AXUM SEC Beta Launches in 10 Days

Africa's first unified bug bounty and PTaaS platform is almost here. Join 500+ ethical hackers and security experts already on the platform.

AI Agents Coming SoonAXGNT and AXUMIS are almost here. Autonomous AI pentesting that thinks, reasons, and adapts like human experts. Operating 24/7 at machine speed.AI Agents Coming SoonAXGNT and AXUMIS are almost here. Autonomous AI pentesting that thinks, reasons, and adapts like human experts. Operating 24/7 at machine speed.
Axum SEC Logo
AXUMIS · AI Pentesting Engine

The AI pentesting engine,operated for you —or run by your team.

AXGNT orchestrates a team of AI specialists, AXUMIS does the testing, and validated findings land straight in your AXUM SEC tenant. Or install AXUMIS-LOCAL inside your own perimeter and run it yourself.

Same engine · same evidence ledger · same CVSS scoring · same replayable PoCs

AXGNTroot planner
Recon
Web
API
Mobile
Code
Validation gatere-tested
live spans · SSEaxgnt://engagements/live

planner·decompose objective → 6 sub-goals

recon·amass + httpx → 43 live hosts

web·testing /api/v2/orders for IDOR

api·schemathesis fuzz → 500 on malformed scopes

Verified findings

Hundreds

reproduced with evidence

Critical in ~1 of 4

25%

engagements surface a critical

CVSS 3.1

6.0 mean

maximum 10.0

Dynamic testing

~90%

reproduced live, not inferred

One engine · two ways to run it

Managed for you, or installed in your perimeter

Same engine, same evidence ledger, same CVSS scoring, same replayable-PoC requirement. Nothing is “cloud tier” — what differs is who operates it and where the data lives.

AXUMIS-CLOUD

Delivered through AXGNT PTaaS orchestration

Request an engagement, watch it run live, and receive deduplicated, validated findings on your tenant. No installation, no maintenance.

zero ops
Who runs it
AXUM SEC, for you
Where it runs
AXUM SEC's environment
Orchestration
AXGNT + operator console
Best for
Teams that want PTaaS with zero ops
Data leaves your network
Findings only (into AXUM SEC)
Setup
Request an engagement
Live view
Streamed by AXGNT
Findings land in
Your AXUM SEC tenant

AXUMIS-LOCAL

An enterprise installation for your security team

Runs entirely inside your perimeter: agent, memory, evidence, and reports stay on your infrastructure. Export Markdown, PDF, SARIF or JSON into your trackers and CI.

air-gap ready
Who runs it
Your security team
Where it runs
Your infrastructure
Orchestration
Your own console / CLI
Best for
Strict data residency or air-gapped requirements
Data leaves your network
Never
Setup
One-command install
Live view
Local viewer UI
Findings land in
Your filesystem, CI, and ticket tracker
same engine same evidence ledger same CVSS scoring MD · PDF · SARIF · JSON
Why agentic pentesting, as a service

Traditional pentesting is expensive, slow and inconsistent. So is rolling out your own AI tool.

AXGNT + AXUM SEC remove both problems at once.

Hiring & cost

A good pentester is scarce and costly.

Your security team simply requests an engagement; AXGNT spins up a team of AI specialists (recon, web, API, mobile, code, reviewer) that plans, tests, and reports autonomously.

Ops burden

Standing up and running AI pentesting is work.

AXGNT operates it for you: engagement lifecycle, agent orchestration, and an operator console with live telemetry — nothing to install or maintain.

Coverage gaps

Humans miss things under time pressure.

Planned, evidence-driven testing with a test-case ledger, attack-chain mapping, and a quality gate before the engagement is allowed to finish.

Unverifiable reports

Findings without proof are just noise.

Every finding ships with CVSS, evidence bundles, attack chains, and replayable PoCs — a reviewer LLM re-tests before sign-off.

Slow retests

Waiting weeks to confirm a fix.

