trident/pentest
Pentests that proveevery finding.
Agents attack your apps and APIs like an operator, and prove every finding with a working exploit. Point it at a URL, or connect the repo too.
- Black-box
- White-box
- Web apps
- APIs
- Proof attached
- Retest in one click
- On your schedule

01Black-box and white-box
Point it at a URL.Or hand it the code too.
Black-box needs nothing but a reachable target. White-box adds the repository, so every finding points at the exact lines that cause it.


Black-box
- Give Trident a URL. It maps routes and APIs.
- Auth, IDOR, injection and business logic get exercised across real flows.
- Point it at a URL. Nothing to install.


White-box
- Connect a repo alongside the live target, from Inventory.
- Findings point at the file and line, with a fix to commit.
02How it reads your app
Your app, taken apartthe attacker's way.
Routes come from the spec and the crawl, inputs from parameters and bodies, auth from how access is actually checked. Candidates that don't reproduce are dropped, not reported.
03Validated by doing
Every candidate is replayedbefore it counts.
- 01
Candidates queue at the gate
Each idea the agents try becomes a candidate, not a finding.
- 02
Only what reproduces passes
Replayed from a clean session with a second account. If it reproduces, it is filed with the steps.
- 03
The rest is dropped
What doesn't reproduce is dropped, not reported. No maybes in your queue.
04Proof attached
Every finding arriveswith the steps to reproduce it.

- ✓Fix mergedacme/payments-api #482 · 9:12 AM
- ↻Replaying the proof from a clean sessionSame steps, same second customer
- ●✓The proof no longer reproducesThe order returns 404 for another customer
- ●Marked resolvedRe-checked on the next scan to confirm it stays closed
Proof attached
Each finding carries the steps that reproduce it and a CVSS score.
Retest in one click
After a fix, Trident replays the proof. Each finding is re-checked on the next scan to confirm it stays closed.
A draft PR with the test
Each confirmed bug opens a draft PR with the regression test.
05Why it is different
Real exploits,not a wall of maybes.
06What it tests
The bugs a scannercan't reach.
IDOR, privilege escalation and auth bypass across your endpoints, tested safely with guardrails. REST and GraphQL endpoints are mapped and replayed.
- Broken access control
- IDOR
- Tenant isolation
- Privilege escalation
- Auth bypass
- Business logic
- Injection
- REST endpoints
- GraphQL endpoints
07Questions
Questions,answered.
No. A vulnerability scanner primarily identifies known conditions or signatures. A penetration test attempts to determine whether weaknesses can be combined or exploited under defined rules of engagement. Trident only files what it can reproduce.
The affected target, the exact steps that reproduce it, the observed impact, a CVSS score, remediation guidance and a retest result.
Not automatically. An auditor or customer may still require an independent assessment with defined dates and scope. Continuous testing improves coverage between those assessments.
New public routes, authentication or authorization changes, material API changes, and the remediation of a confirmed finding.
Find it beforethey do.
Start a free trial. Your first verified findings land within a day of connecting.
- SOC 2 audited by Sensiba LLP
- Read-only cloud access
