Private betaContinuous security validation

A pentest that never stops.

Most pentests tell you what was vulnerable when the test ended. Umbra tells you what's exploitable now, validated against your actual systems before a finding reaches you, with the evidence to reproduce and fix it.

Start free: 25 assets, no card How it proves a finding

External · Web apps · Cloud · Internal · Credentials  ·  Non-destructive · read-only · re-tests free

← BackAttack Surface/Services59A · 1496Cidle
port:22 has_cve:true os:linux✦ AIGo
StatusHostPortProductCVEs
LIVE192.0.2.17wiki.example.com443Atlas Wiki 4.1.03 CVE
LIVE192.0.2.40api.example.com443Envoy 1.292 CVE
LIVE198.51.100.8bastion.example.com22OpenSSH 9.2p128 CVE
LIVE198.51.100.8bastion.example.com179––
GONE203.0.113.5legacy.example.com80Aws Cloudfront–
LIVE192.0.2.61mail.example.com25Postfix 3.8–
LIVE192.0.2.88vpn.example.com443OpenVPN 2.61 CVE
198.51.100.8 : 22LIVE
OPENSSH 9.2P1SERVICELINUX
Auto-exploit →⚡ Try a technique (3)
ResponseVulnsExploitCertificateLocation

AI exploitability validation proves whether a CVE actually works on this target, not just whether it matches the fingerprint.

HIGH 8.1CVE-2024-6387OPENSSH
VERSION-MATCHEDEPSS 100%Exploitable · 73s

Signal-handler race condition in sshd. An unauthenticated remote attacker may trigger it by failing to authenticate within a set time period.

sshd[2231]: timeout before authentication
> race window observed on 3 of 3 attempts
> SIGALRM handler re-entered · async-unsafe call
→ exploitable, unauthenticated · no shell obtained (non-destructive)
source: nvd1 Check · re-test free
Why continuous

A pentest is a person, a scope and two weeks. Then fifty weeks of not knowing.

It produces a PDF that is accurate on the day it is written and slowly stops being true, because your environment keeps changing after the engagement ends. Meanwhile your scanner produces thousands of matches a month and hands you the job of turning maybes into yeses.

Umbra makes the fifty weeks stop being a blind spot: the same rigour on asset 900 as on asset 1, at 3am, every day. Nothing reaches your queue until it survived an agent trying to disprove it.

01External
02Deep Audit
03Internal
04Cloud
05Credentials
06Findings
07Reports
08ChatOps
The engagement

Everything a pentest covers. One standard of proof.

Each surface produces candidates its own way. Every candidate meets the same validator, and every finding arrives in the same shape: what was tested, what came back, what it proves: and what to do about it.

01 · External attack surface

Every port, every version, every change, on the estate you define.

Give it domains, IPs and CIDRs. It sweeps all 65,535 ports by default, fingerprints what answers, matches versions against the full NVD with KEV and EPSS on top, and treats a match as a candidate to go and test, not a ticket to hand you.

-A new service, a version bump, a certificate change, a vanished host: each is an event on a timeline.
-Ask in English, “critical KEVs on internal apache”, and get the tokenised query in under a second.
-Pay for the assets you watch, not the ones it discovers. Scanning is never metered.
← BackAttack Surface/Services
Hosts 1,232Live 1,987Changed 24h 14KEV matches 6
StatusHostPortProductChange
● LIVE
192.0.2.40
api.example.com
8443nginx 1.24new service
● LIVE
192.0.2.17
wiki.example.com
443Atlas Wiki 4.1.0KEV · 3 CVE
● LIVE
192.0.2.61
mail.example.com
443Postfix 3.8cert rotated
● GONE
203.0.113.5
legacy.example.com
80Aws Cloudfrontvanished
● LIVE
198.51.100.8
bastion.example.com
22OpenSSH 9.2p1version bump
02 · Deep Audit · web applications

A full AI pentest of one application and the backends behind it.

A headless browser crawls the app the way a user does. A 56-module scan finds what rules find; an active Triager probes ambiguous results live instead of guessing. Then tiered agents hunt what scanners structurally can’t reach.

