Edgescan Atomic brings controlled AI penetration testing
Edgescan has launched Edgescan Atomic, an autonomous penetration-testing capability that uses agentic AI to probe applications and confirm which attack paths are actually exploitable. The company says the product can run on top of its existing continuous security platform or be deployed as a standalone agentic penetration testing solution.
Edgescan presents Atomic as a response to a specific concern. Organizations want assurance that they can withstand AI-powered cyber attacks. Atomic is meant to give them continuous, fast, on-demand offensive validation so they can check their security posture without waiting for a scheduled engagement.
Built on existing scan data
Atomic can work on its own, but Edgescan says it performs much better when connected to Edgescan Intelligence. This is the data the company already holds on a customer's environment, including:
- historical scan data and earlier assessment results
- findings from PTaaS (penetration testing as a service) engagements
- false positive data and validated vulnerabilities
- asset context and authentication workflows
- API information
According to Edgescan, this background gives the AI a better starting point when it explores possible attack paths and tries to confirm them. Instead of starting each test with no knowledge of the target, Atomic can use metadata from previous assessments where it exists.
A harness to keep the AI in check
The central control mechanism is what Edgescan calls the Edgescan Harness. It sets limits on what the AI is allowed to do during a test. The Harness enforces a defined scope, permissions, approvals and policies.
Within those limits, Atomic can reason and change its approach the way a human attacker would. Its actions stay controlled and auditable, and the Harness logs what the AI does and applies policy to each action. Edgescan says this lets organizations use autonomous penetration testing without losing oversight of what happens in their environment.
What Atomic is designed to find
Edgescan says the tool targets business-logic and access-control vulnerabilities. These include insecure direct object reference (IDOR) flaws, in which an application exposes data or functions by trusting a user-supplied identifier without checking whether that user is allowed to access it. Other targets are authorization weaknesses and broken access control in general.
These bug classes are often hard for traditional automated scanners to catch, because finding them requires an understanding of how an application is supposed to behave.
Atomic also attempts to back up its findings with evidence before they reach human analysts. Edgescan says this should reduce the noise that security operations and AppSec teams have to sort through and cut down on investigation and triage work. Validation is handled by what the company describes as an agentic validation team, with Edgescan's human experts available if needed.
Licensing and cost
On pricing, Edgescan is promising predictability. The licensing model gives customers a defined testing budget, and the Harness provides control over scope and records the actions taken by the AI.
"Edgescan Atomic addresses a fundamental limitation of traditional penetration testing: the AI-powered threat environment and the rate of application code change. Atomic gives customers the power to launch autonomous penetration testing whenever they need it, putting more control, greater flexibility, and faster security validation directly in their hands," said Eoin Keary, CEO of Edgescan.
Our Take
Atomic joins a growing number of products that use AI agents for offensive testing. In recent weeks, Hadrian raised funding for its agentic offensive security platform, and Vijil introduced tooling that red-teams AI agents with adaptive attacks. The pitch is similar each time. Annual or quarterly pentests cannot keep pace with code that changes daily, or with attackers who are also adopting AI, a concern Microsoft raised when it said attackers lead defenders in the early AI race.
The most notable part of Edgescan's announcement is the emphasis on the Harness. This suggests vendors know that buyers are uneasy about letting autonomous agents loose on production systems. The focus on scope enforcement, approvals and audit logs reads as an attempt to answer that concern directly.
It is worth watching how well these controls hold up in practice, and whether AI-driven testing can reliably find business-logic flaws such as IDOR without flooding teams with unverified results. Independent evaluations would help buyers judge those claims.
