Skip to main content

AI Penetration Testing

Get an in-depth, AI-driven penetration test of a web app on demand — one that reads your code, tests the live app to prove what's exploitable, and hands you an audit-ready report.

Written by Joe Haigh

An AI Full Pentest is an on-demand penetration test of a single web application, run end-to-end by Intruder's autonomous AI pentesting agents. It tests your web apps specifically, not your whole external network, so you can run one with every release instead of waiting for an annual or quarterly engagement.

It regularly surfaces critical issues that scanners and human testers both miss, such as authentication and authorization bypasses. Each finding is verified against the running app with live evidence, and the report points to the source file and line it comes from. When it finishes, you get a downloadable PDF report you can hand to an auditor or customer. Intruder's reports are routinely used as evidence for frameworks like SOC 2, ISO 27001, and PCI DSS.

ℹ️ Retesting

Retesting is free and unlimited. Once you have fixed what the report found, you can send those findings back for retesting as many times as you need at no extra cost, and each retest produces its own report confirming what is now remediated. Read more here.

Want to go deeper? Our Chief Security Technologist, Andy, has written a full breakdown of this feature and what it can do on our blog.


Setting up a Pentest

📌 Prerequisites

  • The Admin role in Intruder.

    • Only admins can create, pay for, or cancel an AI Full Pentest.

  • A connectable Bitbucket, GitHub, or GitLab repository for the app you want to test.

⚠️ Bot protection and CAPTCHAs Warning

Two different things can prevent an AI pentest from running, and they require different fixes:

1) Something blocking our scanner before it reaches your app


A web application firewall, CDN, or bot-protection service (e.g., Cloudflare, AWS WAF, Akamai, Imperva, etc.) may challenge, throttle, or block our traffic so we never reach your application. Allowlisting our 64.52.19.0/24 IP range fixes this, and we recommend doing it before any pentest.

2) A CAPTCHA on your login form.


If your login page uses a "verify you are human" widget (Cloudflare Turnstile, Google reCAPTCHA, hCaptcha), it may block our agent from signing into your application. These checks run before password validation, so a login failure often means your credentials were never actually tested.

To fix this, we recommend trying one of the following:

  1. Disable the CAPTCHA entirely - The simplest option. Toggle it off via your application's settings or environment variables for that specific environment.
    ​

  2. Switch to test keys - Providers offer dummy keys that always pass (e.g., Cloudflare Turnstile's testing keys). You must change both the site key (frontend) and the secret key (backend)—updating only the frontend will cause your server to reject the login.
    ​

  3. Use a different environment - Point us to a dedicated staging or test environment where the CAPTCHA is already disabled.
    ​

  4. Skip the CAPTCHA for our IP range in your application - If your code can bypass the check for specific source IPs, add our published 64.52.19.0/24 IP range there. This keeps the CAPTCHA active for everyone else while letting our agent through.

To start, go to the Pentests tab and click New pentest

You'll then see an overview of the feature: what you get, the price, a link to a sample report, the terms and conditions, a Learn more link back to this article, and an Ask us anything button if you'd rather put a question to the Support team first.

If you already have a setup in progress, the overview is skipped and you go straight back into it.

Once you have selected an AI Pentest, you will be presented with a form taking you through the setup stages: two parts are required (Scope and Source), and two are optional (Accounts and Context). Everything you enter saves automatically.

Scope

Scope tells the AI agent what to test.

  • Environment

    Choose Development, Staging, or Production (not recommended).

⚠️ Important

We explicitly advise against running an AI Full Pentest in Production. The agent takes real, sometimes destructive actions and its behavior can't be fully predicted — a production test can disrupt your live service, your users, and third parties you rely on. Use a staging, test, or development environment wherever possible.

If you have no alternative, the AI Pentesting terms require that you've taken full backups or snapshots beforehand, can roll back any changes, and have accepted the risk of disruption. These are conditions of testing production, not an assurance that it's safe.

  • Entrypoint URL

    Select an existing target, or enter a custom URL for the agent to start testing from.

