Novee
An AI agent that behaves like a real hacker against your own applications — chaining exploits together automatically, proving they work, and telling your team exactly what to fix, continuously instead of once a year.
🔗 Visit NoveeDescription
Traditional penetration testing happens once or twice a year, produces a PDF report, and is stale the moment the next code deploy ships — leaving most of the year uncovered. Novee runs the same kind of adversarial testing an experienced human pentester would, but continuously and automatically: it probes your web apps, mobile apps, APIs and AI systems, chains vulnerabilities together the way a real attacker would to prove actual exploitability (not just theoretical findings), and retests automatically as your infrastructure changes.
Novee offers black-box and gray-box testing with no source code access required, multi-agent validation to filter out false positives and confirm real exploitability with working proof-of-concept scripts, architecture-specific code-level remediation guidance and automatic WAF rule generation, and native integrations with Jira, GitHub and ServiceNow. It specifically targets the newer class of AI-application risks — prompt injection, jailbreaks, data exfiltration from LLM-powered features — alongside standard web/API vulnerabilities. Founded in 2025 by three Israeli cybersecurity veterans from Unit 8200 and Talpiot with 20+ years of nation-state offensive security experience, it has raised $51.5M within four months of launch, claims 2x the vulnerability detection and precision of leading open-source alternatives at 60% lower cost, and lists enterprise customers including UiPath, Sentra, hiBob and Cresta, with SOC 2, ISO 27001, ISO 42001, HIPAA and GDPR coverage.
💬 Our review
The short version: Novee's continuous, exploit-chaining approach is a genuine step up from annual pentest reports, and its focus on AI-application-specific attacks (prompt injection, jailbreaks) addresses a real gap that most legacy pentest vendors haven't caught up to yet.
Against traditional pentest firms (which deliver a point-in-time report) and generic vulnerability scanners (which flag issues without proving exploitability), Novee's multi-agent validation step — actually chaining and executing exploits to produce a working proof-of-concept — is the meaningful differentiator, since a false-positive-heavy report is often more work to triage than it's worth. The founding team's offensive-security pedigree (Unit 8200, Talpiot) and the rapid $51.5M raise are credible signals for an enterprise security buyer doing vendor diligence, and the compliance certification list (SOC 2, ISO 27001/42001, HIPAA, GDPR) matters for regulated industries evaluating a third party with this level of access to their systems. Pricing being entirely gated behind a sales demo is standard for enterprise security tooling but means there's no way to self-serve evaluate cost before a sales conversation. Strong fit for enterprise security teams that want continuous, exploit-proven pentesting including AI-specific attack surfaces; overkill and likely cost-prohibitive for a small team that just needs periodic vulnerability scanning.
💰 Pricing
📊 Global score
🤖 AI-enriched data
Non publié, nécessite une démo commerciale. Déploiement SaaS, Bastion Node ou on-premises.
Pros
Pentest continu plutôt qu'un rapport ponctuel annuel
Chaîne les exploits pour prouver l'exploitabilité réelle, pas juste des alertes théoriques
Couvre spécifiquement les risques IA (injection de prompt, jailbreak, exfiltration)
Équipe fondatrice à forte pedigree sécurité offensive (Unit 8200, Talpiot), $51.5M levés
Cons
Tarification totalement opaque, démo commerciale obligatoire
Produit très récent (fondé 2025), peu de recul en production
Probablement hors budget pour une petite équipe
Marché du pentest automatisé déjà concurrentiel (Tenzai, autres)