Bugcrowd is proud to unveil Savant Pathseeker, our agentic pentesting solution. By operating autonomously at machine speed, Savant Pathseeker can quickly identify vulnerabilities in web applications and APIs and provide evidence of exploitability. With this launch, Bugcrowd is the most complete platform that supports the complete preemptive security testing lifecycle in one place: autonomous testing in pre-production or production environments, asset discovery and scanning, and agentic and/or human-led validation.

To apply for early access to Savant Pathseeker, click here.

The need for automated pentesting

Attack surfaces are expanding faster than security teams can test them. Cloud, SaaS, and API sprawl means most organizations have assets that have never been touched by a penetration test or any other testing. 

This problem has only worsened with the adoption of generative AI models. While it allows organizations to ship code at a much faster rate, AI-generated code often contains security vulnerabilities; a recent study shows that 45% of AI-generated code contained security flaws. Threat actors are also adopting AI models to discover, chain, and exploit vulnerabilities faster than ever before, resulting in an increase in cyberattacks. As a result, the regulatory landscape is changing: regulators overseeing common regulations (SEC, DORA, NIS2) now require demonstrable, continuous validation—point-in-time attestations no longer cut it. 

To get ahead of this shift, companies are adopting preemptive security to continuously scan all assets and neutralize threats before attackers can exploit them. But this requires ongoing testing across the entire attack surface, which requires overcoming several challenges. For one, many companies lack the people, hours, and budget; instead, a handful of crown-jewel applications get intensive, if infrequent, manual testing, leaving them exposed for months at a time. Meanwhile, everything else gets high-volume, noisy scanner output, or worse, nothing at all. Additionally, the stack for launching preemptive security programs is completely fragmented: pre-deployment testing, asset discovery and scanning, and human-led validation are delivered by different tools, aligned with different KPIs, and disconnected from one another. The result is a security program that looks complete on paper but leaves most of the real attack surface unvalidated.

Meet Savant Pathseeker

Bugcrowd Savant Pathseeker is an agentic testing solution that provides non-destructive, evidence-based security coverage for all of a company’s web applications and APIs. Rather than simply flagging known issues, it actually attempts exploitation (reconnaissance, vulnerability mapping, exploitation, and reporting) and provides evidence of whether an attack succeeded. As a result, security teams can easily assess more external assets on an ongoing basis, while still protecting the privacy of their data. Here are additional benefits of Pathseeker: 

  • Delivers speed and scale—Delivers industry-standard pen tests in hours, so you can test your entire attack surface more often and remediate vulnerabilities faster. Plus, with Attack Surface Management built into the same platform, you can continuously test new assets with both AI agents and human researchers without stitching together tools.
  • Returns prioritized findings—Pathseeker returns risk-ranked results and chain-attack paths, allowing teams to focus their efforts on investigating the most important vulnerabilities. 
  • Augments human testing—Pathseeker helps teams raise the floor for baseline coverage, allowing human researchers to focus their expertise on complex, high-stakes tasks (such as chaining individual flaws into multi-step attack paths) or creating nuanced, defensible reporting for auditors. This increases coverage without increasing cost. 
  • Helps with compliance—While teams often still need to run human pen tests to fully meet compliance requirements (agentic pentesting in general doesn’t cover some major regulations), Pathseeker can help by providing necessary audit trails (including evidence of exploitability) and meeting regulatory testing cadence expectations.
  • Centralizes preemptive security programs—With Pathseeker, teams can run their entire preemptive security program in one place, covering the entire software lifecycle: autonomous testing in CI/CD, asset discovery and scanning, and agentic and/or human-led validation.
  • Enterprise-ready from day one—Bugcrowd brings 12+ years of proven enterprise infrastructure—SSO, RBAC, audit logging, compliance reporting, SLA-backed delivery, and dedicated customer success—so security teams get a trusted partner ready to support mission-critical programs from day one, not a vendor still figuring it out.

How does Savant Pathseeker work?

Under the hood, Pathseeker orchestrates multiple specialized AI agents, each handling different parts of the agentic pen-testing process (e.g., reconnaissance, planning, synthesis, reporting). Pathseeker uses publicly available foundational models, which will become even more powerful as more capable models are released. 

