Back to vendors
X

XBOW

Also known as: XBOW, xbow.com, XBOW Pentest On-Demand, XBOW autonomous pentester

Visit site
Entry priceXBOW Pentest On-Demand from $6,000 per engagement; continuous platform quoted by salesFull pricing detail

Autonomous offensive-security platform: a coordinator directs thousands of parallel agents that chain vulnerabilities into reproducible, exploit-validated attack paths at machine speed, continuously as apps change, with scope control and SOC 2 / ISO 27001 / PCI DSS / NIS 2 governance. First AI to hit #1 on HackerOne; founded by GitHub Copilot's creator; from $6,000 on-demand.

XBOW is the autonomous offensive-security company, applying AI reasoning and adversarial workflows modeled on real-world attack techniques to find and validate vulnerabilities at machine speed. It became the first AI to reach the top spot on HackerOne's US bug bounty leaderboard, ranking above every human researcher, and has surfaced more than 200 zero-days with a near-zero false-positive rate, including a 9.8 critical Microsoft flaw it found entirely on its own.

Architecturally, a coordinator decides what to test, where, and in what order, then directs a fleet of thousands of agents that attack in parallel, reasoning through and chaining vulnerabilities with an extensive offensive toolkit to reach non-obvious paths that scanners and point-in-time pentests miss. The system runs the entire pentest autonomously, from the context you give it to a confirmed, working exploit, continuously re-testing every time applications change, so risk is measured every day rather than estimated once a year.

Autonomy is paired with governance: customers define scope, every action is logged and auditable, and deployment aligns with data separation, residency, and compliance requirements (SOC 2, ISO 27001, PCI DSS, NIS 2), with XBOW Guardrails enforcing the boundaries enterprise security requires. Products include the continuous platform and XBOW Pentest On-Demand (from $6,000). Founded by GitHub Copilot and CodeQL creator Oege de Moor and backed by a $120M raise, XBOW anchors the offensive/pentest cluster of the security lane, distinct from the defensive AI SOC analyst tier.

Vendor details

Canonical URL

https://xbow.com

Category

Security / SOC agent

Funding status

$120M raise announced March 2026 (DFJ Growth, Northzone; following a prior $75M Series B) to scale the platform; founded and led by Oege de Moor, creator of GitHub Copilot, Semmle, and CodeQL; 150+ security teams including Fortune 500 and global enterprises; named to the 2026 Cyber 150

Company status

independent

Use cases & customers

Primary use cases

autonomous penetration testing at machine speedcontinuous exploit validation across the attack surfacepre-production and CI security testingzero-day and deep-exploit discoveryboard- and auditor-ready security assurance

Target customers

enterprise security and offensive-security teamsFortune 500 and global enterprisesapplication security and product security teamscompanies needing continuous compliance-grade pentesting

Deployment options

cloud platform with deployment aligned to customer data separation, residency, and compliance requirementsXBOW Pentest On-Demand engagements

Integrations

Point XBOW at a target URL and hand it whatever context exists (docs, credentials, API specs, architecture notes); it builds a live map of the attack surface (applications, endpoints, parameters, auth flows), reasons through and chains an extensive offensive toolkit, and integrates into pre-production and CI workflows to test continuously as applications change; findings come as reproducible, exploit-validated proof with board- and auditor-ready reporting.

Agentic Index coverage score

8.0 / 14 capabilities · 57%

Integrations & Tool Calling Full

Agents reason through and chain an extensive offensive toolkit, ingest target context (docs, credentials, API specs, architecture), and integrate into pre-production and CI workflows, a broad tool-calling and integration surface, XBOW platform and blog 2026-07-22

Workflow Orchestration Full

A coordinator decides what to test, where, and in what order and directs a fleet of thousands of agents attacking in parallel, running the entire pentest autonomously end to end and chaining vulnerabilities into working attack paths, XBOW platform page 2026-07-22

