Back to vendors
E

Equixly

Visit site
Entry priceContact sales; no public pricing. Request a demo or start a pentest. Also available on cloud cybersecurity marketplaces.Full pricing detail

Equixly is an autonomous offensive security platform whose Agentic AI Hacker, a team of agents on Equixly's own model, continuously pentests APIs and web applications, chaining interactions to prove exploitable risk and rerunning on each release.

Equixly is an Italian offensive security company whose Agentic AI Hacker continuously attacks APIs and applications the way a skilled human adversary would, at machine speed and without a fixed scope or testing window.

A team of AI agents maps the attack surface, chains API interactions across services, manipulates business logic and adapts its strategy as it finds new paths, targeting issues such as broken object level authorization, privilege escalation and cross service exploit chains across REST and GraphQL APIs, single page and server rendered web applications, and LLM applications and MCP servers.

Equixly starts from an open weight model it does not name, specializes it for offensive work, and runs it on its own inference infrastructure, stating that customer traffic, endpoints and results never leave its environment.

Tests can be triggered from deployment pipelines, rerun after each release and pointed at staging, preview or production, and findings arrive with proof of concept evidence and validated exploitability, aligned to OWASP API risks and to PCI DSS and DORA, ISO 27001 and NIS2 controls. Equixly integrates with CI/CD pipelines, vulnerability management systems and Checkmarx One, and states ISO 27001 certification.

The public estate does not document an API, the agents' roles, an approval or scope control, a run history of what the agents sent, or a hosting region. It fits AppSec and API security teams that want continuous, exploit validated testing wired into their release process; a buyer needing documented integrations beyond Checkmarx, oversight controls or a developer surface will need to ask.

Vendor details

Canonical URL

https://equixly.com

Category

Security / SOC agent

Funding status

Equixly raised a Series A of EUR 10M led by 33N Ventures, with Alpha Intelligence Capital, JME Ventures, 360 Capital, and Fondazione Cassa di Risparmio di Firenze. It was founded in 2022 in Italy and holds QC2 certification from Italy's National Cybersecurity Agency (ACN).

Company status

independent

Use cases & customers

Primary use cases

continuous API penetration testingbusiness logic vulnerability testingattack surface mappingremediation validation

Target customers

enterprisesecurity teamsdevelopersAppSec

Deployment options

SaaS

Integrations

Equixly supports CI/CD pipeline triggering and integrates with vulnerability management systems and Checkmarx One, with API definition ingestion. No API, CLI, ticketing or chat integration is documented. It is procurable through the Google, Microsoft and Amazon cybersecurity marketplaces (purchase channels).

In practice

Your team ships API changes several times a day and the annual pentest is long out of date. Equixly runs from the deployment pipeline on each release, chains API calls to find broken authorization, and sends confirmed findings to Jira.

A developer fixing a flagged endpoint wants to know the fix holds. From GitHub Copilot or Claude, they ask Equixly through its MCP server to retest and confirm the fix.

Your security lead doubts that an AI found a real exploit. Attack Trace shows what the agent noticed and tried, beside the confirming request and response.

Agentic Index coverage score

6.0 / 14 capabilities · 43%

Integrations & Tool Calling Full

Native integrations with Jira, GitHub and ServiceNow ITSM push vulnerability details, including severity, affected endpoints and remediation guidance, into the tools engineering and operations teams use. Equixly also integrates with CI/CD pipelines, vulnerability management systems such as Qualys VMDR and application security platforms including Checkmarx One.

SourceEquixly, equixly.com/blog/2026/04/09/april-2026-product-update and /platformread 2026-10-06

Workflow Orchestration Full

"A team of AI agents" maps the attack surface, chains API interactions across services and adapts strategy as it finds new paths, with the orchestration designed around Equixly's model, and Workflows add an automation layer where the customer defines triggers on predefined conditions. The agents' roles and count are not published.

