Penetrify Introduces AI Security Testing for Small Businesses Facing Growing Software Security Requirements
BRNO, Czech Republic —(SP Tech Solutions)— September 29, 2026 — Czech technology company Penetrify has highlighted an artificial intelligence-based approach to penetration testing designed to provide software companies with faster and lower-cost security testing options.
Penetration testing traditionally involves cybersecurity specialists attempting to identify weaknesses in websites and applications and documenting the methods used to access protected areas or information. Professional penetration testing engagements can require substantial budgets and scheduling time, creating challenges for smaller software companies operating with limited resources.
Penetrify provides an AI agent designed to conduct automated penetration tests against websites and web applications. Testing can be performed using a target application and designated test credentials. The system attempts interactions with application features, authentication areas, forms and other accessible functions while looking for vulnerabilities that could allow unauthorised access or unintended data exposure.
The entry-level Penetrify test can run in approximately ten minutes at a price of about $29. Longer and more comprehensive testing sessions can take several hours and carry higher costs. The company has reported use of shorter testing sessions following significant software updates, allowing security checks to occur more frequently during ongoing development.
The technology differs from conventional automated vulnerability scanners. Security scanners generally identify known configuration issues, outdated software components and other recognised weaknesses by comparing observed conditions against established vulnerability information.
Application-level penetration testing can involve a different process. A test may require authentication and interaction with application functionality to determine whether access controls operate as intended. For example, an authenticated account may potentially gain access to information belonging to another account through manipulation of application requests or identifiers. Penetrify also offers a free version of that kind of check that grades a website from A to F in seconds, without registration.
Penetrify reported analysis involving more than 47,000 confirmed vulnerabilities across nearly 4,000 applications. According to company data, broken access control represented the most frequently identified serious vulnerability category within the dataset, appearing in 42% of the applications tested. Testing performed with authenticated user accounts identified more than three times as many issues as external testing of the same applications, according to the company's analysis.
The findings highlight the role of authenticated testing when assessing application security. Vulnerabilities involving user permissions and access controls can remain undetected when testing is limited to external scanning without valid user credentials.
Penetrify has also published benchmark testing intended to demonstrate the capabilities and limitations of automated security testing. In September, the company tested an entry-level version of the AI system against 104 deliberately vulnerable web applications included in the XBOW benchmark.
The test was conducted without access to underlying application source code and without human intervention. Penetrify reported successful exploitation of all 104 benchmark applications. Each benchmark challenge contains a secret code that can only be obtained through successful exploitation of the associated vulnerability.
Penetrify published testing logs from the benchmark to provide external observers with information about the individual attempts and reported results. The company has also acknowledged that the benchmark has become largely solved across the automated security testing industry, based on statements and information associated with the benchmark. The company also maintains a comparison of AI penetration testing against traditional consultancy engagements, covering cost, turnaround time and the strengths of each approach.
Additional testing against a more challenging collection of real-world vulnerabilities produced weaker results, according to Penetrify. Publication of both benchmark results provides information about areas where automated testing performs effectively and situations where more difficult security assessments can remain challenging.
Traditional penetration testing engagements continue to provide capabilities suited to complex environments and difficult targets. AI-based testing can represent a complementary approach, particularly for organisations seeking more frequent security assessments during active software development.
Regulatory and compliance requirements represent another factor increasing demand for software security testing. Frameworks such as SOC 2 can include security testing expectations for organisations and technology providers. Software companies serving larger enterprise customers may therefore encounter security questionnaires and testing requirements during procurement processes.
The pace of software development also creates additional security considerations. Development teams can release updates multiple times each day, creating repeated opportunities for vulnerabilities to enter production environments. Annual penetration testing can leave substantial periods between formal assessments.
Penetrify's analysis indicates a typical 22-day gap between vulnerability introduction and discovery when testing occurs only during deployment. More frequent automated assessments can provide additional opportunities to identify vulnerabilities closer to the time of introduction.
Penetrify was founded by Viktor Bulanek in Brno, Czech Republic. The company focuses on applying artificial intelligence to automated penetration testing and security assessment. The platform includes an entry-level testing option alongside longer testing configurations for more extensive assessments.
The company also provides a free website security assessment designed to identify common security conditions and assign a website grade from A to F. The assessment operates separately from the AI penetration testing service and provides a rapid indication of selected website security characteristics.
AI-based penetration testing remains part of a broader cybersecurity market that includes automated scanners, specialised security platforms and traditional penetration testing consultancies. Different approaches can provide different levels of coverage depending on application complexity, testing objectives, authentication requirements and assessment depth.
The development of automated security testing reflects increasing demand for more frequent application assessments as software development cycles become faster. For smaller software companies, lower-cost testing options can provide additional opportunities to incorporate security checks into development and deployment processes.
Penetrify's approach centres on automated testing designed to identify exploitable application vulnerabilities, document testing activity and provide security information for development teams. The company's published benchmark results and testing data provide measurable reference points for evaluating the capabilities and limitations of AI-driven penetration testing.
About Penetrify
Penetrify is a Czech cybersecurity technology company focused on AI-powered penetration testing for websites and web applications. Founded in Brno, the company develops automated security testing technology designed to identify exploitable vulnerabilities, assess application security and document testing results. Penetrify also provides website security assessments and publishes benchmark data to demonstrate capabilities and limitations of automated penetration testing.
Media Contact
Viktor Bulanek, Founder, Penetrify
Email: press@penetrify.cloud
Website: https://www.penetrify.cloud/