Find the security holes in your app before hackers do.
Point Sable at your site. Autonomous agents scan it like a real attacker would, then hand you the exact bugs, and the code to fix them. Built for founders and solo devs, not enterprise security teams.
Reads HTTP response headers only — no invasive scanning.
No site to scan yet? Start free — no credit card.
// AI-generated handler, no ownership check
const user = await db.user.findFirst({
where: { id: req.params.id },
});
// pen-triage would add:
// where: { id: req.params.id, ownerId: session.uid }
// ↑ one predicate. every record stays private.AI-generated code ships fast. It also ships the bugs.
Cursor, v0, Bolt, Lovable generate functional code in seconds. They do not sanitize inputs, validate tokens, or check authorization. Your AI assistant is an intern who ships to production.
Sources: Veracode 2025 GenAI Code Security Report (45% of AI-generated samples across 100+ LLMs introduced OWASP Top 10 flaws) · Pearce et al., “Asleep at the Keyboard,” IEEE S&P 2022 (~40% of 1,689 GitHub Copilot programs vulnerable).
A query missing a single ownership check, and every user becomes admin.
Broken access control (BOLA/IDOR) is the #1 category in the OWASP Top 10. It lands in shipped code because the LLM completed the query, then skipped the predicate that proves the caller owns the row.
Five agents. One console.
Each agent is a narrow operator. Scout writes the plan; the others execute. You chat, they run real tools.
Meet the agentsScope & engagement plan
Maps your attack surface, writes the engagement plan, and tells you what NOT to scope. Start every job here.
4 credits / turnExternal recon
Subdomain enumeration, exposed staging envs, leaked secrets, third-party drift. Hands findings to triage.
6 credits / turnFinding explainer
Reads scanner output. Tells you what is real, what is noise, and what would actually hurt in production.
5 credits / turnRemediation walkthroughs
Code-level fixes for OWASP findings: Supabase RLS, Next.js routes, auth flows. Diffs you can paste.
7 credits / turnAudit & compliance
Maps findings to OWASP, PCI-DSS, SOC 2 controls. Generates the evidence pack your auditor asks for.
5 credits / turnThree steps. No onboarding call.
From signup to a scoped pentest in under five minutes. Everything runs in your browser; everything bills by the credit.
Sign up, 150 free credits
No card. Magic-link auth. You land in the console with Scout already waiting.
Pick an agent
Scout writes the engagement plan. Recon maps the surface. Triage reads scanner output. Fixer ships diffs. Compliance preps your evidence pack.
Need depth? Run a scan.
When chat hits its limit, hand off to a one-time pentest ($29, $79, or $199) without leaving the thread.
We ship the work the agents also do.
No fabricated logos. Three real artifacts — read the full write-up or check the source yourself before you spend a credit.
vLLM remote code execution
Discovered by Orca Security, published to NVD. Our exposure research on it followed the same recon-to-PoC workflow pen-scout walks customers through.
Read the write-up$ curl -s https://services.nvd.nist.gov/rest/json/cves/2.0 \?cveId=CVE-2026-22778 | jq .vulnerabilities[0]{"cvssV3": 9.8,"severity": "CRITICAL","vector": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}
Three CVEs in AI gateway agents
Same agents now powering pen-fixer remediations. The fix patterns shipped here come from the actual disclosure write-ups, not blog summaries.
Read the write-up$ git log --grep="CVE" --oneline -3a7c91f2 fix: bound prompt-injection in agent routerd23b40e fix: SSRF in moltbot fetch tool88e1c0a fix: path-traversal in openclaw state dir# 3 CVEs · all patched · disclosed responsibly
Open-source SOAR + XDR + deception
The tooling pen-recon and pen-triage delegate to. Maintained in public; bugs filed there fix the console experience next.
Verify on github.com$ aegis --statussoar: running (12 playbooks)xdr: running (4 sensors)deception: running (3 honeypots)# open-source · github.com/AEGIS
Latest research
Practical security writing for founders shipping fast: the bugs AI assistants ship, what a pentest actually finds, and how to decide what your launch needs.
View all postsPay only what you use. No seats. No contracts.
Credits power agent turns. Scoping and recon questions cost 1 each; triage, patch review and compliance evidence cost 5. Your 150 signup credits go a long way. Top up when you need.
Skip the chat. Fixed scope, fixed price, PDF in 24-48h. Pick a tier below.
What credits buy
Every agent turn, itemised
- Scope conversation
- 1 credit
- Recon question
- 1 credit
- Findings triage
- 5 credits
- Patch review
- 5 credits
- Compliance evidence
- 5 credits
Try the console. 20-ish agent turns. No card to start, 150 free credits on signup.
A real engagement: scope, recon, triage, fixes. The pack most operators land on.
Multi-app coverage or a quarter of triage work. Hands back to scans when depth is needed.
Fixed scope. Fixed price.
No enterprise pricing. No monthly fees. One scan, one PDF, PoC repos included.