-IDOR, OAuth redirect bypass, JWT confusion, GraphQL abuse, mass assignment, price manipulation, multi-step account takeover, cross-tenant access.
-One Audit covers the app plus up to ten related backends, with no per-backend charge.
-If a run hits its budget, the report says exactly what wasn’t covered. No silent drop-offs.
FindingsMethodologyTimelineConfigDebug
Findings (6 of 6)
Deep Audit · 1 Audit · 6 backends
Mission scope:
app.example.com ★api.example.comeditor.example.comauth.example.comcdn.example.com
ALL 6HIGH 1MEDIUM 2LOW 3
SeverityFindingPathSource
HIGHBlind SSRF in tracking-code checker: server fetches attacker-controlled URLsAPI/api/v2/accounts/{id}AI EXPLORER SQUAD
MEDIUMRate-limit bypass on password-reset via spoofed X-Forwarded-ForAPI/api/v2/auth/forgotAI EXPLORER SQUAD
MEDIUMInternal management API docs exposed unauthenticatedAPI/doc/v2/AI EXPLORER DEEPEN
LOWCORS allowlist reflects insecure http:// origin with credentialsAPI/api/v2/userAI EXPLORER TIER3
LOWAnti-CSRF nonce in JS-readable cookie (_ct lacks HttpOnly)API/api/v2/authAI EXPLORER AUTH
03 · Internal pentest · enrolled agent

An attacker who is already inside. Mapped, tested, proven.

A 5 MB agent, one-line install, outbound HTTPS only. One click fans 54 named techniques across every live internal service (Active Directory, ADCS, Kerberos, SMB, databases, hypervisors), and the network map colours every host by its most severe proven finding.

-Safe, Active or Aggressive. You choose the blast radius, enforced server-side. Run Safe on a Tuesday afternoon.
-The AD attack graph populates itself in BloodHound vocabulary, with no separate collector.
-Included from Standard. Not a separate SKU, not a per-assessment charge.
← BackAssess & Validate/Network map: agent #32
AGENT
allcrithighmedlow
44 hosts · 44 visible
10.10.10.0/24 · Safe tier · 54 techniques
Posture
Critical25
High11
Medium3
Low1
At-risk hosts
■ 10.10.10.1080c
■ 10.10.10.7864c
■ 10.10.10.3018c
■ 10.10.10.6518c
Top exposed
SMB5
OpenSSH3
Jenkins2
Redis2
04 · Cloud posture · AWS, Azure, Google Cloud

Read-only in. An attack path and the exact fix out.

World-readable data, identities that escalate to admin, secrets in config, internet-open services, traced into paths that end at your data. Public storage is proven with an anonymous read, not inferred.

-Every finding ships the aws, gcloud or az command that removes it, built from the real resource id, with a guardrail and never auto-applied.
-Effective-permission analysis across SCPs and boundaries means fewer, right findings.
-Coverage is attested, so a clean result is never a blind spot.
← BackAssess & Validate/Cloud / Scan #5
Cloud scan
● complete · scan #5 · took 224s
1
CRITICAL
3
HIGH
0
MEDIUM
21 techniques evaluated · 3 accounts · read-only
● CRITICALEffective administrator (Action:* on Resource:*)
● HIGHS3 objects publicly readable (anonymously confirmed)
● HIGHRewrite a bucket policy to grant self access
● LOWOrg SCPs were not evaluated
CRITICALEffective administrator: iam_user umbra-benchmark
What’s wrong
The principal is allowed *: full administrative control of the account.
How to fix
TARGETED · apply to live policy
aws iam list-attached-user-policies --user-name umbra-benchmark
# remove the statement granting the escalation
# action, then detach/put the corrected policy.
⚠ Before you apply: confirm the principal doesn’t need the flagged action; scope to specific resources rather than blanket-removing.
Evidence
{ "enabling_actions": ["*"], "technique": "iam_admin_wildcard" }
05 · Credential exposure

Know when your people’s credentials surface. Before they’re used.

Verify a root domain and Umbra watches for accounts on it (employees, third parties, customers) appearing in exposed credential data, with where they leaked from and how strong the password was.

-A match is a finding like any other: same queue, same lifecycle, same notifications, same ticket.
-Reveal is gated and logged; resets can be enforced from the finding.
-The attacker who is already inside usually started with a password nobody knew was out there.
← BackAssess & Validate/Credential Exposure
example.comMonitoring since 9/3/2026 · 2 of 2 domains
Employees
12
3 reset enforced
Third party
4
vendors notified
Customers
990
strength captured
Where these leak from
community.example.com555
my.example.com332
http://community.example.com/login89
https://my.example.com/signup75
auth.example.com67
SourceAccountStr.Seen
my.example.com · /login newre●●●@partner.example6/109/2/2026
community.example.comXi●●●10/109/1/2026
my.example.com · /fa●●●@vendor.example6/109/1/2026
06 · Findings · remediation program

What to fix this week. Ranked, assigned, and re-tested for free.

