The AI-native, blackbox, graybox, whitebox pen test

Deeper than a manual pen test, delivered in days and audit-ready for your SOC 2.

your-companypentest-1
Showing 8 of 8 findings
IDTitleFound
Open5
In Progress1
Fixed2
Flagright
Metal
Ordalie
Bastion
Candid Health
PointOne
Moove
MuralPay
LlamaIndex
Station70
Electio
FluxCap

Trusted by fast-moving teams

We needed a new penetration test report for a 3rd party with high urgency, and Trace turned it around faster than a traditional firm could even get us on the calendar. Every finding came with a working exploit and clear remediation — no list of maybes to chase down. They surfaced real, exploitable issues we hadn’t caught.

Director of EngineeringAnti-fraud FinTech SaaS firm
01 / 07

Everything included
in your pen test

Every finding proven, reviewed by a human, and audit-ready.

AcmeFileEditView9:41
AcmeOverviewReports
Home
Analytics
Team
Settings
Revenue$48,290+12%
Users8,214+6%
Retention94%+1%
Revenue · last 30 days
SlackMicrosoft TeamsClaudeCodexCursor
9:41
Total balance
$128,420+2.4%
Stripe+$4,200
AWS-$1,180
Shopify+$2,860

Web · Mobile · Desktop

Trace tests across web, mobile, desktop, and AI surfaces, from native iOS and Android apps to the LLM powered agents and MCP servers behind them.

trace-pentest-report.pdfNew report
TR-PT-2026-03 · Acme · v1.0
Trace · Penetration test reportTR-PT-2026-03-ACME
Prepared forAcme Inc.Acme Platform · Application & Cloud Penetration Test
EngagementMarch 2026 Pentest
Report date31 March 2026
Testing window03 — 28 March 2026
MethodologyTrace exploit-gated · CVSS v4.0
Tested byBrandon Helms, OSCP, CISSP

Audit-ready report

Every engagement ends with a penetration test report and a signed letter of attestation, ready for SOC 2, ISO 27001, HIPAA, PCI DSS, and vendor reviews.

Slack#trace-yourcompany
Message a human

Human in the loop

An OSCP-certified expert signs off on every finding, plus a private Slack channel with the Trace team.

IDOR
---severity: Highowasp: A01cwe: CWE-639cvss: 8.1---The endpoint returns any invoice by id with no ownership check, exposing other tenants' billing data.
Excessive Agency
---severity: Highowasp: LLM06cwe: CWE-250cvss: 7.6---The agent calls privileged tools with no confirmation step, so one crafted response can trigger destructive actions.
Prompt injection
---severity: Criticalowasp: LLM01cwe: CWE-77cvss: 9.1---Untrusted input reaches the agent's system prompt, letting an attacker override its instructions and exfiltrate data.
Broken object level auth
---severity: Highowasp: API01cwe: CWE-639cvss: 8.4---A tenant id in the path is trusted as given, so any account can read another account's orders.

OWASP Top 10 for Web, LLMs, Mobile, and APIs

Every finding maps to the OWASP Top 10 for web, LLMs, mobile, and APIs, with a CWE and CVSS score.

Sandbox
Agent #1
Agent #2
Agent #3
app.acme.com

Proven with real exploits

DAST

Every finding is minimally exploited on your live stack, so there are no false positives to triage.

About
Retests
Retest
StatusDurationRun
Fixed2m 30sJul 10, 2:14 PM
Open3m 45sJul 6, 10:11 AM
Open1m 58sJul 2, 9:03 AM
Fixed2m 05sJun 27, 4:48 PM

Unlimited retests

Deploy a fix and Trace re-tests the exploit and gives you feedback in minutes. No more waiting on a slow retest cycle.

Before TracePoint in time tests
JanDec
With TraceContinuous testing
JanDec

Continuous coverage

Add-on

Pick a cadence, quarterly, monthly, weekly, or continuous, and Trace pen-tests new features as you ship. BYOK and self-hosted options let you use your own inference.

The more context you connect,
the deeper the test

We recommend connecting everything below so Trace can run its deepest scan.

Live Applications

Define your applications in Trace and optionally attach credentials, which agents then use to authenticate and carry out exploits.

Your Company
Email
jane@yourcompany.com
Password
••••••••••
Sign in

Source Code

Trace reads the code across your attack surface, tracing input to sink to confirm real bugs like IDOR, privilege escalation, and injection.

acme/backendPrivate
main
Code
Update search endpoint7ddf16d · 2m
.github2 days ago
src2 hours ago
tests2 hours ago
package.json5 days ago
GitHub
GitLab
Bitbucket

Knowledge Base

Your docs and wikis give Trace the intended behavior, so it can tell a real vulnerability from expected functionality.

docs.company.com/architecture
Architecture
Overview
Services
Data model
Auth & sessions
Deployment
Docs›Architecture
System architecture
Services
Data flow
Slack
Confluence
Notion

Cloud Infrastructure

Trace maps your real cloud topology to find what's internet-facing and reachable, then confirms what's exploitable.

acme-prodCREATE_COMPLETE
app-alb
ELBv2::LoadBalancer
Internet-facing
api-service
ECS::Service
orders-db
RDS::DBInstance
Private
AWS
Azure
GCP
Vercel
Railway
Cloudflare
Supabase

Issue Tracking

Trace opens a ticket for every finding in your tracker, linked back to the full report, so remediation stays in your normal workflow.

LinearPentest Q46 issues
SEC-142SQL injection in /api/search
SEC-141IDOR on /api/invoices/:id
SEC-140SSRF in webhook fetcher
SEC-139Broken access control on exports
SEC-138Missing rate limit on login
SEC-137Verbose error leaks stack trace
Jira
Linear

Logs & Telemetry

Coming soon

Trace reads your logs to catch PHI or PII leaking into them and to confirm how your API routes actually behave.

app-prod · logsLive
12:04:01INFOGET /api/search 200 24ms
12:04:01INFOPOST /api/login 200 88ms
12:04:02WARNpii: email in /api/users response
12:04:02INFOGET /api/invoices/42 200 12ms
12:04:03INFOGET /api/orders 200 41ms
12:04:03WARNslow query 1.2s on /reports
12:04:04INFOPOST /api/webhooks 200 19ms
12:04:04INFOGET /api/profile 200 15ms
12:04:05WARNpii: ssn in /api/kyc log line
12:04:05INFOGET /api/search 200 22ms
Sentry
Datadog
Grafana
“After our pen test, we installed Trace’s PR reviewer so we could shift left and catch security issues before they ever merge.”
Madhu G NadigMadhu G NadigCo-Founder & CTO, Flagright
TraceTraceTraceTrace
Get monthly product updates

© 2026 Trace, Inc.
All rights reserved.