Reflectiz Launches Multi-Agent Web Pentesting Platform
  • News
  • North America

Reflectiz Launches Multi-Agent Web Pentesting Platform

AI agents discover, attack, and validate web vulnerabilities with up to 10x more coverage

9/9/2026
Ali Abounasr El Alaoui
Back to News

Reflectiz, a continuous web exposure management company, today announced a multi-agent penetration testing platform designed for modern websites. The new solution uses specialized artificial intelligence agents to discover, attack, and validate vulnerabilities across complex web environments. By starting from an existing model of each site, the platform promises up to ten times more coverage than conventional penetration testing tools.


Addressing the Limits of Traditional Pentesting

Traditional penetration testing is often a periodic engagement whose final report describes a single moment rather than an evolving website. Login, checkout, payment, and third-party script behaviors keep changing while attackers probe the environment daily. Idan Cohen, CEO and co-founder of Reflectiz, noted that websites change every week and need testing that keeps up with releases at a cost teams can sustain.

Starting with a Live Model of the Website

Reflectiz differentiates its approach by beginning each test with a live model of the website rather than starting blind. The company has spent a decade scanning thousands of production sites and maintains current information on pages, scripts, third parties, domains, sensitive inputs, and behaviors. Its penetration testing agents add an attacker perspective to that same model, while findings include the script involved, accessible data, and whether real users are exposed immediately.

A Coordinated Team of AI Agents

The new platform operates as a coordinated team of AI agents, each with a defined role. One agent crawls the site like a real user, navigating logins, one-time codes, and two-factor authentication. A second fingerprints the technology stack, a third runs applicable attacks and chains findings, and a fourth independently validates every result before it reaches the report to remove false positives by design.

Completing the 360 Degree Map of Web Risk

Agentic pentesting is part of the new Offensive Hub, which joins Security Hub and Privacy Hub on the Reflectiz platform. These components create a complete map of web risk covering what runs on a website, what data it touches, and how it can be attacked. Ysrael Gurt, CTO and co-founder, explained that the hard part of web pentesting was never the payload but understanding what the application actually does, giving Reflectiz agents a map that other tools never build.

Guided Fixes and Workflow Integration

The platform consolidates findings into one exposure picture rather than a fragmented list of alerts. Security teams receive guided remediation steps that are designed to fit within existing operational workflows. This approach helps organizations move from identification to resolution without adding new tools, reducing manual investigation cycles and accelerating risk reduction.

Seeing the Platform in Action

Reflectiz founders Idan Cohen and Ysrael Gurt will demonstrate the agentic pentesting platform in a live webinar on September 15 at 11 AM ET and 5 PM CET. The session is intended to show how the multi-agent system operates in practice against complex web environments. Attendees will see how the platform builds on existing website models to improve coverage and accelerate remediation.


The launch of Reflectiz agentic penetration testing reflects a shift toward continuous, model-informed security validation for websites. By combining live website intelligence with specialized AI agents and independent validation, the company aims to reduce false positives and help teams act faster. Organizations managing frequently changing web environments may find the approach a practical alternative to traditional periodic penetration tests.