Every plan includes
- Security Headers
- Secrets Detection
- CORS Check
- Basic OWASP
Pre-Launch Check
Perfect for MVPs and landing pages
Landing pages, portfolios, simple MVPs
- Security headers analysis
- Exposed secrets detection
- CORS misconfiguration check
- Basic OWASP coverage
- PDF report in 24-48h
- Email support
Founder Shield
For SaaS with user data
SaaS apps, user auth, payment flows
- Everything in Pre-Launch Check
- BOLA / IDOR vulnerability testing
- API endpoint discovery
- Authentication flow analysis
- Full OWASP Top 10 coverage
- 30-min consultation call
- Priority support
Scale Secure
Complete security assessment
Funded startups, enterprise clients
- Everything in Founder Shield
- SQLi & XSS deep testing
- Infrastructure scanning
- Compliance report (OWASP, PCI)
- Re-test after fixes included
- Slack/Discord support channel
- Security badge for your site
Traditional pentesting firms charge $10,000 to $50,000+ for the same coverage.
Compare plans
Pre-Launch
- Security Headers
- Secrets Detection
- CORS Check
- Basic OWASP
- Full OWASP Top 10
- BOLA / IDOR Testing
- API Discovery
- Auth Flow Analysis
- SQLi & XSS Deep Test
- Infrastructure Scan
- Consultation Call
- Re-test After Fixes
- Compliance Report
- Delivery Time
- 24-48h
Founder Shield
- Security Headers
- Secrets Detection
- CORS Check
- Basic OWASP
- Full OWASP Top 10
- BOLA / IDOR Testing
- API Discovery
- Auth Flow Analysis
- SQLi & XSS Deep Test
- Infrastructure Scan
- Consultation Call
- 30 min
- Re-test After Fixes
- Compliance Report
- Delivery Time
- 2-3 days
Scale Secure
- Security Headers
- Secrets Detection
- CORS Check
- Basic OWASP
- Full OWASP Top 10
- BOLA / IDOR Testing
- API Discovery
- Auth Flow Analysis
- SQLi & XSS Deep Test
- Infrastructure Scan
- Consultation Call
- 60 min
- Re-test After Fixes
- Compliance Report
- Delivery Time
- 3-5 days
| Feature | Pre-Launch | Founder Shield | Scale Secure |
|---|---|---|---|
| Security Headers | |||
| Secrets Detection | |||
| CORS Check | |||
| Basic OWASP | |||
| Full OWASP Top 10 | |||
| BOLA / IDOR Testing | |||
| API Discovery | |||
| Auth Flow Analysis | |||
| SQLi & XSS Deep Test | |||
| Infrastructure Scan | |||
| Consultation Call | 30 min | 60 min | |
| Re-test After Fixes | |||
| Compliance Report | |||
| Delivery Time | 24-48h | 2-3 days | 3-5 days |
Reports include compliance mapping for
Continuous monitoring, billed monthly.
One-time scans catch today's issues. Continuous plans keep watching, with automated re-scans, alerts, and reporting every month. Billed immediately, cancel anytime.
Scan cadence by tier
- Starter
- Weekly automated scans
- Pro
- Daily automated scans
- Enterprise
- Continuous 24/7 scanning
Starter
Essential monitoring for small projects
Billed monthly · cancel anytime
- Weekly automated scans
- 1 domain included
- Email alerts
- OWASP Top 10 coverage
- Monthly security report
Pro
Complete protection for growing startups
Billed monthly · cancel anytime
- Daily automated scans
- 3 domains included
- Slack & Discord alerts
- Full vulnerability coverage
- Real-time dashboard
- API endpoint monitoring
- Compliance tracking
Enterprise
Maximum security for scale-ups
Billed monthly · cancel anytime
- Continuous 24/7 scanning
- Unlimited domains
- All alert channels + PagerDuty
- Advanced threat detection
- Custom dashboard & reports
- Dedicated response team
- API access + custom integrations
Real startups. Real vulnerabilities.
Anonymized findings from real security assessments. No brand names, just stacks, vulnerabilities, and outcomes.
Social Media Startup
EdTech Startup
AI Startup
E-commerce Startup
EdTech Platform
Industrial Tech
A reproducible PoC for every finding · all anonymized · stacks & findings only
Autonomous + researcher-grade.
Most security tools force a tradeoff: speed (AI scanners) or depth (traditional firms). Sable runs both: autonomous scans on isolated Kali, then validated by humans who file CVEs.
Comparison data from public pricing pages and standard SaaS pentest deliverables · Q2 2026
| Capability | Sable | Traditional firms | AI-only scanners |
|---|---|---|---|
| Delivery time | 24-48h | 2-4 weeks | Continuous |
| Starting price | $29 | $10,000+ | Free to $200/mo |
| OWASP Top 10 coverage | |||
| Manual validation | |||
| AI-code / LLM app audit | Rare | Limited | |
| Startup-stack specialization | Supabase · Next.js · Vercel | Generic | Generic |
| Published CVEs | 3 | Varies | None |
| Fix guidance in report | Code-level | High-level | Generic |
| Money-back guarantee | 50% if no findings |
Free: Startup security checklist
15-point checklist covering the most common security mistakes in AI-built MVPs.
No spam. PDF downloads instantly when you submit.
sable-startup-security-checklist.pdf
15 points · one page
Questions, answered.
Everything founders ask before their first scan: is it safe, do I need to be technical, what do I get, and how the free credits work.
Still have questions?
Contact us at [email protected]