To adapt these models for security-specific workflows, we utilize a proprietary layer of specialized skills like API fuzzing developed by Bugcrowd’s in-house practitioners, leveraging their hundreds of years of collective preemptive security experience. When Pathseeker runs a test, these skills kick in automatically, pulling in the right knowledge and tools to guide exactly how each task gets executed. 

Does Savant Pathseeker use researcher data?

Bugcrowd does not use customer or researcher data to train or tune the models powering Savant Pathseeker. The product runs on frontier AI models built on a proprietary layer of skills developed by Bugcrowd’s in-house practitioners. For future iterations, we remain committed to working with our Hacker Advisory Board to find the paths where AI can amplify researchers’ work. More details to come. 

What makes Pathseeker different from other options?

Many agentic testing vendors are solely AI-based, and increasingly rely on commoditized capabilities to deliver results. With Pathseeker, we’re taking a different approach. We recognize that while agentic testing is powerful, it needs human offensive validation (via programs such as pen testing as a service, bug bounty programs, and red teaming) to actually assess true risk. 

By working with Bugcrowd, organizations can access both agentic and human validation through a single platform, rather than managing results across multiple vendors. We also have the expertise to back it up. Through the strategic acquisition of Mayhem—whose founders pioneered autonomous offensive security research—our agentic testing is backed by nearly a decade of genuine offensive AI engineering, combined with Bugcrowd’s 14+ years of experience connecting the world’s top researchers with the world’s largest enterprises.

Another option is to use a frontier model to DIY an agentic pen testing solution. However, there’s more to the solution than just the results—enterprise security teams need operational infrastructure to integrate those results into their workflows, such as managing scope, safety controls, dependencies, and reporting. That’s something organizations get for free when they choose Pathseeker. Additionally, DIY solutions often encounter the same issue as scanners (noisy outputs), creating alert fatigue, and have unpredictable spend with token-based pricing. Bugcrowd has predictable pricing, and our customers can validate machine-generated signals through our community of human hackers and pen testers. 

Sign up for early access

For years, security teams have had to choose between breadth and depth of testing their assets. With Savant Pathseeker, they don’t have to make that trade-off. By pairing agentic testing to achieve broad coverage with human validation to investigate complex vulnerabilities, teams can improve their security posture and finally move towards preemptive security. 

Savant Pathseeker will be available for the general public later this year. If you’re interested in applying, you can request to join our early access program.  

FAQs

  • What is agentic pen testing?
    • Agentic pen testing uses autonomous AI systems to compress or automate different parts of the pen testing lifecycle (e.g., pre-engagement activity, reconnaissance and planning, vulnerability mapping, and exploitation)—completing the process in minutes or hours instead of days. 
  • What are the pros and cons of agentic pen testing?
    • Where a vulnerability scanner tells you something might be wrong, agentic testing confirms whether it’s actually exploitable, at machine speed and a fraction of the cost of manual testing. It complements human testing by examining all assets for common issues, allowing human testers to apply their skills to more complex and high-stakes targets. However, it’s not suited for complex business logic flaws, exploit chaining, or zero-days, and cannot be used by itself to meet compliance requirements (like PCI-DSS).
  • What is the difference between scanners, agentic pen testing, and human pen testing?
    • Scanners, agentic, and human pen testing all help organizations answer different questions about a given vulnerability. Scanners can help flag risk factors (but don’t validate that something is wrong); agentic pen testing can help you determine if there’s an exploitable vulnerability (but not what to do about it); human pen testing can help you make sense of all the data and what to do next. With Bugcrowd, you can leverage Savant Vista with Pathseeker to discover vulnerabilities and then validate further. 
  • What is Savant Pathseeker?
    • Savant Pathseeker is Bugcrowd’s new agentic pentesting offering that operates at machine speed and scale. It operates autonomously to find common vulnerabilities in internet-accessible web applications and APIs along with evidence of exploitability.
  • Does Savant Pathseeker replace human pen testing or pen testing as a service (PTaaS)? 
    • No, human pen testing and agentic pen testing are complementary, not competing. PTaaS is human-led testing delivered as an agile, SaaS-style service, and agentic testing can run on its own or alongside PTaaS. The strongest preemptive security programs use both: agentic pen testing for coverage at scale, and human testing to triangulate data points and go deeper into more complex, high-stakes assets.