The teammate
Point it at a target you're authorized to test; get back a ranked, de-noised threat assessment with the evidence behind each finding.
Xseth runs the recon (Subfinder, Naabu, HTTPX, Nmap), then a security-tuned LLM triages the noise into a prioritized threat assessment, with the evidence behind every finding. In minutes. You decide what's real.
Hosted today · self-hosting on the roadmap
Attack surface
~500 alerts → 3 locked
Every finding ranked, with the evidence and the fix beside it. This is the actual assessment, not a slide.

acme.example.com · xseth_demo_8829F
3
Findings
1
High
1
Confirmed
Findings
A datastore reachable from the public internet with no transport security. If it is unauthenticated, anyone who can reach it could read or modify data.
A CI/CD login page exposed to the internet on a known-vulnerable build. An attacker could target the pipeline and the secrets it holds.
Outdated TLS protocols weaken transport security and commonly fail compliance checks (PCI DSS, SOC 2).
Continuous coverage between your pentests. A force multiplier for the engineer you already have, honest about what it does and what it doesn't.
A security-tuned LLM ranks and de-noises raw recon, so one engineer reads signal instead of wading through scanner output.
AI plans the recon and triages the findings using the tools you already trust: Subfinder, Naabu, HTTPX, Nmap. Every result carries its evidence, so you see exactly what it ran and why, and you decide what's real.
Submit a target you're authorized to test, and a prioritized threat assessment comes back, usually in under five minutes.
High-impact findings get a non-destructive validation probe and come back CONFIRMED, or honestly flagged unproven. You see what was verified, not just what was guessed.
Export any assessment as a client-ready PDF: prioritized findings with evidence, impact, and remediation, in plain prose. Drop it in a ticket, or send it to the client.
Every assessment ships with Thoth, a grounded chatbot that answers questions about your findings, validations, and attack paths, and cites the data behind each answer. It's read-only: it explains the scan and never invents a finding.
Xseth is for the security engineer covering an attack surface that used to take a team: lean security teams, technical founders, and small MSPs who'd rather read three real findings than five hundred alerts. If you want a compliance pentest or a managed service, we'll be honest: that's not us, yet.
Scope discipline isn't a setting you can forget to turn on. It's built into the way Xseth runs, at every stage.
An AI intake gate refuses off-limits targets (hospitals, governments, schools) before a single packet leaves. Authorized scope is re-validated at multiple independent gates.
Validation probes are hardcoded non-destructive. Reserved and internal IPs are blocked in every worker.
Every decision the agent makes is logged. Your data stays recon metadata only, never source code or secrets.
A scanner runs a checklist. Xseth keeps a model of the target and reasons over it, and that cognitive core is built and running today. The autonomy is where we're going, one capability at a time, behind controls.
Point it at a target you're authorized to test; get back a ranked, de-noised threat assessment with the evidence behind each finding.
Under the hood Xseth keeps a live world-model of the target, chains low-severity findings into real attack paths, and runs a bounded decide-loop. The difference between a scanner and something that reasons.
An autonomous AI pentesting engine that acts like a hacker: goal-directed, adaptive, and chaining to impact, always scope-bound, approval-gated, and audited. The brain is built; the hands come one capability at a time.
See the engineA2 · world model
liveHosts, subdomains, services and endpoints projected into one persistent graph the agent reasons over.
A4 · attack path
highExposed CI panel + reused credential → pipeline access.
build.acme.io:8080
Exposed Jenkins login surface
ci pipeline
Weak/default credential → pipeline access
build environment
Reach secrets staged in the build
A3 · agent loop
boundedNaabu surfaced a new host: one focused Nmap wave is worth the cost.
Picture is complete and the step budget is reached. Halt cleanly.
Xseth was selected into two of the programs that back the world's most ambitious startups, the same networks behind companies you already know.
NVIDIA Inception
MemberNVIDIA's program for cutting-edge AI startups, with access to NVIDIA's accelerated-computing stack, technical expertise, and go-to-market support.
Learn moreStartup Grind
MemberThe world's largest community of startups, powered by Google for Startups, connecting Xseth to founders, mentors, and investors across hundreds of cities worldwide.
Learn moreStraight answers to what teams ask before their first scan.
Xseth runs the recon (Subfinder, Naabu, HTTPX, Nmap), then a security-tuned LLM triages the output into a prioritized threat assessment. Every finding carries the evidence behind it. You review it and decide what's real. Recon and triage, with a human in the loop.
No. We only send recon metadata to our LLM provider: subdomains, ports, banners, and the HTTP and Nmap evidence used to build the assessment. Never your source code or secrets, and only for targets you're authorized to scan. Self-hosting is on the roadmap.
Usually under five minutes from submitting a target to a ranked threat assessment, depending on the size of the attack surface.
Only targets you're authorized to test. SmartGate refuses off-limits categories like hospitals, governments, and schools before a single packet leaves the box.
No. Xseth is a force multiplier, not a compliance pentest. It makes one engineer faster and cuts down false positives. It supplements human-driven and compliance-grade testing rather than replacing it.
We're onboarding a small group of technical teams to run real targets, self-evaluate the results, and shape what Xseth becomes. Early access, a direct line to the founders, and straight answers about what works today and what's still roadmap.
Transparent pricing, published · see plans →