SourceEquixly, equixly.com/platform and /blog/2026/04/09/april-2026-product-update; equixly.com/blog/2026/06/29/equixly-s-proprietary-ai-a-model-that-only-knows-how-to-attackread 2026-10-06

Knowledge Grounding & RAG Partial

Testing is grounded in the customer's API definitions and a mapped attack surface that is retested as endpoints change, and Discovery crawls from a base URL to find reachable endpoints and generate API documentation when no specification exists. No maintained retrieval structure the agents query is documented.

SourceEquixly, equixly.com/platform and /blog/2026/04/09/april-2026-product-updateread 2026-10-06

Human Oversight & Guardrails Partial

Findings go to the customer's teams to prioritize and fix, and results can feed pipeline gates the customer owns, which leaves decisions with people. For AI red teaming the customer describes the target's general behavior, guardrails and system prompt so attacks fit it, but no approval step or scope control before the agents attack is documented.

SourceEquixly, equixly.com/blog/2026/04/20/how-to-build-api-security-into-your-ci-cd-pipeline-a-devsecops-playbook and /blog/2026/08/24/equixly-august-2026-product-update-see-how-the-agent-got-there-and-moreread 2026-10-06

Security, Identity & Governance Partial

The site states "ISO 27001 Certified", and Equixly is reported to hold Italy's ACN QC2 qualification. MCP access is authenticated and scoped to the customer's organization, but no SSO, role model or audit log for the Equixly console is documented, and inference on Equixly's own infrastructure is a data handling statement rather than an access control.

SourceEquixly, equixly.com, /platform and /blog/2026/06/15/equixly-launches-mcp-integration-bringing-continuous-offensive-security-testing-directly-into-developers-ai-coding-assistantsread 2026-10-06

Observability & Auditability Full

Every issue carries a Proof of Exploit with the confirming request and response side by side, and Attack Trace shows how the agent got there, what it noticed, what it tried and what it learned from attempts that did not work, with each step marked as agent reasoning or an algorithmic platform control. HTTP History lets the team filter the requests sent by a time window on the request histogram.

SourceEquixly, equixly.com/blog/2026/08/24/equixly-august-2026-product-update-see-how-the-agent-got-there-and-more and /platformread 2026-10-06

Memory & State Persistence Not documented

No agent memory with a stated scope and lifetime is documented. Equixly's post on its model lists memory among the tools, planning and verification loops orchestrated around it without saying what is kept, and the mapped attack surface is grounding rather than memory.

SourceEquixly, equixly.com/platform and /blog/2026/06/29/equixly-s-proprietary-ai-a-model-that-only-knows-how-to-attackread 2026-10-06

Deployment & Data Residency Not documented

No hosting region, region choice, customer environment or on premises option is named. Equixly runs its model on its own inference infrastructure and says traffic and results "never leave Equixly's environment", a data isolation claim, and its cloud marketplace listings are purchase channels.

SourceEquixly, equixly.com/blog/2026/06/29/equixly-s-proprietary-ai-a-model-that-only-knows-how-to-attack and /platformread 2026-10-06

Prebuilt Agents / Templates / Packs Not documented

No named prebuilt agents, templates or packs are documented; Equixly sells one Agentic AI Hacker, with DAST, Discovery and MCP testing as capabilities of the same platform.

SourceEquixly, equixly.com and /blog/2026/04/09/april-2026-product-updateread 2026-10-06

Triggers & Channel Coverage Full

"Penetration tests can be triggered automatically as part of deployment pipelines", Workflows fire on conditions the customer defines, and Equixly retests APIs after each release and detects newly exposed endpoints, so pipeline and release events start the agents. A developer can also start a test from an AI coding assistant through the MCP server.

SourceEquixly, equixly.com/platform, /blog/2026/04/09/april-2026-product-update and /blog/2026/06/15/equixly-launches-mcp-integration-bringing-continuous-offensive-security-testing-directly-into-developers-ai-coding-assistantsread 2026-10-06

Model Flexibility & Routing Not documented

The customer has no choice of provider. Equixly starts from an unnamed open weight model, specializes it for offense and runs only its own model on its own inference infrastructure.

