Reflectiz launches an AI-powered, multi-agent penetration testing platform that discovers, exploits, and validates web vulnerabilities to improve coverage and accelerate remediation.
Reflectiz, a continuous web exposure management company, today announced the launch of its multi-agent penetration testing platform for websites. The platform uses specialized AI agents to discover, attack, and validate vulnerabilities across complex web environments. Because testing begins with an existing model of each website, security teams can achieve up to 10 times the coverage of traditional penetration testing tools while reducing noise and speeding remediation.
Traditional penetration testing is often treated as a one-time event. Once testing and reporting are complete, the results represent only a snapshot of the website at that moment. Meanwhile, websites continue to evolve, with logins, checkouts, payment flows, and third-party scripts being changed and targeted by attackers every day.
“Websites change weekly and are penetration tested once or twice a year, and those gaps are where exposure accumulates,” said Idan Cohen, CEO and co-founder of Reflectiz. “Teams need testing that can keep up with releases at a sustainable cost, along with reliable coverage of what is being tested.”
Unlike conventional tools that begin testing without context, Reflectiz already understands your website.
For more than 10 years, Reflectiz has scanned thousands of production websites and maintained live models of their digital environments. These models include pages, scripts, third-party services, domains, sensitive inputs, and user behaviors. Reflectiz’s AI penetration testing agents build on this existing intelligence to bring an attacker’s perspective to the same continuously updated model.
Findings include the relevant scripts, the data those scripts can access, and whether real users are currently exposed. This allows security teams to move beyond time-consuming research and focus directly on remediation.
“The difficult part of web penetration testing wasn’t the payload; it was understanding what the application actually did,” said Ysrael Gurt, CTO and co-founder of Reflectiz. “Because our engine has been analyzing live websites for years, the agent starts with a detailed map of the site that other tools do not build.”
A coordinated team of specialized AI agents
Reflectiz agentic penetration testing uses a coordinated team of AI agents, with each agent assigned a specific role:
- Website discovery agent: Crawls the website like a real user, navigating logins, one-time passcodes, and two-factor authentication to map the live application.
- Technology fingerprinting agent: Identifies the application stack and determines which attacks should be applied to specific pages, components, and user flows.
- Attack execution agent: Performs targeted attacks and chains related vulnerabilities to identify realistic exploitation paths.
- Independent verification agent: Reproduces every result before it reaches the final report, helping remove false positives by design.
The result: Security teams receive validated findings with reproduction steps and supporting evidence, along with a coverage map showing which areas were tested and cleared.
Testing covers the full range of the OWASP Top 10. Teams can configure the depth of testing for each application flow, from predefined rapid checks to expert-level attack chains targeting critical assets.
Complete your 360-degree map of web security risks
Agent Penetration Testing is part of Reflectiz’s new Offensive Hub. It joins Security Hub and Privacy Hub to provide a 360-degree view of web risk—including what runs on a website, what data those technologies access, and how the website could be attacked.
- Unified exposure view: Results from all three hubs are automatically cross-referenced, without requiring manual dashboard adjustments.
- Guided remediation: Atlas, the Reflectiz AI remediation agent, explains each risk and guides security teams through the recommended fix.
- Existing security workflows: Findings can be routed into current operations through REST APIs, CI/CD triggers, and Slack alerts.
Watch the AI penetration testing platform in action
Reflectiz founders Idan Cohen and Ysrael Gurt will demonstrate the company’s agentic penetration testing platform during a live webinar on September 15 at 11 a.m. ET / 6 p.m. CET.
Registration: Register for the live webinar
Product information: Reflectiz Offensive Hub | Watch the walkthrough video
About Reflectiz
Reflectiz is a continuous web exposure management company. Its agentless, outside-in platform monitors, tests, and protects the entire web layer—from third-party scripts and web privacy risks to AI-powered penetration testing of live websites. Reflectiz helps retail, financial services, travel, insurance, healthcare, and gaming organizations address PCI DSS, DORA, NIS2, and global privacy requirements without changing their source code. Learn more at https://www.reflectiz.com.
Contact
Marketing Manager
Oran Frenkel
Reflectiz
[email protected]
Source: www.nextbigfuture.com


