Up to ten models as a team
Claude, GPT, Gemini, Grok, Kimi, Qwen and more. Different approaches plus cross-checking give coverage no single model reaches, and one model failing does not stop the run.
Shared project memory
One ledger of claims, probes, findings and verifications. Models never hit the same point twice, never lose context, and inherit each other’s work.
Skills that grow daily
Reports become a closed skill library. It is the team’s accumulated edge — one we do not publish and update every day.
Local models and fine-tuning
Beyond hosted frontier models, AI Brain runs local ones that fine-tune to a specific target and stack. Sensitive testing stays inside your environment.
Hard scope, read-only
Allowed hosts and paths are baked into every mission. Read-only rules — GET/HEAD/OPTIONS, minimal POST, no more than two requests per second — keep the team inside the perimeter.

How we deliver it

You do not buy a tool and figure it out yourself. The default is a managed service: an operator drives the model team, validates the final findings and signs the report, so the expertise and accountability stay human. When testing has to stay inside your infrastructure, AI Brain is deployed on your own server under licence, with local models and fine-tuning for your stack. Either way you get systematic coverage in hours where manual work takes days.

Why the product is closed

We do not release the skills, the playbooks or the weights of our fine-tuned models. This is the team’s accumulated advantage, not a public library, so AI Brain ships only as a managed service or a supported licence. That keeps the methodology closed and lets us update the system every day without disclosing exactly how it finds vulnerabilities.

Live AI Brain dashboard: a team of AI models works a target and records probes and findings in shared memory
The model team at work: parallel probes, a depth matrix and cross-verified findings in one interface.

AI Brain sits alongside our other solutions. agentpipe scans your CI and agent configs, Airlock gates AI-agent actions at runtime, and AI Brain is the offensive engine that proves what an attacker could actually chain. See how it maps to a delivery in AI-powered penetration testing, or talk to us about a pilot on one of your applications.

AI Brain works alongside our AI & LLM security testing and red team & adversary simulation services — automated penetration testing that plugs into a full offensive-security programme.