Findings are stateful, not snapshots: open → in progress → fixed → verified, with won’t-fix for accepted risk. KPI tiles and a Lumi-ranked top ten sit above the list, so the week starts with the right ten items, not a thousand.

-Every finding carries its HTTP proof: request, response, analyst note, independent re-verification.
-Fix the bug and Umbra re-runs the exploit that worked. Free and unlimited, so a fix that silently reverts is caught.
-Close the Jira ticket and the finding closes. Close the finding and the ticket transitions.
← BackAttack Surface/Findings
What to fix in this viewExecutive report · Ranked by Lumi
Critical open
23
High open
41
Overdue
0
Fixed this week
7
MTTR
4.2d
Top 10 priority issues
CRITICALDCSync rights held by non-default principal10.10.10.10:389IN PROGRESS
CRITICALKerberos unconstrained-delegation feasibility10.10.10.10:389EXPLOITABLE
CRITICALGPP cpassword credential recovered (Administrator)10.10.10.10:445EXPLOITABLE
CRITICALRedis exposed without authentication10.10.10.50:6379EXPLOITABLE
CRITICALKubelet API open without authentication: /pods10.10.10.76:10250EXPLOITABLE
CRITICALPostgres default credential valid10.10.10.57:5432EXPLOITABLE
Lifecycle
ActiveOpenIn progressFixed (awaiting verify)VerifiedWon’t fix
07 · Reports

Hand it to your CISO. Or your client. Or the board.

Three audiences, three reports, one source of truth: a per-target engagement report with every verified finding and its PoC, a non-technical management summary in six languages, and an org-level executive risk report with posture KPIs and trend.

-Every finding linked to a reproducible PoC. No “potentially vulnerable” entries.
-Print → PDF or Markdown. Cloud posture ships the same branded template.
-One email a week: critical open, fixed this week, MTTR, top five risks.
04 · WHAT WE FOUND
Findings Overview
23
CRITICAL
41
HIGH
59
MEDIUM
35
LOW
22
INFO
IDSEVERITYCVSSFINDING
UMB-48-001CRITICAL8.8DCSync rights held by non-default principal
UMB-48-005CRITICAL9.1Redis exposed without authentication
UMB-48-016CRITICAL10.0Jenkins script console reachable without authentication (RCE)
UMB-48-022CRITICAL10.0Telnet: unauthenticated root shell: no credentials required
UMB-48-023CRITICAL10.0Kubelet API open without authentication: /pods access
Engagement report · Management summary (6 languages) · Executive risk report · PDF & Markdown
08 · ChatOps & integrations

Run Umbra from where your team already lives.

Install the Slack app once per org. Anyone in the workspace can triage findings, ask Lumi in plain English, or trigger a validation with a slash command: with the same permissions they have in the web app.

-Two-way Jira and GitHub Issues sync with PoC excerpt and replay link pre-filled.
-Every finding streamed to Splunk HEC or Microsoft Sentinel as a structured event.
-REST API with OpenAPI on every install; partner API with per-org keys.
← BackAutomate/ChatOps
Slack workspace connectedreplies scoped to this org · same permissions as the web app
Triage from chat
/umbra findings criticalLast 10 critical findings
/umbra runs verdict:exploitableAI runs that confirmed an exploit
Ask Lumi anything
/umbra ask what’s exploitable right nowNatural language → the right query
/umbra ask which assets are due this weekLifecycle-aware
Trigger validations
/umbra run Start an AI exploit run from chat
/umbra reportPull the exec summary
Jira ⇄ two-wayGitHub Issues ⇄Splunk HEC →Microsoft Sentinel →Webhooks →Weekly digest ✉
The step that makes it validation

Four engines produce candidates. One validator, whose job is to say no.

Every candidate is re-tested against the live target by a separate agent instructed to disprove it. These are the rules it runs under, not a description of them.

01
The default verdict is not exploited.
The burden of proof sits on the finding. "Plausible" is not a verdict.
02
Reproduction is not impact.
Before confirming, it states what an unauthorised party actually obtained.
03
Try to disprove it before confirming it.
The probe a sceptical bounty triager would demand before paying.
04
If the evidence is a change over time, rule out time.
A control probe repeats the original request afterwards. If it succeeds too, the clock explained it.
Candidate findings across production scans to date · 85 findings
41% of our own AI's candidates never reach you.
Proven exploitable50 · shipped with evidence
Disproved28 · dropped, never sent
Inconclusive7 · marked, not claimed

A small sample; we'll publish a larger figure when we have one rather than round this into a marketing number.

