# SableOffensive - Agent-as-a-Service Pentesting > Chat with autonomous pentesting agents that scan your app on demand. Start with 150 free credits, no credit card. From the security researchers behind 3 published CVEs. ## What is Agent-as-a-Service (AaaS) Pentesting SableOffensive lets you talk to autonomous pentesting agents in a chat interface. Instead of waiting weeks for a manual engagement, you tell the agents your app URL and what to test, and they run real scans on demand — OWASP Top 10, API security, IDOR/BOLA, secrets detection, and AI-generated code review. Findings are validated with proof-of-concept and re-tested, not just flagged. The differentiator is rigor (re-test, real triage, PoC) plus on-demand, conversational access — not "manual vs automated". ## The Pentesting Agents - pen-scout: reconnaissance and attack-surface mapping - pen-recon: deeper enumeration of endpoints, assets, and tech stack - pen-triage: validates findings, assigns severity, and prioritizes what matters - pen-fixer: produces concrete remediation guidance and fix code - pen-compliance: maps findings to OWASP Top 10 and security standards ## Pricing - Free tier: 150 free credits, no credit card required. Runs on OpenRouter models so you can evaluate the agents before paying. - One-time credit packs (pay-as-you-go): $29, $79, $199 - Monthly tiers (continuous, on-demand pentesting): $49/mo, $149/mo, $399/mo Credits are consumed per scan/agent action based on depth. All agents draw from the same credit balance. ## Specializations - Supabase and Firebase BaaS security (RLS policies, security rules, exposed keys) - LLM and AI infrastructure security (vLLM, OpenAI-compatible APIs, AI gateways) - OWASP Top 10 vulnerability assessment and API/IDOR testing - Next.js and React application security - AI-generated code security review (Cursor, Copilot, v0): hardcoded secrets, missing validation, insecure patterns ## Security Research (Credibility) - 3 published CVEs (Moltbot/OpenClaw): CVE-2026-24763, CVE-2026-25253, CVE-2026-25157 — high-severity vulnerabilities in AI agent gateways (1,673 exposed servers) - Exposure analysis on CVE-2026-22778 (vLLM Remote Code Execution via malicious video, CVSS 9.8, discovered by Orca Security): 175K+ servers affected (data: Censys/SentinelOne) - Research published at https://sable.somoswilab.com/research/ ## Free Tools - Free security headers scan: https://sable.somoswilab.com/free-scan - Sample report: https://sable.somoswilab.com/sample-report ## Get Started - Start free (150 credits, no card): https://sable.somoswilab.com/login?intent=aaas - Website: https://sable.somoswilab.com - Pricing: https://sable.somoswilab.com/#pricing - Email: hello@sable.somoswilab.com - Twitter: @sableoffensive