Proof First autonomous pentesting

Autonomous pentesting for modern attack surfaces.

GhostTrace tests authorized external targets across network services, web applications, APIs, and AI enabled systems. It follows what an attacker would try next and reports only what the evidence supports.

Proof FirstAI investigates. Evidence decides. See GhostTrace work Request a demo
  • Authorized scope
  • Attack path reasoning
  • Reproducible evidence
Proof First by design

A finding without proof becomes another task.

GhostTrace reports what the evidence supports.

Without proof

Detect. Dump. Triage. Repeat.

Your team has to reproduce, rank and validate what should already be clear.

With GhostTrace

Investigate. Prove. Act.

GhostTrace tests the route and reports only what the observed result supports.

Proof First

AI investigates.
Evidence decides.

No evidence. No proven claim.

1,482 signals explored1  ·  684 external assets monitored  ·  every signal, before validation
Signal explored Candidate validated Proven result Chains to impact

The figures below are illustrative and represent a fictional assessment. They show how GhostTrace applies its evidence standard: every candidate must clear four independent evidence gates—reachability, signal, exploitability and impact—followed by repeated independent verification of the evidence and result. In this example, 1,482 signals reduce to 96 credible candidates; 28 carry proof strong enough to report, with evidence attached so your team can reproduce each one. The rest remain in the artifacts rather than entering your queue. Across the illustrative 90-day window, 17 proven findings were remediated and 3 reopened after an environmental change—showing the value of continuous testing over a once-a-year assessment.

The problem

A finding without proof becomes your team’s next task.

The burden begins where most scanners stop: reproduce the condition, decide whether it chains into meaningful impact, and assemble evidence another team can act on.

At autonomous volume that gap only widens, because more detection means a longer verification queue rather than a safer system. Trust does not collapse at a number. It goes in three steps, and in this order.

The old way Detect dump triage repeat
  1. 01

    The queue arrives

    Thousands of findings and vulnerability alerts pile up, largely unproven and without a trustworthy order. Somebody now decides by hand which ones are real.

  2. 02

    Triage becomes the job

    Most of what you open turns out to be nothing, and the one genuinely dangerous finding reads exactly like the rest.

  3. 03

    The critical finding gets buried

    Every scan returns another mix of findings and artifacts. Your team spends time proving authenticity while the highest-severity exposure risks disappearing into the noise.

The GhostTrace way Scan chain verify independently report proof
Possible Exploit chained Finding with proof

Every finding GhostTrace reports has travelled the whole way along that line before you see it.

The third step is the one you cannot fix by working harder. GhostTrace closes the gap before reporting rather than after it, keeping the route, the proof and the remediation context in one inspectable record. It does not infer exploitability; it confirms it with non-destructive techniques and hands over the evidence, so a finding arrives already verified instead of arriving as work.

Autonomous reasoning

Watch GhostTrace follow the path.

GhostTrace starts from the authorized external surface and follows only the route the evidence supports.

Illustrative reasoning trace · fictional client data
  1. Observe
  2. Test
  3. Learn
  4. Pivot
  5. Chain what holds
Starting positionAuthorized external surfaceNo special access required
GhostTrace route searchWhat could this unlock next?
01
Path testedStatus pageReached and accessed. Expected health data returned. No exploitable behavior.
No reportable finding
No viable next stepPivot ↓
02
Path testedProtected archiveReachable. Further access is outside the authorized boundary, so it is not accessed.
Boundary held
Cannot advance safelyPivot ↓
03
Path testedReachable entry pointA controlled request shows the route can advance.
Route advances
Route holds
Evidence-backed chainOnly the verified route advances
Evidence heldInternal serviceInternal response returned
Evidence carried forwardSensitive access pathSupporting evidence retained
Business impactImpact confirmedA real path to impact
The engine learns from every stop.Safe response? Move on. Scope boundary? Stop and pivot. Working weakness? Chain it to the next evidence-backed step.

Proof First keeps the reasoning honest. GhostTrace can investigate possibilities, but evidence decides what can be reported.

Coverage

Built for the modern external attack surface.

One reasoning system across the surfaces attackers actually test.

01 · Network

Network exposed services

Find reachable services, exposed infrastructure and risky changes.

02 · Web

Web applications

Test user journeys, sessions and application behavior.

03 · API

APIs

Validate identity, object access and data exposure.

04 · AI

AI applications

Assess chatbots, tools and AI enabled workflows.

05 · Agents

MCP and agent workflows

Review connected tools, permissions and trust boundaries as coverage matures.

Start with an authorized surface Let GhostTrace show what an attacker could actually do.

Run a governed assessment and review evidence backed findings your team can act on.

Request a demo
The platform

Four ways to run it. One standard of proof.

Start with a managed, bounded design-partner assessment and inspect the evidence before committing to annual coverage. The platform expands from autonomous surface monitoring through continuous proof without changing what a finding must demonstrate before it is reported.

Surface · autonomous monitoring

EASM

Discovers and verifies the assets, services and APIs exposed to the internet, including forgotten staging and newly introduced surface. It establishes what exists and what changed.

