Most pentests tell you what was vulnerable when the test ended. Umbra tells you what's exploitable now, validated against your actual systems before a finding reaches you, with the evidence to reproduce and fix it.
External · Web apps · Cloud · Internal · Credentials · Non-destructive · read-only · re-tests free
It produces a PDF that is accurate on the day it is written and slowly stops being true, because your environment keeps changing after the engagement ends. Meanwhile your scanner produces thousands of matches a month and hands you the job of turning maybes into yeses.
Umbra makes the fifty weeks stop being a blind spot: the same rigour on asset 900 as on asset 1, at 3am, every day. Nothing reaches your queue until it survived an agent trying to disprove it.
Each surface produces candidates its own way. Every candidate meets the same validator, and every finding arrives in the same shape: what was tested, what came back, what it proves: and what to do about it.
Give it domains, IPs and CIDRs. It sweeps all 65,535 ports by default, fingerprints what answers, matches versions against the full NVD with KEV and EPSS on top, and treats a match as a candidate to go and test, not a ticket to hand you.
A headless browser crawls the app the way a user does. A 56-module scan finds what rules find; an active Triager probes ambiguous results live instead of guessing. Then tiered agents hunt what scanners structurally can’t reach.
A 5 MB agent, one-line install, outbound HTTPS only. One click fans 54 named techniques across every live internal service (Active Directory, ADCS, Kerberos, SMB, databases, hypervisors), and the network map colours every host by its most severe proven finding.
World-readable data, identities that escalate to admin, secrets in config, internet-open services, traced into paths that end at your data. Public storage is proven with an anonymous read, not inferred.
Verify a root domain and Umbra watches for accounts on it (employees, third parties, customers) appearing in exposed credential data, with where they leaked from and how strong the password was.
Findings are stateful, not snapshots: open → in progress → fixed → verified, with won’t-fix for accepted risk. KPI tiles and a Lumi-ranked top ten sit above the list, so the week starts with the right ten items, not a thousand.
Three audiences, three reports, one source of truth: a per-target engagement report with every verified finding and its PoC, a non-technical management summary in six languages, and an org-level executive risk report with posture KPIs and trend.
Install the Slack app once per org. Anyone in the workspace can triage findings, ask Lumi in plain English, or trigger a validation with a slash command: with the same permissions they have in the web app.
Every candidate is re-tested against the live target by a separate agent instructed to disprove it. These are the rules it runs under, not a description of them.
A small sample; we'll publish a larger figure when we have one rather than round this into a marketing number.
Before Umbra, its founder reported 2,000+ confirmed vulnerabilities to the security programs of 1,000+ companies, including the ones below. Umbra exists because the tools available weren't operator-grade enough for that work.
Companies whose security programs accepted findings from Umbra's founder. Umbra is in private beta; these are not Umbra customers.
Pick a framework. Umbra maps its own data (assets, scans, findings, the audit log) to the framework’s control IDs and produces a branded artifact you hand to a SOC 2, ISO 27001 or NIS2 auditor. No spreadsheet reconciliation.
Findings are stateful: assignee, due date, history. Close the Jira ticket and the finding closes; fix the bug and Umbra re-runs the exploit that worked: free, unlimited: so a fix that silently reverts is caught. The board gets a report; the auditor gets an evidence pack; Slack gets a slash command.
Automation is better at frequency, breadth, consistency and volume. A person is still better at business logic that needs domain knowledge, long chains, and the bug nobody has named yet. Scale includes a five-day human pentest every year, so the humans spend their days on that column, not on re-checking last quarter's TLS finding.
A flat monthly price with an allowance of two counted units, an Audit (one full AI pentest of one app, up to ten backends) and a Check (one AI verification). Scanning, cloud posture, reports, integrations and API are never metered. Re-testing a fix is always free. Annual saves two months.
Non-destructive · read-only cloud · EU data residency by default · your data is never sold or trained on · SSO with Google and Microsoft · DPA available · cancel anytime