Q: Pentesting Sounds Interesting...
Very Sorry for the long message in advance. I’m interested in learning more about InsecureWeb’s penetration testing capability. Before we test it, I have a few questions:
• Is it fully AI/automated, or is there human pentester involvement?
• Does it actively exploit/validate vulnerabilities or primarily scan for them?
• What testing is supported (external network, web apps, APIs, authenticated testing)?
• What methodology/framework does it follow (OWASP, PTES, NIST, etc.)?
• Can we define scope, exclusions, and testing windows?
• What safeguards prevent disruption to production systems?
• What does the final report include, and is remediation retesting available?
• Have customers used the reports as SOC 2 audit evidence?
• What exactly does the 250-credit pentest cover?
insecurewebapp
Sep 21, 2026A: Hi!
1. Fully automated, this is designed to help with 80% of the pentesting exercise but still requires human review and validation.
2. Yes, it actively exploits them to a level of depth (safe/agressive) determined by the scan configuration.
3. External assets only for now. It supports authenticated and unauthenticated testing external network, web apps, APIs, authenticated testing all supported.
4. PTES+ OWASP for web apps.
5. Yes, in the memory items.
6. Testing on windows not available yet, internal testing only available in our dedicated platform at threatexploit.ai.
7. High availability (we host and produce the LLM ourselves) in case of outage we failover to server on runpod.
8. Final report includes, finding, evidence, reproduction of findings and remediation.
9. Yes, the reports are actively used for SOC 2 and ISO 27001
10. The 250 credits cover everything under the light of PTES and OWASP as it applies to the targets pentested. Including the compliance mapping to controls and reports and evidence.
TY! For #7 - I'm asking about data security/privacy when the AI/LLM is performing the pentest. Specifically, is any customer data, scan data, vulnerabilities, credentials, API responses, or other information discovered during testing retained by the LLM, used for model training, or accessible outside of the customer's testing environment?
Our LLM is trained from a combination of ThreatInteligence gathered by ThreatWinds.com using their honeypot network and destilation from other models with permissive licensing. Customer's data cannot be used for training for privacy reasons.