Building an API fast? Your first two scans are on us.
If you are actively shipping an API, we will run two full agentic penetration tests against it, free. The agent tests every operation for the flaws that actually breach APIs, BOLA, BFLA, broken auth and injection across roles, and proves each finding with a working exploit. No credit card, no sales call to get value. We do it to earn design partners while your product is young.
Two real scans, not a trial teaser
Every operation tested
From your OpenAPI spec, the agent enumerates and tests every endpoint across your user roles, not a sampled subset.
Exploits, not alerts
Each finding ships reproduced, with the exact request and response and a CVSS v3.1 vector. Near-zero false positives.
Scope-locked on staging
Non-destructive by default, scope enforced in software, run it against staging. Stop any run instantly.
Watch the agent test an API
This is the Operator console streaming a run: it maps every operation, replays one role's requests as another to confirm BOLA and BFLA, then proves each finding. Illustrative demo against api.example.com, the requests, sessions, and confirmations are what a real scan streams.
Free scans, in exchange for a partnership
What you give
Candid product feedback as a design partner, and, only if you agree later, an optional short case study or testimonial. That is it. No obligation to buy, no credit card.
Why we do it
Our product is young and we would rather earn early believers than run ads. Testing real, fast-moving APIs makes the agent sharper and gives us partners we grow with.
Best fit: API-first SaaS, fintech, and AI startups from pre-seed through Series A that are shipping an API right now.
From application to proof in days
Apply
Tell us about your API in the form below. We review for fit within a couple of business days.
Scope
You share your spec and one token per user role, and pick a staging target. We confirm scope and authorization.
Two scans
The agent runs two full engagements and streams its work. You receive proof-backed findings.
Decide
Fix what it found, share feedback, and continue on a startup-friendly plan only if it earned it.
Claim your 2 free scans
Actively building an API? Tell us about it. We reply within a couple of business days.
Questions about the program
Who is eligible?
Startups actively developing an API, with (or able to produce) an OpenAPI or Swagger spec, and authorized to permit security testing. Aimed at API-first SaaS, fintech, and AI companies from pre-seed through Series A.
What do the two free scans include?
Each is a full agentic API penetration test: the agent parses your spec, tests every operation for BOLA, BFLA, broken authentication, injection, and mass assignment across roles, and proves each finding with the exact request and response and a CVSS v3.1 vector.
Is it really free? What is the catch?
The two scans are free. In return we ask for candid product feedback and, optionally and only with your agreement later, a short case study or testimonial. No obligation to buy, no credit card.
Is it safe to run against our systems?
Yes. Testing is scope-locked and non-destructive by default, and we recommend staging. Nothing with real side effects runs without your written approval, and you can stop a run instantly.
What happens after the two scans?
You keep the findings and fix them. If it earned a place in your stack, you can continue on a startup-friendly plan. There is no automatic charge and no obligation.
Two scans. Real proof. On us.
If you are shipping an API, there is no reason to wait for the flaws that breach it. Apply and put the agent on your endpoints.