Private technical preview — applications open for design partners

For professional pentesters and security teams

An AI-native pentest workbench, from recon to report.

Orchestrate the tools you trust, preserve every attack chain, and keep credentials and target traffic in your environment.

Private technical preview · built on the open-source RedAmon foundation
engagement · app.lab.internal
Local execution
Engagement graph
Attack graph An interactive chain connecting the lab application, import endpoint, metadata service, data store, and SSRF finding. app.lab.internal POST /api/import IMDS s3://data SSRF
click a node
Finding
no findings yet
01Engagement model

One engagement. One body of evidence.

Context compounds instead of resetting every session.

02Operator control

Agent when useful. Human when it matters.

Your decision changes the engagement — and control has a real cost. Both paths above are legitimate outcomes.

✓ You approve
  • Agent assumes app-prod-role and lists the bucket.
  • Impact is proven — 14,208 customer objects readable.
  • Finding lands Critical, confirmed, ready to report.
✕ You deny
  • Credential use is blocked and logged. Nothing touches the data store.
  • The agent reports the SSRF and role exposure from metadata alone.
  • Finding lands High, impact unproven — needs manual verification.
ScopeRules of EngagementApprovals Audit logEmergency stop
03Evidence

A finding you can defend.

Evidence, not severity badges.

SSRF → IAM credential theft → customer data

Critical
04Architecture

Reason in the cloud. Execute under your control.

Credentials, tools and target traffic stay on your machine.

Detailed data-boundary documentation is shared during preview onboarding.

Askar control planecloud
authenticated channel
Local execution planeyour machine
Click any component to see where it runs.
05Attack memory

Attack chains, not chat threads.

A pentest is dependent steps, not a stream of prompts.

Typed

Semantic, not decorative

Assets, endpoints, identities and evidence carry meaning the agent can query.

Persistent

Survives the session

Hypotheses and attack paths are retained across reconnect and restart.

Inspectable

You can read the state

An engagement model you can open — not a hidden context window.

06Tooling

Use the tools you already trust.

Askar orchestrates proven tools. It doesn't replace them.

07Platform

The full engagement, end to end.

Every stage of the workflow, in one system.

Recon

Parallel discovery

Subdomains, ports, services and technologies mapped concurrently into structured state.

Reasoning

Graph-backed context

A typed attack graph the agent queries — assets, endpoints, identities, objects, evidence.

Execution

Tool orchestration

Specialist security tools dispatched against hypotheses through your local execution plane.

Control

Scope & approvals

Rules of Engagement enforced in the executor, with per-action approval and a full audit trail.

Evidence

Reproducible proof

Requests, responses and attack chains captured as defensible case files.

Reporting

Structured output

Findings assembled for review, retest and remediation.

Built on an open-source foundation. Askar Security extends the agentic pentesting architecture of the open-source RedAmon project — an independent project with its own maintainers, whose work we build on and credit.

08Preview resources

Review the evidence before you commit.

These materials are shared directly with qualified preview teams as they become available.

Available during private preview

Sample case file

A redacted finding with request, response, attack chain, and remediation context.

Available during private preview

Data-boundary documentation

A detailed view of what runs in the cloud and what remains in your execution environment.

Available during private preview

Design-partner references

Reference conversations will be offered only after participating teams approve them.

Seeking design partners

Put Askar through a real engagement.

We’re working with a small number of professional pentesters and security teams. Tell us what you want to evaluate and we’ll follow up about fit and access.

  • No credentials or target data requested
  • Direct conversation with the product team
  • Private preview; no public-launch claims
Please do not include credentials, target details, or sensitive engagement data.

We use these details only to respond about the Askar technical preview. Website visits are handled as described in our privacy notice.