🛑 Critical

Never run an AI Full Pentest against safety-critical or physical systems — industrial control, OT or SCADA systems; medical or life-safety systems; vehicles, aircraft or marine systems — or against any system you don't own or aren't authorized to test.

These are prohibited targets under the AI Pentesting terms.

  • App name

    Name your application — this is how it appears in your report.

  • App overview (optional)

    Briefly describe what the app does and who uses it, for example: "B2B SaaS platform for managing invoices. Used by accountants and their clients." This gives the agent context before testing starts.

Test Accounts (highly recommended)

Test accounts let the agent log in and test the authenticated parts of your app, which is usually where the interesting risk lives. If your app has any kind of login, adding credentials matters: without them, the agent can only test what's reachable when logged out, so most of the application goes untested. Only skip this step if the target is a fully public site with no authenticated area.

We highly recommend adding as many accounts as you can, covering every access level in your app — and, if it's multi-tenant, accounts belonging to different tenants or customers. This lets the agent test for privilege escalation and cross-tenant authorization failures, where a user reaches data or actions they shouldn't, which are among the most common critical issues it finds. As a rule of thumb, more is better — we test our own platform with roughly a dozen accounts covering every access level.

To add an account:

  1. Select Add account and choose either User account or API account

  2. For a User account, enter a username or email, a password, and a note under Account access describing what the account can reach, for example: "Admin with full access."

    If a user account is protected by TOTP-based 2FA, turn on Use authenticator app (TOTP) and enter the Authenticator secret:

    The secret field takes either the secret key itself or a full otpauth:// URL, so you can paste whichever your authenticator app gives you.

  3. For an API account, enter a name, the header or parameter that carries the key (e.g. X-API-Key), the API key value, and a note describing what the account can access.

  4. Repeat to add more. Each account card can be collapsed, expanded, or deleted.

💡 Tip

Provide accounts covering as many access levels as you can so the agent can reach more of your app. Because the agent may take destructive actions to confirm a weakness is real, the safeguard that matters is running against a non-production environment: if the test affects data there, it doesn't matter.

Source code

Source code is where you connect the repository that the agent reviews. This is a required part of an AI Full Pentest — the test is code-assisted, so the agent needs to read your code to pinpoint where issues originate.

  1. Select Bitbucket, GitHub or GitLab. Providers you've already connected appear as cards showing how many repositories we can see. Anything not connected is listed underneath, and selecting it connects it there and then.

    GitLab and Bitbucket connect in a window inside the setup. GitHub installs as an app, so it opens the integrations page in a new tab, and you come back once it's done.

    ℹ️ Note: Bitbucket means Bitbucket Cloud. Bitbucket Server and Bitbucket Data Center aren't supported. Bitbucket also asks for your Atlassian account email alongside the API token, where GitHub and GitLab only need the token.

  2. Select a repository and a branch.

  3. Add notes to guide the agent, for example: "Monorepo — focus on /services/auth. Ignore generated code in /dist."

  4. Select Add repository to include more than one repo (these need to be from the same platform). You should connect as many repos as you need to cover the application.

Repositories are connected read-only, are not accessed by a person, and our engagement data is deleted when the pentest is torn down; we may keep limited source code excerpts for up to 30 days to improve the service. See the Intruder Trust Center for the full picture.

⚠️ Important

Switching providers after adding repositories removes any repositories already added under the previous provider. You're asked to confirm first, naming both providers, before anything is cleared. Add all repositories from one provider before switching.

Context (highly recommended)

Context is where you point the agent at what matters. Every field is optional, but highly recommended. The more you give, the more targeted the results.

  • Environment details

    • What the environment is and what it's built on, for example: "Staging, identical to production but with no WAF or rate limiting. Frontend on CloudFront/S3, API on Lambda in a private VPC, PostgreSQL on RDS." Most useful for things the agent can't infer, like a third-party payment provider or an API the app depends on.

