Security evidence your clients can use.
Without the $20,000 bill.

Continuous application-security testing, verifiable reports, and an optional analyst attestation for growing SaaS teams facing customer or auditor pentest requirements.

Findings classified using industry standards

OWASP Top 10
CVSS CVSS v4.0
CWE CWE
NIST800-53 NIST 800-53
ATT&CK MITRE ATT&CK

What You Get

AI Attack Engine

Our AI doesn't just run a scanner - it reasons about your application, chains findings together, tests business logic flaws, and adapts its attack strategy based on what it discovers. The kind of creative testing you'd expect from an experienced pen tester.

Deep DAST + OWASP Coverage

Full OWASP Top 10 coverage is just the baseline. The AI layer goes further - probing for access control gaps, privilege escalation, and multi-step attack chains that off-the-shelf scanners can't find.

Authenticated Testing

We test behind your login pages using securely stored credentials - because that's where critical vulnerabilities actually live. The AI navigates your app like a real user, finding flaws in protected workflows.

Compliance-Ready Reports

Professional PDF reports with CVSS scores, CWE references, NIST 800-53 control mappings, and MITRE ATT&CK techniques - with compliance summaries and remediation guidance formatted for SOC 2, PCI-DSS, and auditor handoff.

CISA KEV Alerts

Every scan cross-references your tech stack against the CISA Known Exploited Vulnerabilities catalog. If your infrastructure runs software with actively exploited CVEs - especially those tied to ransomware campaigns - you'll know immediately.

Black-Box, Zero Friction

No agents to install, no code changes required. We attack your application from the outside - exactly as a real attacker would. The AI maps your attack surface automatically and tests every angle.

How It Works

1

Register Your Target

Enter your application URL, confirm your authorization, and choose email or DNS ownership verification to define the test scope.

2

Verify Domain Ownership

Click the email link or publish the unique DNS TXT value to confirm control - a required step in any professional pen test engagement.

3

Activate Your Subscription

Choose continuous testing at $150/month with a three-month initial commitment, or annual human review at $2,500/year. Testing begins automatically.

4

Review Findings & Export Reports

Triage vulnerabilities on your dashboard, track remediation progress, and download compliance-ready PDF reports on demand.

Fix It Once. We Verify It Automatically.

With a traditional pen test, you get a report, fix the issues, and then pay thousands more to schedule a rescan to prove remediation. That cycle can take months.

Smoke Test's AI runs every week. When you fix a vulnerability, the next test picks it up automatically - no rescan request, no additional cost, no waiting. Your dashboard shows exactly when each finding was resolved, giving you a clear audit trail of continuous improvement.

Your clients and auditors don't want a point-in-time snapshot from six months ago. They want proof that your security posture is current. That's what continuous AI-driven pen testing delivers.

See the Deliverable Before You Buy

The public sample is generated from the same reporting pipeline customers receive. It shows the evidence, prioritization, standards mappings, and remediation detail included with a scan.

Actionable Evidence

Affected endpoints, observed evidence, confidence, and finding counts.

Audit Mapping

CVSS, CWE, NIST 800-53, MITRE ATT&CK, and CISA KEV context.

Remediation

Prioritized fixes and mitigation notes your team can carry into delivery workflows.

Authorized targets only. Email or DNS verification is required before activation. Private and link-local destinations are blocked, and active tests exclude denial-of-service and destructive exploitation.

Simple Pricing

Start with continuous automated evidence, or add an annual analyst review and signed attestation for customer and auditor handoff.

Continuous
$150/month

Three-month initial commitment, then month-to-month

  • Weekly AI-driven penetration test
  • Daily baseline regression scans
  • Business logic & access control testing
  • Authenticated testing behind login
  • Versioned PDF reports with integrity verification
  • NIST 800-53 + MITRE ATT&CK mappings
  • CISA KEV alerts with ransomware flags
  • OWASP Top 10 + beyond
  • Continuous monitoring dashboard
  • Email alerts for new findings
  • Expiring, revocable client share links
Start Continuous Testing

FAQ

Will this satisfy our compliance requirements?

Our reports are built for auditor handoff. Every finding maps to NIST 800-53 controls and MITRE ATT&CK techniques, with CVSS scores, CWE references, and remediation guidance. Reports include a compliance summary showing which NIST control families are affected and the top ATT&CK techniques observed - formatted for SOC 2 Type II, PCI-DSS, and similar frameworks.

Is this a real penetration test?

Smoke Test performs authorized active security testing using OWASP ZAP and custom authenticated, access-control, business-logic, and attack-chain modules. Continuous-plan reports are automated and say so explicitly. Human Reviewed reports add analyst review and a signed attestation; neither format guarantees security or replaces an auditor's independent judgment.

How does this compare to a manual pen test?

Traditional manual engagements can provide deeper exploratory coverage, but are expensive and point-in-time. Smoke Test provides repeatable weekly testing and automatic fix verification. The Human Reviewed plan adds analyst oversight to one selected full assessment per subscription year while continuous testing runs between reviews.

How is this different from running OWASP ZAP ourselves?

ZAP is one tool in our arsenal, not the whole product. Our AI engine orchestrates ZAP alongside custom attack modules, then reasons about the results - chaining findings, testing business logic, and pursuing attack paths that a standalone scanner would never attempt. Think of it as the difference between owning a stethoscope and having a doctor.

Can we use these reports for client audits?

Yes. Every report includes a stable report ID, version, integrity seal, testing scope, methodology, vulnerability evidence, remediation guidance, and standards mappings. You can issue an expiring, revocable share link. Human Reviewed reports also carry a named analyst attestation. Your client or auditor remains responsible for deciding whether the evidence satisfies its specific requirement.

Can I cancel anytime?

The Continuous plan has a three-month initial commitment and becomes month-to-month afterward. The Human Reviewed plan is annual. Billing and payment methods are managed through Stripe.

Built by Security Professionals

We've spent 20+ years working with security-conscious clients - organizations where a data breach isn't just a bad day, it's an existential event. In that time, one problem came up again and again: clients needed a third-party penetration test to satisfy a compliance requirement or close a deal, but the quotes from pen test firms were absurd.

Smoke Test exists because we got tired of telling clients their only option was a $15,000 engagement. So we built what we wished existed - an AI attack engine that thinks like the pen testers we've worked with for decades, running continuously, at a price that makes sense. Not a scanner with a dashboard. Not a startup experiment. AI-managed penetration testing, born from two decades of real-world security work.