SourceEquixly, equixly.com/blog/2026/06/29/equixly-s-proprietary-ai-a-model-that-only-knows-how-to-attackread 2026-10-06

APIs / SDKs / MCP Extensibility Partial

Equixly's MCP server at https://mcp.equixly.com, with authentication scoped to the customer's organization, lets GitHub Copilot, Claude and other AI coding tools configure a new service, trigger a continuous penetration test, retrieve findings and confirm that a fix worked. The auth scheme and the tool list are not published, and no API reference, CLI or SDK is documented.

SourceEquixly, equixly.com/blog/2026/06/15/equixly-launches-mcp-integration-bringing-continuous-offensive-security-testing-directly-into-developers-ai-coding-assistants and /blog/2026/08/24/equixly-august-2026-product-update-see-how-the-agent-got-there-and-moreread 2026-10-06

Testing, Debugging & Optimization Not documented

No harness, scored test cases or quality gate for Equixly's agents is offered. Equixly tests the customer's applications and automatically retests remediated vulnerabilities, and its sub one percent false positive figure is a vendor claim.

SourceEquixly, equixly.com/platformread 2026-10-06

Browser / Computer-use Not documented

Equixly attacks at the API and request level across REST, GraphQL and gRPC, single page and server rendered targets, and its DAST engine handles client side JavaScript, forms and the DOM, but no agent operating a browser or desktop is documented.

SourceEquixly, equixly.com/platform and /blog/2026/04/09/april-2026-product-updateread 2026-10-06

The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded

Recent platform changes

2026-08-24·Agent capabilityVerified

Equixly released its August 2026 product update, introducing Attack Trace to show how the agent executes attacks alongside new AI Red Teaming controls. The update also delivers faster penetration testing scans, workspace upgrades, Discovery tags, and bulk actions.

Bears on: Observability / auditability

View source
2026-07-23·IntegrationsVerified

Equixly released its July 2026 product update, introducing a Service Overview dashboard for visualizing the complete API attack surface in a single view. The release also adds a native integration with Qualys VMDR for asset and finding synchronization, alongside Discovery scans that automatically adjust their speed to bypass rate limits.

Bears on: Integrations

View source
View all 2 changes for Equixly →Tracked since Jul 2026 · Verified from public vendor sources

Pricing

Contact sales; no public pricing. Request a demo or start a pentest. Also available on cloud cybersecurity marketplaces.

not disclosed

What is public

No prices are public. Entry is a demo or pentest request, and the platform is listed on the Google, Microsoft and Amazon cybersecurity marketplaces.

Cost watchouts

Inference, not stated by the vendor: scope may expand with the number of APIs and applications and with testing frequency; marketplace procurement terms may differ from direct.

Variable cost rationale

Inference, not stated by the vendor: a continuous testing subscription likely scales with the APIs and applications under test; the pricing axis is not disclosed.

Sales call required

Yes, required for paid access

Free / trial

No public free tier; demo on request

Lowest paid plan

Not public

Key ambiguities

There is no public pricing, and whether billing is per application, per API, or platform tier is not disclosed.

Agentic Index verified 2026-09-28

Alternatives to Equixly

The closest documented capability profiles to Equixly among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.

  • Ocean5.0 / 14Adds documented Prebuilt Agents, Templates & Packs and APIs, SDKs & MCP Extensibility
  • Knostic5.5 / 14Adds documented APIs, SDKs & MCP Extensibility and Testing, Debugging & Optimization
  • Portal265.5 / 14Fuller documented coverage on Integrations & Tool Calling and Knowledge Grounding & RAG
  • Terra Security6.5 / 14Adds documented Prebuilt Agents, Templates & Packs and Testing, Debugging & Optimization
  • Token Security6.5 / 14Adds documented Prebuilt Agents, Templates & Packs and APIs, SDKs & MCP Extensibility
  • AirMDR6.0 / 14Adds documented Prebuilt Agents, Templates & Packs

Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.