  • Areas of concern

    • The best place to set scope expectations when you don't want the whole application tested. Say what to prioritize, and call out anything that should not be tested, for example: "Focus on the checkout and admin panel. Don't test the data-export endpoint."

  • Other

    • Anything else that helps. It's especially worth flagging intentional behavior that might otherwise be reported as a vulnerability — for example, a deliberately public endpoint, or a debug header that's expected in staging — so the agent doesn't raise it as a finding.

💡 Tip

Areas of concern is the highest-leverage field — it's where you both point the agent at what matters and mention anything that shouldn't be tested.

Checkout

Checkout shows a summary of your configuration to review, then handles payment.

  1. Check the summary matches what you intended. You can go back to any earlier section to make changes.

  2. Accept the terms and conditions.

  3. If you chose a Production environment, you'll also confirm you understand you've selected a production environment and accept that the test may affect your live systems.

  4. Complete payment.

    1. Payment is handled by Stripe (card, Apple Pay, Google Pay, and more). Depending on your account, an invoice option may also be available.

    2. If you've already bought pentests in bulk, checkout shows Prepaid pentest instead of a payment method, and the button reads Start pentest rather than asking you to pay again.

  5. Once payment completes, the pentest starts.

Starting over

To discard your progress and start fresh, open the ⋯ menu at the top of the setup and select Start again. This menu is available throughout setup. Starting again clears your saved draft completely — there's no undo.

⚠️ Important

Start again wipes the entire draft, including any credentials, repositories, and context notes you've added. If you only want to change one thing, go back to that specific section instead.


What happens after you submit

After you submit, you're taken to the pentest's status page, where the AI agent's progress is shown in real time — moving from Pending to Running to Completed. You can leave and return; the pentest keeps running regardless.

Before testing gets fully underway, Intruder runs preflight checks that confirm it can access your repository and log in with any credentials you supplied. If a check fails, you'll see a clear error — "Source code check failed" or "Accounts check failed" — with a Contact us button, so a misconfigured repo or credential doesn't quietly waste a test.

⚠️ Important

To prove what's exploitable, the agent takes real actions on your target — it may create, modify, or delete data, submit forms, upload files, or trigger notifications, workflows, and third-party integrations. This is by design and stays within the scope you authorize. It's why staging is the safe default, and why you should take a backup before testing production.

You can cancel at any point up until a report has been generated — while the pentest is still running, a Cancel pentest button is available on the status page. Canceling stops further testing, but can't undo actions the agent has already taken. It does not refund the test, and it won't produce a report for that engagement. If you want to resume a canceled pentest, contact us — but we can't guarantee it can be continued. Once the report exists, the pentest is complete and can't be canceled, but you can still leave feedback or raise questions with support.


Your report

The deliverable is a downloadable PDF report, accessed through a secure, time-limited link, and built to be handed to a third party. It follows a consistent structure:

  • Executive summary — a plain-language account of what was found and the business risk, with recommended remediation timelines.

  • Overview — the scope, the accounts used, what was out of scope, and the test's limitations.

  • Summary table — every finding ranked by risk, each with a reference (VULN-001, VULN-002, …).

  • Findings — for each issue: a risk rating, its impact and likelihood, a description, live evidence, technical detail, remediation advice, and the exact source file and line where it originates.

  • Appendices — the risk-rating methodology (risk is impact × likelihood, rated Info / Low / Medium / High / Critical), the testing methodology, and an About Intruder section covering accreditations and the team behind the agent.

Findings come with built-in recommended remediation SLAs — Critical within 24 hours, High within 7 days, Medium within 30 days, Low by the next release — so you have a timeline you can commit to internally or show an auditor.

ℹ️ Note

Intruder's reports are routinely used to satisfy compliance frameworks such as SOC 2, ISO 27001, PCI DSS, and Cyber Essentials, and have been accepted in B2B supplier security audits. An AI Full Pentest report is designed to stand in for — or supplement — a traditional manual pentest report for these purposes.

