AXUM SEC Beta Launches in 10 Days

Africa's first unified bug bounty and PTaaS platform is almost here. Join 500+ ethical hackers and security experts already on the platform.

AI Agents Coming SoonAXGNT and AXUMIS are almost here. Autonomous AI pentesting that thinks, reasons, and adapts like human experts. Operating 24/7 at machine speed.AI Agents Coming SoonAXGNT and AXUMIS are almost here. Autonomous AI pentesting that thinks, reasons, and adapts like human experts. Operating 24/7 at machine speed.
Axum SEC Logo
Back to documentation
AIAICapabilities

AI assistance

Version 1.03 min readLast updated September 23, 2026

Where AI is applied across triage, remediation guidance, reporting and researcher support — and where human judgement is required.

AI on AXUM SEC is applied to the parts of running a security program that do not scale by hiring: classification, overlap detection, drafting and summarisation. It is designed to take administrative load off the team, not to replace the decisions that carry contractual or legal weight.

Where it is applied

CapabilityWhat it doesHuman decision that remains
Automated triageClassifies a submission and predicts severity so reviewers start from a proposalSeverity confirmation and reward pricing
Duplicate intelligenceFlags likely repeats, including across programsMerge, attribution and reward split
Remediation guidanceTechnology-specific fix guidance with before/after examples and testing stepsWhether the fix is acceptable
Report generationDrafts structured reports from raw findings and evidenceReview, edit and sign-off
Threat modelling assistanceSupports structured threat modelling workshops and outputModel validity and prioritisation
Policy generationDrafts program and disclosure policy text aligned to your programLegal review
Risk scoringModel-based scoring to support prioritisationAcceptance of the score
Researcher assistantHelps researchers structure a submission before it reaches triageValidation on arrival

Remediation guidance

Guidance is written for the technology in use rather than in generic terms, covering the languages and frameworks most commonly found in customer codebases — Node.js, Python, Java, PHP, Go and their common frameworks.

Each guidance block typically contains:

  • What the issue is in plain language, tied to the affected code path.
  • Why it is exploitable, including the preconditions.
  • A before/after example showing the vulnerable pattern and a corrected one.
  • Testing steps — how to confirm the fix actually closes the finding rather than hiding it.

Guidance is a starting point for the engineering team, not a substitute for their understanding of the codebase.

Report generation

Reports assembled from raw findings keep the structure auditors and stakeholders expect: summary, severity, affected assets, reproduction, evidence, impact and remediation. Drafting is automated; the reviewer edits and approves before anything is published or attached to a compliance pack.

The researcher assistant

Submissions improve when the reporter gets help before they hit send. The assistant prompts for missing reproduction steps, checks that the affected asset is in scope, and suggests the evidence a triage team will ask for. Higher quality input means a higher validation rate and less back-and-forth for everyone.

What it does not do

  • It does not auto-close reports on similarity alone.
  • It does not set the reward — pricing follows the program's severity model and the reviewer's decision.
  • It does not replace legal review of disclosure policy, or tax and compliance advice on payouts.
  • Drafted content is always attributed as drafted and requires human approval before it leaves the platform.

Availability and limits

  • AI triage, duplicate intelligence and automated payouts are Professional-tier.
  • Threat modelling assistance and advanced vetting are Enterprise-tier.
  • Availability of individual features can change; confirm the current tier on the platform's plan comparison before relying on a capability in a contract.