Evidence-ranked recon · not another scanner

Your scanner found 500 alerts.Three of them matter.

Xseth runs the recon (Subfinder, Naabu, HTTPX, Nmap), then a security-tuned LLM triages the noise into a prioritized threat assessment, with the evidence behind every finding. In minutes. You decide what's real.

Hosted today · self-hosting on the roadmap

subfindernaabuhttpxnmaptriagingacme.example.com≈ 4m

Attack surface

~500 alerts → 3 locked

ranked by impact
  • HIGHExposed Redis datastore:6379
  • MEDJenkins login exposedConfirmed ✓:8080
  • MEDDeprecated TLS enabled:443
No demo flow · the real console

What lands on your screen

Every finding ranked, with the evidence and the fix beside it. This is the actual assessment, not a slide.

09:15
Xseth

Threat Assessment

acme.example.com · xseth_demo_8829F

3

Findings

1

High

1

Confirmed

Findings

1. Exposed datastore: Redis reachable on the internet

HIGHUnproven

A datastore reachable from the public internet with no transport security. If it is unauthenticated, anyone who can reach it could read or modify data.

2. Exposed CI/build login surface (Jenkins)

MEDIUMConfirmed ✓

A CI/CD login page exposed to the internet on a known-vulnerable build. An attacker could target the pipeline and the secrets it holds.

3. Deprecated TLS enabled on the main site

MEDIUMUnproven

Outdated TLS protocols weaken transport security and commonly fail compliance checks (PCI DSS, SOC 2).

What you get today

A recon & triage teammate, not another scanner.

Continuous coverage between your pentests. A force multiplier for the engineer you already have, honest about what it does and what it doesn't.

01

Less noise, not more

A security-tuned LLM ranks and de-noises raw recon, so one engineer reads signal instead of wading through scanner output.

02

You stay in control

AI plans the recon and triages the findings using the tools you already trust: Subfinder, Naabu, HTTPX, Nmap. Every result carries its evidence, so you see exactly what it ran and why, and you decide what's real.

03

Minutes, not weeks

Submit a target you're authorized to test, and a prioritized threat assessment comes back, usually in under five minutes.

04

Findings you can trust

High-impact findings get a non-destructive validation probe and come back CONFIRMED, or honestly flagged unproven. You see what was verified, not just what was guessed.

05

A report you can hand over

Export any assessment as a client-ready PDF: prioritized findings with evidence, impact, and remediation, in plain prose. Drop it in a ticket, or send it to the client.

06

Ask Thoth

Every assessment ships with Thoth, a grounded chatbot that answers questions about your findings, validations, and attack paths, and cites the data behind each answer. It's read-only: it explains the scan and never invents a finding.

Who it's for

Built for the team of one.

Xseth is for the security engineer covering an attack surface that used to take a team: lean security teams, technical founders, and small MSPs who'd rather read three real findings than five hundred alerts. If you want a compliance pentest or a managed service, we'll be honest: that's not us, yet.

Safety & scope

Safe by architecture, not by promise.

Scope discipline isn't a setting you can forget to turn on. It's built into the way Xseth runs, at every stage.

Scope

Scope is the spine.

An AI intake gate refuses off-limits targets (hospitals, governments, schools) before a single packet leaves. Authorized scope is re-validated at multiple independent gates.

Non-destructive

Non-destructive by design.

Validation probes are hardcoded non-destructive. Reserved and internal IPs are blocked in every worker.

Audited

Everything audited.

Every decision the agent makes is logged. Your data stays recon metadata only, never source code or secrets.

Scanner vs. engine

It already has a brain

A scanner runs a checklist. Xseth keeps a model of the target and reasons over it, and that cognitive core is built and running today. The autonomy is where we're going, one capability at a time, behind controls.

01 · todayshipping

The teammate

Point it at a target you're authorized to test; get back a ranked, de-noised threat assessment with the evidence behind each finding.

02 · the brainalready built

The cognitive core

Under the hood Xseth keeps a live world-model of the target, chains low-severity findings into real attack paths, and runs a bounded decide-loop. The difference between a scanner and something that reasons.

world-modelattack-chainingOODA loop
How the cognitive core works
03 · the visionroadmap

The engine

An autonomous AI pentesting engine that acts like a hacker: goal-directed, adaptive, and chaining to impact, always scope-bound, approval-gated, and audited. The brain is built; the hands come one capability at a time.

See the engine

A2 · world model

live

What it sees

acme.ioapi.build.:6379:8080

Hosts, subdomains, services and endpoints projected into one persistent graph the agent reasons over.

A4 · attack path

high

What it chains

Exposed CI panel + reused credential → pipeline access.

  1. 1

    build.acme.io:8080

    Exposed Jenkins login surface

  2. 2

    ci pipeline

    Weak/default credential → pipeline access

  3. 3

    build environment

    Reach secrets staged in the build

A3 · agent loop

bounded

What it decides

budget1 / 2 spent
0
continue

Naabu surfaced a new host: one focused Nmap wave is worth the cost.

1
stop

Picture is complete and the step budget is reached. Halt cleanly.

Frequently asked

Questions, answered

Straight answers to what teams ask before their first scan.

What does Xseth do, exactly?

Xseth runs the recon (Subfinder, Naabu, HTTPX, Nmap), then a security-tuned LLM triages the output into a prioritized threat assessment. Every finding carries the evidence behind it. You review it and decide what's real. Recon and triage, with a human in the loop.

Is my source code sent anywhere?

No. We only send recon metadata to our LLM provider: subdomains, ports, banners, and the HTTP and Nmap evidence used to build the assessment. Never your source code or secrets, and only for targets you're authorized to scan. Self-hosting is on the roadmap.

How long does an assessment take?

Usually under five minutes from submitting a target to a ranked threat assessment, depending on the size of the attack surface.

What am I allowed to scan?

Only targets you're authorized to test. SmartGate refuses off-limits categories like hospitals, governments, and schools before a single packet leaves the box.

Does Xseth replace a penetration test?

No. Xseth is a force multiplier, not a compliance pentest. It makes one engineer faster and cuts down false positives. It supplements human-driven and compliance-grade testing rather than replacing it.

Early access

Become a design partner.

We're onboarding a small group of technical teams to run real targets, self-evaluate the results, and shape what Xseth becomes. Early access, a direct line to the founders, and straight answers about what works today and what's still roadmap.

Transparent pricing, published · see plans →