Contents Page

Summary Section

Vulnerability Details

You can use the report internally and share it with your own customers, regulators, auditors, and professional advisors to demonstrate your security posture. You can't share it with other third parties — in particular, providers of competing security testing services — without Intruder's written consent.

ℹ️ Info: You can find a downloadable sample PDF report here:

Retesting your findings

What is retesting?

Retesting is a follow-up test that checks whether the findings from your AI Full Pentest have actually been fixed. Retesting is included with every AI Full Pentest at no extra cost, and there is no limit on how many times you can retest. You choose which findings to send back, the agent rechecks only those, and you get a new report showing which are remediated and which are still present.

How to run a retest

  1. Open the completed pentest from the Pentests tab.

  2. In the Findings section, select Retest.

  3. Tick the findings you want rechecked, or use Select all. Findings already confirmed Remediated cannot be selected again.

  4. Select Retest selection, then confirm with Retest.

Retesting needs the Admin role, the same as setting up a pentest.

While a retest runs, the pentest page shows Retest in progress with an elapsed timer, and each finding being rechecked shows a Retesting badge. You can leave the page and come back; the retest keeps running.

What a retest covers

A retest covers only the findings you selected from your most recent report. It does not test the rest of your application again. Changes made elsewhere since the original test are not tested, except where they relate directly to the findings being rechecked. If you want the whole application tested again, that is a new AI Full Pentest.

A retest reuses the setup from the original pentest: the same scope, the same source code repositories, and the same test account credentials. There is nothing to configure. If those credentials have changed since the original test, contact us before starting the retest and we will update them for you.

What you get back from a retest

Each retest produces its own PDF report, separate from your original report. The retest report:

  • Is dated Retested on [date] on the cover.

  • Lists every finding from the original test, with remediated ones greyed out in the summary table.

  • Marks any finding whose risk rating changed during retesting with a severity change indicator.

  • Includes a timeline of the original test and every retest, showing what had been remediated by each point.

  • Adds a short retest summary to each finding, explaining the outcome.

In the portal, each retested finding ends up as either Remediated or Still present. The Executive summary on the pentest page becomes a Retest summary once your first retest completes.

⚠️ Important
Download and keep each retest report. Intruder keeps your original test report and your most recent retest report available to download. Reports from earlier retests cannot be downloaded again.

Retesting limits

  • One retest at a time. You cannot start a retest while another one is running, or while the original pentest is still running.

  • Open findings only. Once a finding is confirmed remediated it drops out of the selectable list.

  • At least one finding must still be open. If everything has been fixed, there is nothing left to retest.


FAQs

Do I have to pay for a retest?

No. Retesting is included with your AI Full Pentest at no extra cost, and there is no limit on how many retests you can run.

How many times can I retest?

As many times as you need. There is no cap on the number of retests. You can only run one retest at a time, so wait for one to finish before starting the next.

Can I retest only some of the findings?

Yes. You choose which findings go into each retest, either individually or with Select all. Findings you leave out are unaffected and can be retested later.

Does a retest test my whole application again?

No. A retest checks only the findings you select from your most recent report. It does not retest the rest of the application and will not pick up new issues introduced since the original test. To test the whole application again, buy another AI Full Pentest.

Do I get a new report after a retest?

Yes. Each retest produces its own PDF report showing which findings are now remediated and which are still present. Your original test report stays available to download alongside it.

Who can start a retest?

Any user with the Admin role on your Intruder account, the same permission needed to set up an AI Full Pentest.

Do I have to connect source code?

Yes. An AI Full Pentest is code-assisted, so a connectable GitHub, GitLab, or Bitbucket Cloud repository is required. The agent reviews your source as part of the test. If you can't connect a repo, you can't run one yet.

Which source code providers can I connect?

GitHub, GitLab, and Bitbucket Cloud. Bitbucket Server and Bitbucket Data Center aren't supported. All the repositories in a single pentest have to come from the same provider.

Do I have to add test accounts?

Test accounts are optional in the wizard, but if any part of your app sits behind a login, you should add them — without credentials, the agent can't reach those areas, and most of the app goes untested. For a site with no authenticated area, you can skip this.

