In the AI Pentest, AI agents test your infrastructure the way an attacker would.
CheckFix shows where your attack surface lies. The AI Pentest actively attacks and tests what can be exploited.
On our own hardware in Austria, with no data shared with third parties.
Automated penetration testing
Own hardware in Austria
Report Builder for tech & management
1 re-check per run included
CheckFix identifies the attack surface reachable from outside, based on your domains including subdomains.
In the dashboard, you switch to the AI Pentest and approve individual hosts or the entire company.
The agents work through the approved scope systematically and decide for themselves where it pays to keep digging.
All findings appear in your dashboard with full technical details.
In the Report Builder, you create the report you need: a detailed report per host or an executive summary for management.
Billing is based on runs, meaning complete passes. It follows the same logic as person-days in a classic penetration test: you decide how much search depth the test is worth to you. Our pentest agent learned from our pentesters where to keep digging and when to move on to the next target.
AI Pentest
The AI Pentest costs less than a manual penetration test and can be repeated regularly. After fixing, the re-check shows you whether the gap is really closed. Behind the agents are experienced pentesters who monitor the system continuously and, if you wish, explain the results to you in detail in the findings review.
Classic penetration test
For very specific scenarios, or if you would like personal advice and a person to guide you through the process, secinto’s pentesters are still available. Feel free to contact us.
For regular, broad testing of your attack surface, however, the AI Pentest is the faster and more affordable choice.
The AI Pentest builds on a complete analysis of your external attack surface. Instead of blindly testing a single target, it tests what is actually reachable in your environment.
Others price a single web application. With us, you approve the scope you need, and the agent decides where depth makes sense.
The AI Pentest runs on our own hardware in Austria. Your data does not go to any cloud service or third party. For critical infrastructure operators and companies subject to NIS2, this is often the deciding question.
Behind the agent are a second model that cross-checks its results and our pentesters, who continuously monitor and further develop the system.
The AI Pentest is aimed at organisations with specific security and compliance requirements: critical infrastructure operators, companies subject to NIS2, DORA, ISO 27001 or the Austrian NISG 2026, and larger businesses that want to test their attack surface regularly and reliably.
No. In the CheckFix AI Pentest, purpose-built AI agents test your infrastructure for exploitable vulnerabilities. It is not about testing an AI or language model itself.
The AI Pentest is an add-on to CheckFix Basic or Premium and requires the external security assessment. Billing is based on runs. The smallest package includes 4 runs for 3,900 euros net, the largest standard package 20 runs for 13,500 euros. Purchased runs do not expire, even if the CheckFix subscription is cancelled.
A run is one pass of the agents across your approved scope. More runs mean more search depth. Each purchased run includes one re-check, available within 4 weeks.
A manual penetration test with a comparable scope can easily cost 15,000 euros and usually runs once a year. The AI Pentest costs less and can be repeated regularly. For very specific scenarios, the experience of human pentesters remains valuable. That is why our pentesters monitor the system continuously.
For regular, broad testing of your attack surface, yes. For complex business logic or very critical individual targets, a manual test is a useful addition.
Yes. CheckFix first identifies your external attack surface. The AI Pentest builds on that.
The AI Pentest runs on our own hardware in Austria. Your data does not go to any cloud service or third party. The data from CheckFix stays in Europe.
It provides reliable technical proof of your external security posture. With the paid pentest certificate, secinto officially confirms the test and signs the proof of scope, time period and methodology, for use in audits and tenders.
Start with CheckFix and enable the AI Pentest directly in your dashboard.