VYPR
researchPublished Sep 8, 2026· 1 source

Reflectiz Launches Agentic Pentesting to Revolutionize Website Security

Reflectiz introduces an AI-driven penetration testing platform for websites, promising up to 10x coverage and faster remediation compared to traditional methods.

Reflectiz, a company specializing in continuous web exposure management, has launched a novel agentic penetration testing platform designed to significantly enhance the security of websites. This new platform utilizes a specialized team of AI agents that work collaboratively to discover, attack, and validate web vulnerabilities. By leveraging pre-existing contextual data about each website, these agents aim to eliminate noise, reduce false positives, and accelerate the remediation process, offering up to ten times more coverage than conventional penetration testing tools.

Traditionally, penetration testing has been a periodic event, providing a snapshot of a website's security at a specific moment. However, the dynamic nature of modern websites, with frequent updates and the integration of numerous third-party scripts, creates a gap between testing cycles where vulnerabilities can emerge and be exploited. Reflectiz CEO Idan Cohen highlights this challenge, stating that "Teams need testing that keeps up with releases at a cost they can sustain, and trusted coverage of what was tested." The company's decade-long experience in scanning production websites has resulted in a comprehensive live model for each site, encompassing pages, scripts, third-party domains, sensitive inputs, and user behaviors.

The agentic pentesting platform builds upon this existing knowledge base by adding an attacker's perspective. Instead of generic findings, the AI agents provide detailed context, including the specific script involved, the data it can access, and whether real users are currently exposed. This allows security teams to bypass the often time-consuming investigation phase and proceed directly to fixing the identified issues. CTO Ysrael Gurt emphasizes that the core difficulty in web pentesting lies not in crafting payloads, but in understanding the application's actual functionality, a challenge Reflectiz's engine has been addressing for years.

The platform operates as a coordinated team of distinct AI agents, each assigned a specific role. One agent meticulously crawls the website, mimicking real user interactions through logins and multi-factor authentication to map its current state. A second agent fingerprints the technology stack to determine applicable attack vectors. A third agent executes these attacks and chains together any discovered vulnerabilities. The critical fourth agent acts as an independent validator, reproducing each finding before it is reported, thereby minimizing false positives by design.

This comprehensive approach ensures that findings are delivered with clear reproduction steps and supporting evidence. Furthermore, the platform provides a coverage map detailing exactly what was tested and cleared. The testing capabilities span the entire OWASP Top 10 and allow teams to customize the depth of testing for specific user flows, ranging from quick, predefined checks to complex attack chains on critical assets.

The agentic pentesting is integrated into Reflectiz's new Offensive Hub, complementing the existing Security Hub and Privacy Hub. This unified platform offers a holistic view of web risk, mapping what runs on a website, the data it handles, and its potential attack surfaces. Findings from all three hubs are automatically cross-referenced, eliminating the need for manual dashboard reconciliation. For remediation, the Reflectiz AI agent, Atlas, provides guided fixes, explaining each risk and walking teams through the resolution process.

Reflectiz aims to streamline security operations by routing results directly into existing workflows via a REST API, CI/CD triggers, and Slack alerts. The company will demonstrate its agentic pentesting capabilities in a live webinar on September 15th. This new offering is part of Reflectiz's broader mission to provide continuous web exposure management, helping enterprises across various sectors meet compliance requirements like PCI DSS, DORA, and NIS2 without requiring code modifications.

Synthesized by Vypr AI