What does an AI Full Pentest cover?

It's a web application penetration test, run both unauthenticated and (if you supply credentials) authenticated. It covers the OWASP Top 10 and beyond — authentication and session handling, authorization, business logic, input validation and injection (XSS, SQL injection, command injection, and similar), file uploads, information leakage, and server configuration. Denial-of-service, social engineering, phishing, and physical security testing are out of scope.

How much does an AI Full Pentest cost?

Each AI Full Pentest is a one-off, per-engagement payment. The exact price is shown at checkout before you pay; it varies by currency and by whether you're on a paid plan, and existing paying customers currently get a discount.

How long does an AI Full Pentest take?

Most run in minutes to hours, depending on the size and complexity of your app and how much context you've given the agents. You don't need to wait around — progress shows on the status page in real time, and you can leave and come back while it runs.

Can I cancel an AI Full Pentest after starting?

You can, up until a report has been generated, using the Cancel pentest button on the status page. However, canceling stops the test, but it isn't refunded, and won't produce a report for that engagement. Resuming a canceled pentest isn't always possible, so contact us if you need to. Once the report exists, the pentest is complete.

What happens to the credentials and code I submit?

Credentials are encrypted at rest and never included in reports or logs. Nobody at Intruder ever accesses a complete copy of your repository. Your source code is sent to Anthropic's Claude API as part of the test, where it may be held for up to 30 days before deletion, and Intruder may keep limited source code excerpts for up to 30 days to improve the service. Everything else from the engagement is deleted at teardown. Your data is never used to train or fine-tune any AI model.

For the exact retention periods, sub-processors, and data flows, see the AI Pentesting terms and our Intruder Trust Center - AI FAQs.

Who's behind the AI agent's methodology?

The methodology is distilled from Intruder's in-house security team, whose qualifications include CREST certifications and the Offensive Security Certified Professional (OSCP). Intruder is a CREST member company, is SOC 2 Type II compliant, holds Cyber Essentials, and was selected for the UK government's GCHQ Cyber Accelerator. The agent applies the same methods as a human tester — sending requests, analyzing responses, and validating findings against the live app. Full details are in the About Intruder appendix of every report.

Is my data used to train AI models?

No. Your data, including any source code, is never used to train or fine-tune any AI model, and each customer's data is kept isolated from every other customer's. The Intruder Trust Centre has the full breakdown of what's sent where.

Does an AI Full Pentest expire, and can I re-run it?

An AI Full Pentest is a one-off engagement against a single target. You cannot re-run the full test, extend it, or change the target after it launches without buying another. You can, however, retest its findings as many times as you need at no extra cost. A purchased pentest must be used within 12 months.

Troubleshooting

Setup won't let me leave the Scope section.

  • Cause: A required field is missing — Environment, Entrypoint URL, or App name.

    • Fix: Fill in all three before continuing. (These are the only fields Scope checks; App overview is optional.)

  • Cause: A pentest is already running on the target you selected.

    • Fix: Wait for it to complete, or choose a different entrypoint. You can't start a second pentest against a target that already has one in progress.

Setup won't let me leave the Source code section.

  • Cause: No repository is added, or a repository is missing its branch.

    • Fix: Add at least one repository and select a branch for it. Source code is required for an AI Full Pentest.

My pentest failed a preflight check.

  • Cause: "Source code check failed" — the scanner couldn't access your repository.

    • Fix: Check that the integration is still connected and the repo and branch still exist, then use the Contact us button on the error, and we'll help you resolve it.

  • Cause: "Accounts check failed" — the scanner couldn't log in with one of the accounts you supplied.

    • Fix: Confirm the username, password, or API key are correct and still active, then use Contact us for help.

I didn't type https:// — will my Entrypoint URL still work?

  • Cause: You entered a URL without a scheme.

    • Fix: This is fine. If you leave off the scheme, https:// is added automatically, and surrounding spaces are trimmed. There's no need to strip trailing slashes.