Built by someone who's been on the other side

They heard about their vulnerabilities from us. Not from an attacker.

Before Umbra, its founder reported 2,000+ confirmed vulnerabilities to the security programs of 1,000+ companies, including the ones below. Umbra exists because the tools available weren't operator-grade enough for that work.

AppleGoogleTeslaPayPalSpotifyCoinbaseGoldman SachsCloudflareShopifyAT&TSpaceXPlayStationAppleGoogleTeslaPayPalSpotifyCoinbaseGoldman SachsCloudflareShopifyAT&TSpaceXPlayStation
DellSnapchatAirbnbUberDropboxAtlassianHubSpotPinterestNetflixVolkswagenWells FargoSquareDellSnapchatAirbnbUberDropboxAtlassianHubSpotPinterestNetflixVolkswagenWells FargoSquare

Companies whose security programs accepted findings from Umbra's founder. Umbra is in private beta; these are not Umbra customers.

09 · Compliance evidence · for the person who signs the invoice

The audit evidence, generated from the work you already did.

Pick a framework. Umbra maps its own data (assets, scans, findings, the audit log) to the framework’s control IDs and produces a branded artifact you hand to a SOC 2, ISO 27001 or NIS2 auditor. No spreadsheet reconciliation.

-SOC 2 (6 controls) · ISO 27001 (5) · NIS2 (5) · GDPR Art. 32 (4), each with evidence pulled live.
-When a customer’s security team sends a questionnaire, mint a password-gated link to a redacted pack instead.
-Four roles, module-level access, and an audit log with CSV export sit underneath.
UmbraAUDIT EVIDENCE PACK
SOC 2 Audit Evidence Pack
FrameworkSOC 2 Trust Services CriteriaPublisherAICPA · 2017 TSC (rev. 2022)Period2026-06-06 → 2026-09-04 (91 days)Controls6 in pack · 6 with evidence
CC7.1Detection and monitoring of new vulnerabilitiesCOVERED
How Umbra addresses this. Continuous discovery scans every monitored asset on the configured cadence; new CVEs from NVD + CISA KEV are matched on each fingerprint refresh; critical findings fire to Slack / email / SIEM.
Monitored assets4,071
Live services tracked4,039
Scans completed in period911
Median scan cadence1.0 days
Print → Save as PDF · Markdown export · password-gated share link
Fix · re-test

A remediation program, not another list.

Findings are stateful: assignee, due date, history. Close the Jira ticket and the finding closes; fix the bug and Umbra re-runs the exploit that worked: free, unlimited: so a fix that silently reverts is caught. The board gets a report; the auditor gets an evidence pack; Slack gets a slash command.

And when you need a human

Automation is better at frequency, breadth, consistency and volume. A person is still better at business logic that needs domain knowledge, long chains, and the bug nobody has named yet. Scale includes a five-day human pentest every year, so the humans spend their days on that column, not on re-checking last quarter's TLS finding.

Tickets
Jira · GitHub Issues
two-way: close either side
ChatOps
Slack
/umbra ask, run, report
SIEM
Splunk · Sentinel
every finding, structured
Evidence
SOC 2 · ISO · NIS2 · GDPR
from real findings, shareable
Reports
Engagement · Exec · Board
six languages, print-ready
Digest
One email a week
critical open, MTTR, top 5
Access
SSO · 4 roles · audit log
Google and Microsoft OIDC
API
REST + OpenAPI
every surface is an endpoint
Pricing

Pay for the assets you monitor, not the ones we discover.

A flat monthly price with an allowance of two counted units, an Audit (one full AI pentest of one app, up to ten backends) and a Check (one AI verification). Scanning, cloud posture, reports, integrations and API are never metered. Re-testing a fix is always free. Annual saves two months.

$0 forever
Free · 25 assets
$249 /mo
Starter · 1 Audit, 15 Checks
$1,500 /mo
Essential · cloud, credentials
$4,000 /mo
Standard · internal, compliance
Custom
Scale · + human pentest
Custom
Enterprise · MSSP
See full pricing and what each plan includes →Annual billing: two months free. Cancel anytime.

Start the engagement today. 25 assets, free, no card.

Start freeHow it proves a finding

Non-destructive · read-only cloud · EU data residency by default · your data is never sold or trained on · SSO with Google and Microsoft · DPA available · cancel anytime