Assail
Also known as: Assail Ares, Assail Sidewinder
Autonomous red teaming platform (Ares) whose twelve Sidewinder agents discover, chain and exploit vulnerabilities across APIs, web and mobile apps, driving a real browser and running on Assail's own offensive security models, managed in the major clouds or on premises.
Assail builds Ares, an agentic offensive AI platform for continuous penetration testing of the application layer: APIs, mobile apps and web applications. Rather than scanning for known signatures, Ares deploys coordinated AI agents that plan engagements, chain multi step attacks and prove impact through exploitation, and every finding ships with the request sent, the response received and a replayable record running from the agent's reasoning transcript to the live network trace.
Ares runs on Assail's own models rather than a wrapped frontier model: Dagger, a 14 billion parameter offensive security model, and then, with Sidewinder in July 2026, a fine tuned 31 billion parameter model.
Sidewinder puts twelve specialized agents against a living knowledge graph of the target's attack surface, drives a real browser with vision grounded analysis through single page apps and multiple authenticated identities, and reviews its own operations for false positives, missed steps and misclassified findings, rewriting its skills and running repair cycles; a co evolutionary loop called Javelin pits attacking and defending agents against each other. Assail presented the rebuilt stack as Ares v2 at Black Hat 2026.
Customers run Ares as a managed deployment on AWS, Azure or Google Cloud, or fully on premises through a Campaign Agent for sovereign and air gapped environments, and an Ares Docker Agent inside the network reaches internal services over outbound connections within approved ranges.
Assail was founded by Alissa Knight, a long time offensive security practitioner, is backed by Venture Guides after a pre seed led by Squared Circle Ventures, and announced a five year, 4.125 million dollar contract with Qanapi in August 2026. Ares became generally available in February 2026.
No public API, attestation or role model is documented, and the agents' approval model is described only as safe by design with progressive autonomy.
It fits security teams that want continuous, exploit proven testing of their application layer, including in air gapped environments; a team that needs to integrate findings into its own tooling through an API or wants to choose the underlying model will find neither documented.
Vendor details
Canonical URL
https://www.assailai.com
Category
Security / SOC agent
Subcategory
Autonomous offensive security testing
Funding status
Pre seed of two hundred fifty thousand dollars led by Squared Circle Ventures (January 2026); backed by Venture Guides per March 2026 announcement; NVIDIA Inception member
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Ares tests customer APIs, web applications and mobile apps directly, driving a real browser with multiple authenticated identities, and reaches internal services through the Ares Docker Agent (GitHub and Docker Hub, proprietary license, Ares subscription required), which connects outbound to the Ares control plane and enforces approved network ranges. Managed deployments run on AWS, Azure and Google Cloud, with an on premises Campaign Agent for sovereign and air gapped environments. No ticketing, chat or CI/CD connectors and no public API are documented.
In practice
A security team replaces point in time pentests with always on engagements, and Ares maps shadow endpoints then exploits broken authorization with proof of impact
After a fix ships, the team reruns the attack chain to validate remediation in minutes instead of waiting weeks for a retest
An analyst chats with Ares agents about how they would breach the environment and which findings are actually exploitable, prioritizing remediation accordingly
Sources & related URLs
Research sources
Agentic Index coverage score
8.0 / 14 capabilities · 57%
| Integrations & Tool Calling | Partial |
|---|---|
|
Ares acts on the applications under test, operating several authenticated identities through a real browser and reaching internal services through the Ares Docker Agent's tunnel, but no connector to ticketing, chat, CI/CD or other outside systems is documented. Sourceprnewswire.com/news-releases/assail-launches-sidewinder-purpose-built-and-fine-tuned-exploitation-platform-capable-of-recursive-self-healing-302819438.htmlread 2026-09-28 |
|
| Workflow Orchestration | Full |
|
"A fleet of twelve specialized, autonomous agents reasons against a living attack-surface knowledge graph" and rewrites the plan as evidence arrives, with a mission planning agent directing the others. Sourceprnewswire.com/news-releases/assail-launches-sidewinder-purpose-built-and-fine-tuned-exploitation-platform-capable-of-recursive-self-healing-302819438.htmlread 2026-09-28 |
|
| Knowledge Grounding & RAG | Full |
|
The agents reason against "a living attack-surface knowledge graph" that "remembers every probe, observation, and proven finding", a maintained retrieval structure over the customer's own targets. Sourceprnewswire.com/news-releases/assail-launches-sidewinder-purpose-built-and-fine-tuned-exploitation-platform-capable-of-recursive-self-healing-302819438.htmlread 2026-09-28 |
|
| Human Oversight & Guardrails | Partial |
|
The Docker agent enforces customer approved network ranges twice and logs every refusal. The January release names "safe-by-design" live fire and "progressive autonomy" without describing them, and no approval step before an exploit runs is documented. Sourceassailai.com/press-releases/pr-20260113read 2026-09-28 |
|
| Security, Identity & Governance | Not documented |
|
No attestation, SSO, role model or trust page is published, and the product at ares.assailai.com sits behind registration. Sourceassailai.comread 2026-09-28 |
|
| Observability & Auditability | Full |
|
Every finding ships "with a complete, replayable record of how it was found, from the agent's reasoning transcript to the live network trace", and every finding carries the request sent, the response and how it was exploited, the agent's own run trace. Sourceprnewswire.com/news-releases/assail-launches-sidewinder-purpose-built-and-fine-tuned-exploitation-platform-capable-of-recursive-self-healing-302819438.htmlread 2026-09-28 |