Engagements resume where they left off, and cross-run delta reports show exactly what is new, recurring, or fixed.

Siloed tooling

Pentest output stuck in a PDF.

Findings flow directly into AXUM SEC vulnerability management, ready for triage and remediation tracking.
Track record

Real engagements, real findings

Aggregate results across the engagements we have run to date. These are counts of findings, never of clients — no client names, sectors-by-name, targets, hostnames, credentials, or engagement identifiers appear anywhere on this page.

Findingsby severity
  • Critical6%
  • High23%
  • Medium62%
  • Low9%

Evidence, not inference

Every finding reproduced with evidence — never inferred from a scanner feed.

Critical where it matters

Roughly a quarter of engagements surface at least one critical finding.

Auth is the weak spot

Findings concentrate in authorization, authentication and credential handling.

Live, not theoretical

~90% came from dynamic testing against a running system.

What it finds

distribution by weakness family

  • Information DisclosureCWE-200
    21%
  • Broken AuthenticationCWE-306
    11%
  • Broken Access ControlCWE-862
    10%
  • Security MisconfigurationCWE-16
    8%
  • Hardcoded CredentialsCWE-798
    8%
  • Cryptography / TransportCWE-327
    6%
  • Memory Corruption (dependency CVE)CWE-787
    5%
  • Broken Access Control (IDOR)CWE-639
    4%
  • Business LogicCWE-840
    3%
  • Denial of ServiceCWE-400
    3%
  • Rate Limiting / AbuseCWE-770
    3%
  • Integrity Check BypassCWE-345
    3%
  • Injection (XSS)CWE-79
    3%
  • CSRFCWE-352
    2%
  • Injection (SQL)CWE-89
    2%

The top three weaknesses are authorization and authentication failures — not scanner-fodder. CWE-306 (Missing Authentication), CWE-862 (Missing Authorization) and CWE-798 (Hardcoded Credentials) lead the list: the defects a template scanner cannot confirm and a time-pressured human tester runs out of hours to chase.

Where it has been used

Regulated banking & financeTelecomPayments & fintechNational identity & governmentRetail & e-commerceEnterprise portals & SaaSStandalone mobile applications

Target classes

  • Web applications
  • APIs — OpenAPI, GraphQL, Postman
  • Mobile / APK — static + dynamic
  • Source code — white box
  • IPs, domains & networks

We do not publish per-sector engagement counts, and no client is identifiable from anything on this page.

What the platform delivers

A live AI agent team, operated for you

Orchestration, sandbox, evidence and lifecycle — handled end to end, with you watching every step in real time.

A live AI agent team, operated for you

AXGNT orchestrates the root planner plus parallel specialist agents and streams the live agent graph, spans, plans and deltas to your console over SSE.

  • Start · pause · resume · cancel mid-run
  • Inject instructions and answer agent questions
  • Approve disruptive actions before they run
  • A Finding Reviewer sub-agent independently re-tests before sign-off

Coverage on demand

One engagement can mix every target class — web, API, mobile, code and network assets.

  • OpenAPI / Swagger and GraphQL schemas
  • Postman collections + schemathesis fuzzing
  • APK static analysis with dynamic ADB / Frida
  • Repos and white-box source review

Isolated, full-arsenal sandbox

Engagements run in an isolated Kali-based sandbox with 100+ tools, reset between runs — tooling is fully managed for you.

  • nmap, nuclei, sqlmap, OWASP ZAP, Metasploit
  • SecLists, gobuster, ffuf, amass, dalfox, feroxbuster
  • schemathesis, ligolo-ng, frida, objection, hashcat
  • Clean state per run, no cross-engagement bleed

Evidence-first findings

A finding is not confirmed until it can be reproduced.

  • Per-engagement evidence ledger: HTTP transcripts, commands, screenshots, OOB callbacks
  • CVSS 3.x scoring and attack-chain mapping
  • Test-case notebook per engagement
  • Markdown / PDF reports plus SARIF and JSON exports

Built for the security lifecycle

Everything after the engagement, handled — so testing compounds instead of resetting.