I added a repo, then switched provider, and my repo is gone.

  • Cause: Switching providers removes any repositories added under the previous provider (you're warned first).

    • Fix: Pick one provider and add every repository before switching. If you need to change provider, expect to re-add everything.

The GitHub, GitLab, or Bitbucket integration won't connect.

  • Cause: You're connecting a self-hosted GitLab (or similar) instance that sits behind a firewall or WAF, or is only reachable over a VPN.

    • Fix: A self-hosted instance behind a WAF needs our scanner IP ranges allowlisted, and may also need an additional address to be allowlisted — contact support and we'll work through it with you, case by case.

    • Instances that are only reachable over a VPN can't be supported.

  • Cause: Your Intruder user can't authorize integrations.

    • Fix: Ask an admin to connect it, or have them grant you the permission.

  • Cause: The OAuth flow was blocked by your browser.

    • Fix: Allow pop-ups for intruder.io and retry.

  • Cause: Your Bitbucket API token is missing a scope.

    • Fix: The error names the scope Bitbucket is asking for. Create a new scoped API token with read:repository:bitbucket, read:workspace:bitbucket, and read:user:bitbucket, then reconnect. Atlassian's guide to creating an API token walks through it.

  • Cause: You're trying to connect a Bitbucket Server or Bitbucket Data Center instance.

    • Fix: Only Bitbucket Cloud is supported.

Payment failed at checkout.

  • Cause: The card was declined.

    • Fix: Update the card on file in Account settings > Billing and try again.

  • Cause: Your account is set up for invoicing, but the invoice option isn't showing.

    • Fix: Contact support — the invoicing arrangement on your account may need enabling.

I want to change a setting after starting the pentest.

  • Cause: Configuration is locked once the pentest is submitted.

    • Fix: Cancel the pentest (as long as no report has been generated), then start a new one with the corrected settings. Canceling doesn't refund the original, and a pentest that produced a report still counts as billable, so you'll pay again for the corrected run.

My repositories won't load in the Source code step.

  • Cause: A Bitbucket API token can connect successfully while still missing the repository or workspace scope, because only the account scope is checked when you connect.

    • Fix: Create a new token with all three scopes and reconnect.

  • Cause: The repository is in a workspace beyond the first 25 we list, or beyond the first 2,000 repositories in a workspace.

    • Fix: Contact us and we'll help.

The Retest button is not showing.

  • Cause: The pentest has not finished, or a retest is already running.

    • Fix: Wait for the run in progress to finish. You can only run one test or retest at a time on a given pentest.

  • Cause: Every finding has already been confirmed remediated.

    • Fix: There is nothing left to retest. Retesting only applies to findings that are still open.

  • Cause: Your user does not have the Admin role.

    • Fix: Ask an admin on your account to start the retest, or have them grant you the Admin role.

I cannot download the report from an earlier retest.

  • Cause: Only the original test report and the most recent retest report stay available to download.

    • Fix: Download each retest report when it is produced and keep your own copy. If you need an earlier one, contact us.

Glossary

  • AI Full Pentest — An in-depth, code-assisted penetration test of a web application, run by an AI agent and paid for as a one-off. Distinct from AI Issue Validation.

  • Code-assisted penetration test — A test that combines review of the application's source code with live testing of the running app, so each finding is backed by real evidence and mapped to the exact code responsible.

  • AI pentesting agents — The autonomous system that runs the pentest: a pipeline of specialized agents that interpret your scope, source code, credentials, and context, test the target, and produce a report.

  • Preflight check — An automated check run before testing proceeds, confirming the agent can access your repository and log in with any supplied credentials.

  • Entrypoint URL — The URL the AI agent uses as its starting point when testing the app.

  • Retest - A follow-up test that rechecks selected findings from a completed AI Full Pentest to confirm whether they have been fixed. Included at no extra cost, and produces its own report.

    • Remediated - The status a finding is given when a retest confirms it has been fixed.

    • Still present - The status a finding keeps when a retest finds it is not yet fixed.

Did this answer your question?