tiresias.report
Governed autonomous security assessment

The autonomous pentest that's provably in-scope.

Continuous security testing that finds what an attacker really could - then hands you an auditor-ready, standards-mapped report and a signed record it never touched what it wasn't allowed to.

Built for compliance owners & vCISOs SOC 2 PCI DSS HIPAA
Scope token · live enforcement
estate 203.0.113.0/24 · actions [recon] · depth safe · ttl 1h
recon → 203.0.113.10 ALLOW in scope · class granted · probe ran · signed 55264c8b
recon → 8.8.8.8 DENY out of scope · no packet left the box · signed 73a35f70
exploit → 203.0.113.10 DENY action class not granted · signed 65b2b2b4
recon/active → 10.0.5.10 HOLD depth over ceiling · held for human approval · signed c29330ea
hash-chained audit verified ✓ tamper-evident
The problem

An AI turned loose in your network is a breach waiting to happen.

So security teams keep autonomy on a leash - a human watching every move, or a "safety layer" bolted on top and hoped to hold. tiresias.report is the governed inverse: the boundary isn't watched, it's enforced. The agent physically cannot act outside the scope you authored.

Why it's safe

Provably in-scope. By construction.

Every competitor bolts safety on top of the agent. We put a deny-by-default policy underneath it - so staying in scope isn't a promise, it's an enforced property of how the assessment runs.

PDP

Deny-by-default, under the agent

Out-of-scope action is impossible, not discouraged. No packet leaves without passing the policy.

RoE

Signed capability-token scope

Your rules of engagement are a cryptographic token the tooling cannot exceed - not a PDF someone promises to honor.

LOG

Every action recorded

A hash-chained, tamper-evident, signed audit of every decision and result. Alter one entry and verification fails.

DEPTH

Gated depth ceilings

Recon, active, exploit - each a separate grant. Exploit depth requires explicit human approval and a signed RoE.

STOP

Emergency stop & impact limits

Customer-controlled throttling and hard limits. You hold the controls, not us.

PROOF

Reproducible by anyone

Every cited finding can be re-verified from the signed record by an independent party - including your auditor.

The loop

Scope, assess, prove, report.

STEP 01

Scope

You author the rules of engagement. They become a signed capability token the agent cannot exceed.

STEP 02

Assess

The agent tests continuously. Every action is checked against the token before it runs.

STEP 03

Prove

Findings are validated as real and exploitable, each mapped to ATT&CK and NIST, cited to a tamper-evident source.

STEP 04

Report

An auditor-ready report plus the signed action log. The deliverable is the point - it's in our name.

The deliverable

Every finding, mapped and cited.

No raw scanner dump. Each validated finding maps to a MITRE ATT&CK technique and a NIST 800-53 control, cited by tamper-evident hash. SOC 2, PCI, and HIPAA crosswalks turn it into evidence your auditor accepts.

See the full sample report →

Assessment report · excerpt signed ✓
CriticalDefault admin credentials, no lockout
ATT&CK   T1110 Brute Force @6b974a77
NIST      AC-7 Unsuccessful Logon Attempts @487d41d8
CSF       PR.AA-01 · remediation: enforce lockout + rotate
HighSQL injection in search parameter
ATT&CK   T1190 Exploit Public-Facing App @7e328752
NIST      SI-10 Information Input Validation @e6b84331
CSF       PR.PS-06 · remediation: parameterize + validate
Sample. Findings shown against a fictional target. Re-verify any hash: tkhr_store.py verify.
The obvious question

Can I trust an AI in production?

The category answers with reputation - leaderboard ranks, PhDs, "attacker-aligned." We answer with architecture and receipts, because your job is verification, not faith.

Constrained

A deny-by-default policy makes out-of-scope action impossible - not merely discouraged, and not dependent on a human catching it in time.

Recorded

Every action is captured in a signed, immutable log. Nothing the agent did can be quietly rewritten.

Attestable

The output maps to the frameworks your auditor already accepts, cited to sources anyone can re-verify.

Don't trust the AI. Trust the policy it can't break, and the signed record it can't alter.

Where we fit

Pentera-grade offense. Vanta-grade evidence. A policy the AI can't break.

Every adjacent tool does part of the job. Only a governed autonomous assessment does all of it - and proves it stayed in bounds.

What the alternatives leave open
Vulnerability scanners list what might be wrong - unvalidated, no proof, no defensible report.
We validate - real, exploitable findings, cited to a tamper-evident source.
Annual pentests are a snapshot - stale the day after, and a human writes the report.
We're continuous - your evidence is current the day the auditor asks.
Compliance tools collect evidence but outsource the actual test to someone else.
We run the test - and produce the mapped, signed evidence directly.
Autonomous-pentest tools bolt safety on top, or keep a human on the loop to catch it.
We enforce scope underneath - the agent can't step out to begin with.
How it deploys

Hosted control plane. Enforcement where the work happens.

The control plane is ours to run. The policy enforcement point sits wherever the assessment executes - our cloud for your public perimeter, a lightweight connector inside your network for everything behind the firewall.

Starter
Cloud-run

Runs from our cloud against your public perimeter. Nothing to install. External assets only.

Professional
+ Internal connector

One container inside your network, outbound-only. Reaches internal assets, enforces scope and signs the audit locally.

Enterprise
On-prem PEP fleet

Multiple connectors, air-gapped option, SSO. Assessment and evidence never leave your boundary.

The connector is itself governed. It dials out, never in - no inbound firewall changes - and it can do nothing your scope token doesn't authorize, with every action written to the signed audit. It isn't a backdoor; it's a box whose every move is deny-by-default and on the record.

Pricing

Transparent, because most of this category isn't.

Priced per estate - assets, scope profiles, cadence, and depth. Unlimited assessments within your scope. Start free; publish nothing you can't verify.

Starter
First compliance cycle, small estate.
$750 / mo
or $7,500 / yr (save ~17%)
  • Up to 25 assets, 1 scope profile
  • Monthly cadence, recon + active depth
  • Cited report: ATT&CK + NIST 800-53 / CSF
  • Signed RoE token & tamper-evident audit
Start free
Professional
Regulated mid-market. The compliance sweet spot.
$2,500 / mo
or $25,000 / yr (save ~17%)
  • Up to 250 assets, up to 5 scope profiles
  • Weekly / continuous cadence
  • SOC 2 / PCI / HIPAA control crosswalks
  • Auditor-ready export, 1-year audit retention
Start free
Enterprise
Security orgs, MSSPs, regulated enterprise.
Custom
from ~$60,000 / yr
  • Unlimited assets & scope profiles
  • Exploit depth (human-approval gated, signed RoE)
  • On-prem PEP fleet, air-gapped option, SSO / RBAC
  • Custom frameworks, dedicated CSM, white-label
Talk to us

Every plan includes the whole governance guarantee - deny-by-default enforcement, the capability-token RoE, and the signed audit. Tiers scale reach and compliance packaging, never the guarantee.

What we can show you today

We lead with proof, not logos.

A real signed report

Not a data sheet - an actual cited, standards-mapped report you can read end to end and re-verify by hash.

tiresias.report/sample
Grounded methodology

Every claim traces to a source: NIST SP 800-115 and 800-86, MITRE ATT&CK, and NIST 800-53 / CSF 2.0.

cited · re-verifiable
A scope-integrity record

Every engagement ships with a signed record of every action taken - and proof that none fell outside your scope.

zero out-of-scope, by construction
Get started

See what an attacker could do - inside the lines you set.

Run a free governed assessment on one scope profile. You keep the signed report - whether or not you ever talk to us.