Proof · managed assessment

Pentest

Runs active, governed testing inside an authorized scope. Autonomous scanning and AI-driven exploit chaining turn candidate exposure into evidence your team can inspect and reproduce.

Proof · recurring

Pentest Continuous

Re-runs the same governed checks on a recurring cadence and when relevant conditions change, surfacing only what is new, remediated or reopened.

Surface + proof · continuously

Continuous Coverage

Combines external attack surface monitoring with continuous pentesting. Surface changes trigger a bounded assessment, and only newly proven exposure reaches the queue.

Now seeking design partners Put GhostTrace against a real, authorized surface.

Work with us through a managed, governed assessment, inspect the proof firsthand and help shape the continuous platform.

Discuss a design partnership
How it compares

Scanners guess. Pentests expire. AI tools can’t show their work.

The honest comparison, including where each alternative is the right call.
Legacy scannersManual pentestAI-pentest toolsGhostTrace
What’s reportedPattern matches, far more than are actionableWhat a human verified, varies with the teamAI-generated findings, varying validationOnly gate-verified findings, evidence attached
Can you audit it?Opaque rules; clean and broken look identicalAsk the consultant, until the engagement endsBlack-box reasoning; can’t explain a findingEvery decision in a ledger, traceable to evidence
Triage burdenYours; staff closing tickets that shouldn’t openLow, but findings arrive as a PDF snapshotLower volume, but you still verify the AINear zero; if it’s reported, it passed
Trust the quiet?Zero findings may mean the scanner brokeSilence between engagements means nothingNo way to prove the AI actually lookedCI gates prove every claimed capability runs
Cost shapeCheap per scan, costly in triage headcount$30K to $200K per engagement, weeks to schedulePlatform pricing, opaque AI spendAutomated cadence; AI spend capped per run
Right tool whenYou need checkbox breadth at minimal costStakes demand bespoke human adversariesYou want autonomy and accept the opacityYou want findings you can verify
Before you authorize testing

Common questions before GhostTrace runs.

Scope, safety, evidence and what GhostTrace reports.

How does the product test?

GhostTrace tests external attack surfaces, including network exposed services, web applications, APIs, AI applications, and MCP or agent connected workflows. Coverage depth may vary by surface, and GhostTrace should never label a result beyond what the evidence supports.

What keeps an autonomous system inside our rules?

Testing begins with an approved target and defined rules of engagement. GhostTrace is designed to operate only inside the authorized scope, including approved domains, systems, credentials, timing, and exclusions. Expanding scope requires additional authorization.

How do you test like an attacker without acting recklessly?

GhostTrace is designed for controlled, evidence oriented testing. It looks for proof without unnecessary impact, stops when a boundary holds, and records what happened so your team can review the result. The objective is to establish what is real, not to damage systems.

What does Proof First mean?

AI investigates what may be worth testing. Evidence decides what GhostTrace can report. If the evidence does not support a strong claim, GhostTrace should not call it proven.

What happens to things GhostTrace cannot prove?

They can remain as observations or candidates with supporting context, but they are not reported as proven findings. This helps your team see useful signal without confusing it with verified impact.

Can our engineers reproduce a finding themselves?

That is the point. Every proven finding ships with the request, the response, each check’s decision and the verification verdict. Replay it and you should get the same result. If it does not reproduce on your side you should not trust it, and we would want to hear about it.

Do you test authenticated areas?

Yes, when credentials are provided and approved for the assessment. Roles, test accounts, and access boundaries are defined during scoping so GhostTrace can test realistic application behavior safely.

Are you SOC 2 certified?

Not yet. SOC 2 is in progress, and we will not claim certification until it is complete. Until then, GhostTrace should be evaluated through its engagement controls, authorization process, evidence handling, and transparency about what is ready and what is still maturing.

Can customers run their own assessments?

The product direction is governed self service: customers verify ownership, define authorized scope, and run approved assessments without opening the platform to unrestricted targets. Early customers may receive guided onboarding while self service workflows mature.

Who is actually building it?

Two founders. Engineering and detection architecture is led by a security engineer with over 30 years in the enterprise, including a decade as the top security executive of a global consulting firm. The AI reasoning layer and the checks that constrain it were architected by our CEO, who built production LLM systems before this. Development is substantially AI-assisted under their direction with a verification-heavy process, and we say so openly because it is part of the story. More about the team.

A product of CySecTrust Inc. For more detail on authorization, evidence handling and current control maturity, read the Trust Center or contact [email protected].

Read it yourself

The whole argument is a document you can read without talking to us.

A full sample assessment: six findings, the evidence behind each, and one proven chain. No form, no gate.

Read the sample report Take the 2 minute tour

Or talk to us about a design partnership. We open with a real proven finding on your surface, not a feature demo.

Request a demo

  1. 1

    All figures on this page come from the Meridian Mutual demo engagement, a fictional tenant we use to demonstrate the product without exposing a customer. The mechanism, the checks and the console are real; the numbers belong to that demo environment rather than to a named client. We do not publish customer data, and we do not have permission to name design partners yet.