Back to vendors
X

XBOW

Also known as: XBOW, xbow.com, XBOW Pentest On-Demand, XBOW autonomous pentester

Visit site
Security / SOC agentindependentVerified 2026-07-22

Autonomous offensive-security platform: a coordinator directs thousands of parallel agents that chain vulnerabilities into reproducible, exploit-validated attack paths at machine speed, continuously as apps change, with scope control and SOC 2 / ISO 27001 / PCI DSS / NIS 2 governance. First AI to hit #1 on HackerOne; founded by GitHub Copilot's creator; from $6,000 on-demand.

XBOW is the autonomous offensive-security company, applying AI reasoning and adversarial workflows modeled on real-world attack techniques to find and validate vulnerabilities at machine speed. It became the first AI to reach the top spot on HackerOne's US bug bounty leaderboard, ranking above every human researcher, and has surfaced more than 200 zero-days with a near-zero false-positive rate, including a 9.8 critical Microsoft flaw it found entirely on its own. Architecturally, a coordinator decides what to test, where, and in what order, then directs a fleet of thousands of agents that attack in parallel, reasoning through and chaining vulnerabilities with an extensive offensive toolkit to reach non-obvious paths that scanners and point-in-time pentests miss. The system runs the entire pentest autonomously, from the context you give it to a confirmed, working exploit, continuously re-testing every time applications change, so risk is measured every day rather than estimated once a year. Autonomy is paired with governance: customers define scope, every action is logged and auditable, and deployment aligns with data separation, residency, and compliance requirements (SOC 2, ISO 27001, PCI DSS, NIS 2), with XBOW Guardrails enforcing the boundaries enterprise security requires. Products include the continuous platform and XBOW Pentest On-Demand (from $6,000). Founded by GitHub Copilot and CodeQL creator Oege de Moor and backed by a $120M raise, XBOW anchors the offensive/pentest cluster of the security lane, distinct from the defensive AI SOC analyst tier.

Vendor details

Canonical URL

https://xbow.com

Category

Security / SOC agent

Funding status

$120M raise announced March 2026 (DFJ Growth, Northzone; following a prior $75M Series B) to scale the platform; founded and led by Oege de Moor, creator of GitHub Copilot, Semmle, and CodeQL; 150+ security teams including Fortune 500 and global enterprises; named to the 2026 Cyber 150

Company status

independent

Use cases & customers

Primary use cases

autonomous penetration testing at machine speedcontinuous exploit validation across the attack surfacepre-production and CI security testingzero-day and deep-exploit discoveryboard- and auditor-ready security assurance

Target customers

enterprise security and offensive-security teamsFortune 500 and global enterprisesapplication security and product security teamscompanies needing continuous compliance-grade pentesting

Deployment options

cloud platform with deployment aligned to customer data separation, residency, and compliance requirementsXBOW Pentest On-Demand engagements

Integrations

Point XBOW at a target URL and hand it whatever context exists (docs, credentials, API specs, architecture notes); it builds a live map of the attack surface (applications, endpoints, parameters, auth flows), reasons through and chains an extensive offensive toolkit, and integrates into pre-production and CI workflows to test continuously as applications change; findings come as reproducible, exploit-validated proof with board- and auditor-ready reporting.

Capability coverage

8.0 / 14 capabilities · 57%

Integrations & Tool CallingAgents reason through and chain an extensive offensive toolkit, ingest target context (docs, credentials, API specs, architecture), and integrate into pre-production and CI workflows, a broad tool-calling and integration surface, XBOW platform and blog 2026-07-22 Full
Workflow OrchestrationA coordinator decides what to test, where, and in what order and directs a fleet of thousands of agents attacking in parallel, running the entire pentest autonomously end to end and chaining vulnerabilities into working attack paths, XBOW platform page 2026-07-22 Full
Knowledge Grounding & RAGGrounds each test in the context the customer provides (docs, credentials, API specs, architecture, and white-box source), going deeper the more context it is given, short of a documented knowledge base or retrieval product, XBOW platform and blog 2026-07-22 Partial
Human Oversight & GuardrailsExecution is fully autonomous with no human supervision required, but customers define scope and XBOW Guardrails plus full auditability keep it bounded, a scope-and-guardrail oversight model rather than step-level approval, XBOW site 2026-07-22 Partial
Security, Identity & GovernanceCustomers define scope, every action is logged and auditable, and deployment aligns with data separation, residency, and compliance requirements across SOC 2, ISO 27001, PCI DSS, and NIS 2, with XBOW Guardrails governing autonomy, XBOW site 2026-07-22 Full
Observability & AuditabilityEvery action is logged and auditable, findings are reproducible exploit-validated proof with board- and auditor-ready reporting, and risk is measured every day, giving first-class observability and auditability, XBOW site 2026-07-22 Full
Memory & State PersistenceBuilds and maintains a live map of the attack surface (applications, endpoints, parameters, auth flows) that persists and updates as applications change, a durable state model short of a documented agent memory layer, XBOW platform page 2026-07-22 Partial
Deployment & Data ResidencyDeployment aligns with the customer's data separation, residency, and compliance requirements, an explicit and deployment-control posture, XBOW site 2026-07-22 Full
Prebuilt Agents, Templates & PacksShips as a finished, out-of-box autonomous pentester plus a productized Pentest On-Demand offering that needs no scoping setup, a productized starting point short of a customer-facing template or agent library, XBOW site and Business Wire 2026-07-22 Partial
Triggers & Channel CoverageRuns continuously and re-tests every time applications change, plus on-demand engagements and point-at-a-URL starts, covering continuous, change-triggered, and on-demand modes on a single app and API testing surface, XBOW site 2026-07-22 Partial
Model Flexibility & RoutingNo customer facing model choice or routing documented; the AI reasoning stack is internal, XBOW materials 2026-07-22 Unable to verify
APIs, SDKs & MCP ExtensibilityIntegrates into pre-production and CI workflows and ingests API specs, implying an integration and API surface, short of a documented public SDK or MCP for customer extension, XBOW blog 2026-07-22 Partial
Testing, Debugging & OptimizationXBOW is itself the testing product and validates its own exploits, but exposes no customer-facing tooling to test, debug, or optimize a configurable agent, XBOW materials 2026-07-22 Unable to verify
Browser & Computer UseExplores applications and APIs like an attacker through an offensive toolkit and HTTP-level interaction rather than documented browser or GUI computer use, XBOW platform page 2026-07-22 Unable to verify

Pricing

XBOW Pentest On-Demand from $6,000 per engagement; continuous platform quoted by sales

per engagement (on-demand) + enterprise platform contract

Public — partialMedium variable cost

What is public

XBOW publishes an exact starting price for Pentest On-Demand ($6,000 per engagement); the continuous enterprise platform is quoted by sales.

Variable cost rationale

On-Demand is priced per engagement from $6,000, so cost scales with the number of engagements; continuous-platform economics are quoted by sales.

Sales call required

Yes — required for paid access

Free / trial

Not published

Verified 2026-07-22

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.