What automation is genuinely better at

A traditional penetration test is a person, a scope, and two weeks. It produces a PDF that is accurate on the day it is written and slowly stops being true.

Where each one wins

We are not neutral here and it would be silly to pretend otherwise — but we also sell human pentest days on the Scale plan, so we have no incentive to tell you automation replaces them. It does not. It changes what you should spend them on: a human should be doing the work in the right-hand column, not re-checking whether last quarter's TLS finding is still open.

How Umbra automates it

A headless Chrome crawls the application the way a user does — rendering JavaScript, following flows, logging in when you supply credentials — alongside a static crawler and wordlist fuzzing. Modern applications do not reveal their surface to an HTTP client.

Candidate generation, then scenario execution, then an open-ended hunt, then specialist agents per vulnerability class — IDOR, business logic, auth, SSRF, injection, and more. Each fires real requests at the target and reads real responses.

Every candidate is re-tested against the live target by a separate agent instructed to disprove it. Its default verdict is NOT_EXPLOITED. In production it drops roughly 41% of what the hunters produce — see{" "} exploit validation .

An agent runs 54 named techniques against Active Directory, ADCS, Kerberos, SMB, databases and hypervisors, with a blast radius you choose — see{" "} internal pentest .

One Audit per application

A full AI penetration test of one application costs one Audit, whatever its size, with up to ten related backends included. Plans start at one Audit a month.

Part of{" "} continuous security validation {" "} — discover, prove, fix, re-test.