  • Resume any engagement where it left off
  • Delta and regression reports: new, recurring, fixed
  • Auto-remediation guidance and ticket filing to Jira / GitHub
  • Shared tenant memory with RAG so the platform learns your environment
isolated kali sandbox · 100+ tools · reset every run
nmapnucleisqlmapOWASP ZAPMetasploitSecListsgobusterffufamassdalfoxferoxbusterschemathesisligolo-ngfridaobjectionhashcatburp suitehydrajohn the ripperniktowpscansubfinderhttpxkatananmapnucleisqlmapOWASP ZAPMetasploitSecListsgobusterffufamassdalfoxferoxbusterschemathesisligolo-ngfridaobjectionhashcatburp suitehydrajohn the ripperniktowpscansubfinderhttpxkatana
How it's delivered

The whole engagement, on rails

AXGNT drives the lifecycle. AXUMIS does the testing. Confirmed findings land on your tenant — or on your own disk, if you run it yourself.

Step 01 · Request

A company requests AI pentesting from the AXUM SEC platform — which also hosts bug bounty and PTaaS. Targets, scope and instructions are defined up front.

AXUM SEC environment
Customer / companyrequests · watches live · receives vulns

AXUM SEC — main platform

Vulnerability ManagementBug BountyPTaaS

AXGNT — orchestration & operator console

AXUMIS — AI pentesting engineinternal

tests · evidence · reports → AXGNT

AXGNT → final report · dedup · validation

AXGNT updates the tenant's vulnerabilities in AXUM SEC

Customers never install or operate AXUMIS

In the managed model AXUMIS exists only inside AXUM SEC's environment and is delivered entirely through AXGNT and AXUM SEC. That is what AXUMIS-CLOUD is for.

  • All internal steps happen in our environment
  • Live operator console with streamed telemetry
  • Validated findings written onto your tenant
  • No installation, no maintenance, no tooling to patch
How it works for your team

Five steps from request to remediated

You stay in control the whole way: watch the AI team work, answer its questions, adjust scope mid-run, and receive findings that are already validated and deduplicated.

If you run it yourself

With AXUMIS-LOCAL the engagement is yours end to end: point it at your scope, watch it work in the local viewer, and take the findings straight into your CI and trackers. Nothing is sent to us.

Ask about an installation
  1. 1

    Request AI pentesting

    Targets, scope and instructions submitted from AXUM SEC.

  2. 2

    Watch it live

    AXGNT streams the AI team’s graph, plan and progress; answer questions or adjust scope mid-run.

  3. 3

    AXUMIS runs the tests

    Executed on AXUM SEC’s environment, reporting every raw finding with evidence back to AXGNT.

  4. 4

    AXGNT produces the report

    Duplicates removed, findings validated with CVSS, evidence, attack chains and replayable PoCs.

  5. 5

    Vulnerabilities updated

    Confirmed findings land on your tenant, ready for triage and remediation.

Security & privacy by design

Your perimeter, your rules

Local-first

Under AXUMIS-LOCAL the agent, its memory and all findings stay on your infrastructure. Under AXUMIS-CLOUD only findings transit into AXUM SEC.

Tenant-scoped memory

A per-company credential vault — credentials never leak across engagements.

Injection defence

Untrusted content is fenced and annotated before an agent ever reasons over it.

Operator approvals

The agent pauses and asks before disruptive actions are executed.

Scope enforcement

Every engagement is validated against an explicit in-scope / out-of-scope policy.

Questions

Everything teams ask before their first engagement

Still deciding between managed and self-hosted? We will scope it with you and tell you plainly which model fits your constraints.

AXUMIS · AXGNT

Request AI pentesting — or run AXUMIS inside your own perimeter.

Same engine, same evidence, same findings. Tell us the scope and AXGNT takes it from there.

Same engine · same evidence · same findings