|
| Memory & State Persistence | Not documented |
|
Beyond the attack surface knowledge graph that remembers probes and findings, and the skill rewriting that follows self review, no agent memory with a stated scope and lifetime is documented. Sourceprnewswire.com/news-releases/assail-launches-sidewinder-purpose-built-and-fine-tuned-exploitation-platform-capable-of-recursive-self-healing-302819438.htmlread 2026-09-28 |
|
| Deployment & Data Residency | Full |
|
Customers "can run Ares... as a managed deployment on AWS, Azure, or Google Cloud, or fully on-premises through our new Campaign Agent" for sovereign and air gapped environments, and the Ares Docker Agent runs inside the customer network with outbound only connections, named customer environment options. Sourceprnewswire.com/news-releases/assail-launches-sidewinder-purpose-built-and-fine-tuned-exploitation-platform-capable-of-recursive-self-healing-302819438.htmlread 2026-09-28 |
|
| Prebuilt Agents, Templates & Packs | Partial |
|
Sidewinder runs "twelve specialized, autonomous agents" and the homepage names agents specialized for APIs, mobile and web, but the individual agents and their jobs are not named. Sourceprnewswire.com/news-releases/assail-launches-sidewinder-purpose-built-and-fine-tuned-exploitation-platform-capable-of-recursive-self-healing-302819438.htmlread 2026-09-28 |
|
| Triggers & Channel Coverage | Partial |
|
Ares is described as continuously hunting the customer's API, web and mobile estate, but no event, schedule, webhook or CI/CD hook that starts an engagement is published. Sourceassailai.comread 2026-09-28 |
|
| Model Flexibility & Routing | Not documented |
|
Ares runs on Assail's own models, the 14 billion parameter Dagger and then a fine tuned 31 billion parameter model for Sidewinder, and customers cannot choose another provider. Sourceprnewswire.com/news-releases/assail-launches-sidewinder-purpose-built-and-fine-tuned-exploitation-platform-capable-of-recursive-self-healing-302819438.htmlread 2026-09-28 |
|
| APIs, SDKs & MCP Extensibility | Not documented |
|
No public API, SDK or MCP server is documented. The Ares Docker Agent is a deployment component configured by environment variables and a dashboard token, now under a proprietary license tied to an Ares subscription, not a surface for building on the platform. Sourcegithub.com/assailai/ares-agentread 2026-09-28 |
|
| Testing, Debugging & Optimization | Full |
|
Sidewinder "autonomously reviews its operations to find false positives, missed steps, or misclassified findings, instantly rewriting its own skills" and runs repair cycles, an optimization loop on the agent itself, and every finding is independently verified and deduplicated before it ships, a quality gate; the Javelin loop pits attacking and defending agents against each other. No customer facing harness or scored test set is documented. Sourceprnewswire.com/news-releases/assail-launches-sidewinder-purpose-built-and-fine-tuned-exploitation-platform-capable-of-recursive-self-healing-302819438.htmlread 2026-09-28 |
|
| Browser & Computer Use | Full |
|
Sidewinder drives "a real browser with vision-grounded analysis to crawl single-page apps, defeat simple challenges, and operate multiple authenticated identities at once", an agent operating a browser. Sourceprnewswire.com/news-releases/assail-launches-sidewinder-purpose-built-and-fine-tuned-exploitation-platform-capable-of-recursive-self-healing-302819438.htmlread 2026-09-28 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Recent platform changes
Assail released Sidewinder, a complete version 2 redesign of its Ares offensive security platform powered by a new 31 billion-parameter model. The platform shifts to a plan-driven architecture featuring 12 specialized autonomous agents that operate against a persistent knowledge graph. It also introduces vision-grounded analysis to drive real browsers for crawling single-page applications.
Bears on: Agent capability
View sourcePricing
Contact sales
What is public
Product capabilities and deployment options are public; the Ares Docker Agent is published on GitHub and Docker Hub under a proprietary license tied to an Ares subscription; commercial terms are not public.
Billing mechanics
Not publicly documented; enterprise sales with registration gating.
Cost watchouts
Inference, not stated by the vendor: likely priced by applications or targets under continuous testing, and managed cloud versus on premises Campaign Agent deployments may price differently.
Variable cost rationale
Inference, not stated by the vendor: continuous autonomous pentesting typically scales by applications, targets or engagements under test; no metering is published.
Additional watchouts
Early stage with a fast release cadence (Ares GA Feb 2026, Sidewinder July 2026); packaging likely to change.
Sales call required
Yes, required for paid access
Free / trial
No free tier; the Ares Docker Agent is proprietary and requires an active Ares subscription
Key ambiguities
Commercial model and pricing axis are unpublished; company is early stage.
Missing data
All pricing figures, billing axis, trial terms.
Related vendors
- 7AI — Agentic SOC from the Cybereason founders: domain specialized agents…
- Abnormal AI — Behavioral AI email security with three named autonomous agents: a…
- AirMDR — AI-native MDR whose AI analyst investigates every alert and writes…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Human-AI SOC platform where customers build their own agents and…
- Anvilogic — Agentic security operations platform that works on top of existing…
Alternatives to Assail
The closest documented capability profiles to Assail among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Vulnetic5.5 / 14A lighter documented profile than Assail
- Pillar Security7.5 / 14Adds documented Security, Identity & Governance
- Straiker8.5 / 14Adds documented Security, Identity & Governance and APIs, SDKs & MCP Extensibility
- Terra Security6.5 / 14Adds documented Security, Identity & GovernanceAssail vs Terra Security →
- Noma Security7.0 / 14Adds documented Security, Identity & Governance
- Simbian9.0 / 14Adds documented Memory & State Persistence
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded