The AI-native,
blackbox, greybox, and whitebox pen test

Deeper than a manual pen test, delivered in days and audit-ready for your SOC 2.

your-companypentest-1
Showing 8 of 8 findings
IDTitleFound
Open5
In Progress1
Fixed2
Flagright
Metal
Clueso
Bastion
Candid Health
PointOne
Moove
MuralPay
WeMaintain
Crouton
Electio
FluxCap

Everything included
in your pen test

Every finding exploited on your stack, reviewed by a human, and audit-ready.

AcmeFileEditView9:41
AcmeOverviewReports
Home
Analytics
Team
Settings
Revenue$48,290+12%
Users8,214+6%
Retention94%+1%
Revenue · last 30 days
9:41
Total balance
$128,420+2.4%
Stripe+$4,200
AWS-$1,180

Web · Mobile · Desktop

Trace tests across web, mobile, desktop, and AI surfaces, from native iOS and Android apps to the LLM powered agents and MCP servers behind them.

trace-pentest-report.pdf
Penetration test report page 1Penetration test report page 2Penetration test report page 3Penetration test report page 4Penetration test report page 5Penetration test report page 6

Audit-ready report

Every engagement ends with a penetration test report and a signed letter of attestation, ready for SOC 2, ISO 27001, HIPAA, PCI DSS, and vendor reviews.

Slack#trace-yourcompany
Your private channel with the Trace team

Human in the loop

An OSCP-certified expert signs off on every finding, plus a private Slack channel with the Trace team.

IDOR
---severity: Highowasp: A01cwe: CWE-639cvss: 8.1---The endpoint returns any invoice by id with no ownership check, exposing other tenants' billing data.
Excessive Agency
---severity: Highowasp: LLM06cwe: CWE-250cvss: 7.6---The agent calls privileged tools with no confirmation step, so one crafted response can trigger destructive actions.
Prompt injection
---severity: Criticalowasp: LLM01cwe: CWE-77cvss: 9.1---Untrusted input reaches the agent's system prompt, letting an attacker override its instructions and exfiltrate data.

OWASP Top 10 for Web, LLMs, Mobile, and APIs

Every finding maps to the OWASP Top 10 for web, LLMs, mobile, and APIs, with a CWE and CVSS score.

Sandbox
Agent #1
Agent #2
Agent #3
Your stack

Exploits run on your stack

DAST

Every finding is minimally exploited on your live stack, so there are no false positives to triage.

About
Retests
Retest
StatusDurationRun
Fixed2m 30sJul 10, 2:14 PM
Open3m 45sJul 6, 10:11 AM
Open1m 58sJul 2, 9:03 AM

Unlimited retests

Deploy a fix and Trace re-tests the exploit and gives you feedback in minutes. No more waiting on a slow retest cycle.

Point-in-timeBefore
JanDec
ContinuousAfter
JanDec

Continuous coverage

Add-on

Pick a cadence, quarterly, monthly, weekly, or continuous, and Trace pen-tests new features as you ship. BYOK and self-hosted options let you use your own inference.

The more context you connect,
the deeper the test

We recommend connecting everything below so Trace can run its deepest scan.

Live Applications

Define your applications in Trace and optionally attach credentials, which agents then use to authenticate and carry out exploits.

Your Company
Email
jane@yourcompany.com
Password
••••••••••
Sign in

Source Code

Trace reads the code across your attack surface, tracing input to sink to confirm real bugs like IDOR, privilege escalation, and injection.

acme/backendPrivate
main
Code
Update search endpoint7ddf16d · 2m
.github2 days ago
src2 hours ago
tests2 hours ago
package.json5 days ago
GitHub
GitLab
Bitbucket

Knowledge Base

Your docs and wikis give Trace the intended behavior, so it can tell a real vulnerability from expected functionality.

docs.company.com/architecture
Architecture
Overview
Services
Data model
Auth & sessions
Deployment
DocsArchitecture
System architecture
Services
Data flow
Slack
Confluence
Notion

Cloud Infrastructure

Trace maps your real cloud topology to find what's internet-facing and reachable, then confirms what's exploitable.

acme-prodCREATE_COMPLETE
app-alb
ELBv2::LoadBalancer
Internet-facing
api-service
ECS::Service
orders-db
RDS::DBInstance
Private
AWS
Azure
GCP
Vercel
Railway
Cloudflare
Supabase

Issue Tracking

Trace opens a ticket for every finding in your tracker, linked back to the full report, so remediation stays in your normal workflow.

LinearPentest Q46 issues
SEC-142SQL injection in /api/search
SEC-141IDOR on /api/invoices/:id
SEC-140SSRF in webhook fetcher
SEC-139Broken access control on exports
SEC-138Missing rate limit on login
SEC-137Verbose error leaks stack trace
Jira
Linear

Logs & Telemetry

Coming soon

Trace reads your logs to catch PHI or PII leaking into them and to confirm how your API routes actually behave.

app-prod · logsLive
12:04:01INFOGET /api/search 200 24ms
12:04:01INFOPOST /api/login 200 88ms
12:04:02WARNpii: email in /api/users response
12:04:02INFOGET /api/invoices/42 200 12ms
12:04:03INFOGET /api/orders 200 41ms
12:04:03WARNslow query 1.2s on /reports
12:04:04INFOPOST /api/webhooks 200 19ms
12:04:04INFOGET /api/profile 200 15ms
12:04:05WARNpii: ssn in /api/kyc log line
12:04:05INFOGET /api/search 200 22ms
Sentry
Datadog
Grafana
“After our pen test, we installed Trace’s PR reviewer so we could shift left and catch security issues before they ever merge.”
Madhu G NadigMadhu G NadigCo-Founder & CTO, Flagright

Trusted by fast-moving teams

We needed a new penetration test report for a 3rd party with high urgency, and Trace turned it around faster than a traditional firm could even get us on the calendar. Every finding came with a working exploit and clear remediation — no list of maybes to chase down. They surfaced real, exploitable issues we hadn’t caught.

Director of EngineeringAnti-fraud FinTech SaaS firm
01 / 06