By stage — Enterprise

Point AI pentest agents at your whole estate.
Keep every control you already have.

Autonomous agents map every domain you own and prove what is exploitable, inside the scope, rate limits and permissions your team sets. Findings go to your engineers' coding agent over MCP with the exploit as the specification, and replay re-runs it to confirm the fix held.

  • Scope, limits and permissions you set
  • Findings in your engineers' own tools
  • Every agent action on the record
The whole surface

Every domain you own, and how it hangs together. Findings hang off the nodes.

An inventory tells you how many hosts you have. A graph tells you what happens when one of them falls: which hosts share an origin, which names point at providers that no longer claim them, and where a finding sits relative to everything around it.

Attack surface map

Your company, from the outside
AWS eu-west-1168 assets
Vercel96 assets
Cloudflare41 assets
Auth06 assets
Stripe9 assets
Datadog14 assets
Sentry4 assets
Heroku35 assets
Customer API42 assets
2api.acme.com
4api-eu.acme.com
gw.acme.com
events.acme.com
webhooks.acme.com
sandbox.acme.com
docs-api.acme.com
status.acme.com
Acquired estate26 assets
3sso.oldco.net
1vpn.oldco.net
2jira.oldco.net
wiki.oldco.net
mail.oldco.net
ftp.oldco.net
git.oldco.net
old-cdn.oldco.net
1
Payments18 assets
9
Internal tooling51 assets
3
Web application87 assets
Edge and DNS41 assets
1
Identity tenant6 assets
Billing9 assets
2
Observability14 assets
1
Error tracking4 assets
2
Legacy DNS9 assets
Critical findingsHigh findingsObserved relationshipReachable, not provenProven crossing
Integrate everything from your surface
  • AWS
  • Google Cloud
  • Azure
  • Cloudflare
  • GitHub
  • GitLab
  • Bitbucket
Guardrails

Autonomous does not mean uncontrolled. You set the boundary, the runtime holds it.

Define exactly which hosts agents may reach, what they are allowed to do when they get there, and how hard they are allowed to push. The runtime enforces it and records every denial.

Agent guardrails

Target scope
In scope
  • api.acme.com
  • app.acme.com
  • staging.acme.com
Never dispatched
  • legacy.acme.com
  • 10.0.0.0/8 (internal)
Agent permissions
Limits and hours
  • Rate limit

    5 requests per second, per host

  • Concurrency

    3 agents working in parallel

  • Quiet hours

    No traffic between 09:00 and 18:00

Granted agents may send POST, PUT and PATCH against this target. Every request it makes is written to the audit log.

Platform security

What your security review asks for. All of it, before anything touches production.

  • SAML and SSO with Okta, Azure AD and Google Workspace
  • Role-based access control across your organisation
  • Your data is never used to train models
  • Findings delivered to Slack, email, or a signed webhook your SIEM can consume
  • Fixes go out through your own tooling and review process, then are verified by re-running the exploit
  • Attended sign-in for applications behind SSO that nothing else can test
  • Full audit log of every action your team takes, filterable by actor and object

Identity and access

SSO enforced
Identity providers
  • OktaConnected
    SAML 2.0
  • Azure ADAvailable
    SAML 2.0
  • Google WorkspaceAvailable
    SAML 2.0
Roles and permissions
  • OwnerFull access2
  • AdminScope and policy6
  • MemberRun and review24
  • Read-onlyFindings and reports8
The loop

Find it. Prove it. Fix it. Verify the fix. One system, one record.

A report tells you what was wrong in the week it was written. It cannot tell you whether the fix worked. Replay can.

1Prove
superhack.io / finding
proven
CRITICAL
$ curl -b "session=$B" /api/records/8124
HTTP/2 200
{ "id": 8124, "owner": "tenant-a" }
4 steps · captured verbatim

The finding is the transcript

Nothing is recorded without the requests and identities that proved it.

2Fix
Claude Code
Cursor
Windsurf
Copilot
Codex
Zed
Any client

It reaches your engineers over MCP

The exploit chain is the specification, so the patch is written against evidence rather than a description.

3Verify
superhack.io / replay
verdict
Exploitablebefore
Solvedafter retest
Exploit no longer reproduces

Replay settles it

The original exploit runs again against the changed system and returns a dated verdict.

Scale

Built for an estate this size. And the record to match.

  • Every registrable domain you own, discovered and grouped
  • Agents work an organisation of any size, from one domain to an estate of thousands
  • Any infrastructure provider you run on, supported through integrations with AWS, GCP, Azure, Cloudflare and more
  • An end-to-end workflow for fixing what we find, embedded in the processes your team already runs
  • An attack-surface graph showing what is adjacent to what, with the evidence behind every edge
  • Targeted re-scans and depth modes for re-validation
The record

Every action your team takes, on the record. Filterable, and there before anyone asks for it.

Who tightened a policy, who took a host out of scope, who accepted a risk, who exported evidence and who changed somebody's role. Not a login history with everything interesting missing from it.

Audit trail

Every action taken in Superhack
EventActorActionObjectWhen
PolicyJ. ChenTurned destructive requests offapi.acme.com2m ago
ScopeJ. ChenMarked the host out of scopelegacy.acme.com18m ago
ScanA. NovakStarted a targeted re-scan of 12 hostsCustomer API41m ago
TriageS. PatelAccepted the risk on a findingSH-44711h ago
ExportM. TorresDownloaded the evidence bundleSH-41883h ago
MembersR. KimChanged a member's role to read-onlyj.doe@acme.com5h ago
SettingsR. KimEnforced SSO for the workspaceacme.com1d ago
IntegrationJ. ChenConnected Okta over SAMLOkta2d ago
Deploy across your estate

Every domain you own,
under agents you control.

Point agents at your surface with the scope, limits and permissions your team sets, and find out what is reachable before somebody else does.

Scope
Enforced
The fix
Yours
Every action
Logged
Coverage
Continuous