Skip to content

AI pen-test scans

An AI pen-test scan turns Vortex into an agentic, ML-driven pen-tester. Instead of running a fixed checklist, it reasons about your application the way a human attacker would: it explores, forms hypotheses, and attempts to exploit what it finds — working through distinct phases and narrating its reasoning as it goes.

The AI pen-tester is generally available on Growth and higher.

The AI pen-test works in four phases, shown as a timeline on the report. The phase indicator advances as the scan progresses, so you can watch it move from reconnaissance toward exploitation in real time.

PhaseWhat happens
ReconnaissanceMaps the application, discovers surfaces, and gathers context
Vulnerability ScanningProbes the discovered surfaces for weaknesses
ExploitationAttempts to actively exploit promising findings to confirm impact
ReportingConsolidates confirmed findings into the report

Throughout the scan, the report shows a live thought trail — a running log of the AI’s reasoning. You can follow why it chose a particular surface, what it tried, and what it concluded. This makes the results auditable: you see not just what was found but how.

  1. Go to VortexRun scan.
  2. Choose your target site.
  3. Set the scan type to AI.
  4. Choose an intensity — higher intensities let the pen-tester go deeper.
  5. Optionally scope the test to specific routes. If you’ve configured routes for the site, you can point the pen-tester at the whole site or narrow it to particular routes.
  6. Optionally attach test users for authenticated testing (see below).
  7. Launch, then watch the phase timeline and thought trail on the report page.

To let the pen-tester reach surfaces behind a login, attach pre-configured test users when you launch. The AI signs in with those credentials and reasons about the authenticated parts of your application — often where the most serious issues live. Configure test users ahead of time so they’re ready to attach — see Authenticated scanning.

  • The AI pen-tester generally requires Growth or higher. If the AI scan type is unavailable, your plan may need an upgrade — check pricing in the app.
  • Acting on a finding with Fix with AI consumes a remediation credit and requires a connected version-control integration — see AI remediation.