Novee

Novee

An AI agent that behaves like a real hacker against your own applications — chaining exploits together automatically, proving they work, and telling your team exactly what to fix, continuously instead of once a year.

🔗 Visit Novee
📁 Security & Privacy🗣️ English

Description

Traditional penetration testing happens once or twice a year, produces a PDF report, and is stale the moment the next code deploy ships — leaving most of the year uncovered. Novee runs the same kind of adversarial testing an experienced human pentester would, but continuously and automatically: it probes your web apps, mobile apps, APIs and AI systems, chains vulnerabilities together the way a real attacker would to prove actual exploitability (not just theoretical findings), and retests automatically as your infrastructure changes.

Novee offers black-box and gray-box testing with no source code access required, multi-agent validation to filter out false positives and confirm real exploitability with working proof-of-concept scripts, architecture-specific code-level remediation guidance and automatic WAF rule generation, and native integrations with Jira, GitHub and ServiceNow. It specifically targets the newer class of AI-application risks — prompt injection, jailbreaks, data exfiltration from LLM-powered features — alongside standard web/API vulnerabilities. Founded in 2025 by three Israeli cybersecurity veterans from Unit 8200 and Talpiot with 20+ years of nation-state offensive security experience, it has raised $51.5M within four months of launch, claims 2x the vulnerability detection and precision of leading open-source alternatives at 60% lower cost, and lists enterprise customers including UiPath, Sentra, hiBob and Cresta, with SOC 2, ISO 27001, ISO 42001, HIPAA and GDPR coverage.

💬 Our review

The short version: Novee's continuous, exploit-chaining approach is a genuine step up from annual pentest reports, and its focus on AI-application-specific attacks (prompt injection, jailbreaks) addresses a real gap that most legacy pentest vendors haven't caught up to yet.

Against traditional pentest firms (which deliver a point-in-time report) and generic vulnerability scanners (which flag issues without proving exploitability), Novee's multi-agent validation step — actually chaining and executing exploits to produce a working proof-of-concept — is the meaningful differentiator, since a false-positive-heavy report is often more work to triage than it's worth. The founding team's offensive-security pedigree (Unit 8200, Talpiot) and the rapid $51.5M raise are credible signals for an enterprise security buyer doing vendor diligence, and the compliance certification list (SOC 2, ISO 27001/42001, HIPAA, GDPR) matters for regulated industries evaluating a third party with this level of access to their systems. Pricing being entirely gated behind a sales demo is standard for enterprise security tooling but means there's no way to self-serve evaluate cost before a sales conversation. Strong fit for enterprise security teams that want continuous, exploit-proven pentesting including AI-specific attack surfaces; overkill and likely cost-prohibitive for a small team that just needs periodic vulnerability scanning.

💰 Pricing

Sur devisTarification non publique, nécessite une démo commerciale.
Enterprise Sur devis

📊 Global score

53Average
🌐Availability15/100Faible

1 language · 0 platform

📄Profile90/100Excellent

Profile completeness

🤖 AI-enriched data

💰 Pricing model
💳 Sur devis

Non publié, nécessite une démo commerciale. Déploiement SaaS, Bastion Node ou on-premises.

👥 Target audienceÉquipes sécurité d'entreprise qui veulent un pentest continu et prouvé (pas juste des rapports annuels), y compris sur les risques spécifiques aux applications IA
🗣️ Languagesen
🌍 Target countriesWorldwide
👍

Pros

Pentest continu plutôt qu'un rapport ponctuel annuel

Chaîne les exploits pour prouver l'exploitabilité réelle, pas juste des alertes théoriques

Couvre spécifiquement les risques IA (injection de prompt, jailbreak, exfiltration)

Équipe fondatrice à forte pedigree sécurité offensive (Unit 8200, Talpiot), $51.5M levés

👎

Cons

Tarification totalement opaque, démo commerciale obligatoire

Produit très récent (fondé 2025), peu de recul en production

Probablement hors budget pour une petite équipe

Marché du pentest automatisé déjà concurrentiel (Tenzai, autres)

❓ Frequently asked questions

What is Novee in one sentence?
How much does it cost?
Does it test AI applications specifically?
How is this different from a scanner that just flags issues?
What compliance certifications does it have?
Is it worth the money compared to alternatives?
Which tool should you pick for your case?