VYPR
researchPublished Jul 28, 2026· 1 source

Prescient Security Enhances AI Pentesting with Attack Surface Management and Broader Asset Support

Prescient Security's AI-driven penetration testing service, Cait, now includes attack surface management and expanded asset testing, offering continuous security validation beyond web applications.

Prescient Security is significantly expanding the capabilities of its AI-assisted penetration testing service, Cait (Cacilian AI), with new features set to roll out through the summer of 2026. These enhancements include the addition of attack surface management (ASM) and support for a wider range of asset testing types, extending Cait's reach beyond its initial focus on web applications to provide a more comprehensive approach to continuous security testing.

The latest updates follow Cait's general availability launch earlier this year, which introduced an autonomous, context-aware penetration tester designed to explore applications before attempting to exploit them. The service delivers exploit-validated findings with audit support on a subscription or one-time engagement basis, aiming to provide continuous security validation.

One of the key expansions is enhanced environment support, allowing Cait to test across various enterprise environments. This enables organizations to maintain their existing operational and security requirements while extending continuous, AI-assisted security testing. For large enterprises that require isolated testing environments, Prescient Security has developed a process aligned with autonomous testing protocols to ensure secure and effective testing.

The new attack surface management (ASM) capability, slated for release in Summer 2026, will provide security teams with automated discovery and mapping of their external-facing assets. This feature aims to identify what is exposed before Cait begins its testing phase. By integrating asset discovery with continuous penetration testing, organizations can achieve a closed-loop security process: discovering exposed assets, testing them, validating findings, and tracking remediation efforts, all within the Cacilian platform.

Furthermore, Cait is broadening its testing scope to include additional asset types beyond web applications. This expansion means that teams can place more of their digital assets under continuous, recurring security coverage without needing to initiate separate manual engagements. This addresses a critical need for ongoing security validation as environments evolve.

Fabrice Mouret, CEO at Prescient Security, highlighted the value of the new ASM feature, stating, "Most organizations still discover their own attack surface the hard way when an auditor flags it or an attacker finds it first." He added, "Adding ASM to Cait means teams can go from ‘what do we even have exposed?’ to ‘here’s the validated evidence that it’s been tested and remediated.’"

Sammy Chowdhury, CCO at Prescient Security, emphasized the challenge of maintaining current security coverage in dynamic environments. "Security teams tell us the hardest part isn’t finding a good pentester, it’s keeping coverage current as their environment changes," Chowdhury explained. "Every new asset type and environment we bring into Cait is another surface that no longer goes stale between annual engagements."

These enhancements position Cait as a more robust solution for continuous security validation, addressing the evolving needs of organizations to proactively identify and remediate vulnerabilities across their entire digital footprint.

Synthesized by Vypr AI