Knowledge Grounding & RAG Partial

Grounds each test in the context the customer provides (docs, credentials, API specs, architecture, and white-box source), going deeper the more context it is given, short of a documented knowledge base or retrieval product, XBOW platform and blog 2026-07-22

Human Oversight & Guardrails Partial

Execution is fully autonomous with no human supervision required, but customers define scope and XBOW Guardrails plus full auditability keep it bounded, a scope-and-guardrail oversight model rather than step-level approval, XBOW site 2026-07-22

Security, Identity & Governance Full

Customers define scope, every action is logged and auditable, and deployment aligns with data separation, residency, and compliance requirements across SOC 2, ISO 27001, PCI DSS, and NIS 2, with XBOW Guardrails governing autonomy, XBOW site 2026-07-22

Observability & Auditability Full

Every action is logged and auditable, findings are reproducible exploit-validated proof with board- and auditor-ready reporting, and risk is measured every day, giving first-class observability and auditability, XBOW site 2026-07-22

Memory & State Persistence Partial

Builds and maintains a live map of the attack surface (applications, endpoints, parameters, auth flows) that persists and updates as applications change, a durable state model short of a documented agent memory layer, XBOW platform page 2026-07-22

Deployment & Data Residency Full

Deployment aligns with the customer's data separation, residency, and compliance requirements, an explicit and deployment-control posture, XBOW site 2026-07-22

Prebuilt Agents, Templates & Packs Partial

Ships as a finished, out-of-box autonomous pentester plus a productized Pentest On-Demand offering that needs no scoping setup, a productized starting point short of a customer-facing template or agent library, XBOW site and Business Wire 2026-07-22

Triggers & Channel Coverage Partial

Runs continuously and re-tests every time applications change, plus on-demand engagements and point-at-a-URL starts, covering continuous, change-triggered, and on-demand modes on a single app and API testing surface, XBOW site 2026-07-22

Model Flexibility & Routing Unable to verify

No customer facing model choice or routing documented; the AI reasoning stack is internal, XBOW materials 2026-07-22

APIs, SDKs & MCP Extensibility Partial

Integrates into pre-production and CI workflows and ingests API specs, implying an integration and API surface, short of a documented public SDK or MCP for customer extension, XBOW blog 2026-07-22

Testing, Debugging & Optimization Unable to verify

XBOW is itself the testing product and validates its own exploits, but exposes no customer-facing tooling to test, debug, or optimize a configurable agent, XBOW materials 2026-07-22

Browser & Computer Use Unable to verify

Explores applications and APIs like an attacker through an offensive toolkit and HTTP-level interaction rather than documented browser or GUI computer use, XBOW platform page 2026-07-22

The Agentic Index coverage score grades every vendor Full, Partial or Unable to verify against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded

Pricing

XBOW Pentest On-Demand from $6,000 per engagement; continuous platform quoted by sales

per engagement (on-demand) + enterprise platform contract

What is public

XBOW publishes an exact starting price for Pentest On-Demand ($6,000 per engagement); the continuous enterprise platform is quoted by sales.

Variable cost rationale

On-Demand is priced per engagement from $6,000, so cost scales with the number of engagements; continuous-platform economics are quoted by sales.

Sales call required

Yes, required for paid access

Free / trial

Not published

Agentic Index verified 2026-07-22

Alternatives to XBOW

The closest documented capability profiles to XBOW among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.

  • Horizon3.ai8.5 / 14Fuller documented coverage on Triggers & Channel CoverageXBOW vs Horizon3.ai →
  • WitnessAI8.5 / 14Fuller documented coverage on Triggers & Channel Coverage
  • Operant AI9.0 / 14Adds documented Testing, Debugging & Optimization
  • Zenity8.0 / 14Fuller documented coverage on Triggers & Channel Coverage
  • Equixly7.5 / 14Fuller documented coverage on Triggers & Channel Coverage
  • HiddenLayer8.5 / 14Adds documented Testing, Debugging & Optimization

Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.