# Parameter > Parameter is an AI security company. Its agents continuously pentest web apps, APIs, cloud infrastructure and code, proving every vulnerability they find before it reaches you. Parameter (parameter.ai, formerly Hex Security; legal entity Anytool, Inc.) builds autonomous security agents: continuous AI penetration testing, cloud security mapping, software supply chain analysis, and Sentinel, an AI security review for every pull request. ## Products - [AI Penetration Testing](https://www.parameter.ai/pentesting): Autonomous agents that pentest web apps and APIs on demand and on every release, with audit-grade SOC 2 / ISO 27001 reports. - [Cloud Security](https://www.parameter.ai/cloud-security): Agents inventory AWS, Google Cloud and Azure resources, trace real attack paths, and open the Terraform fix. - [Supply Chain Security](https://www.parameter.ai/supply-chain): Full dependency-graph resolution, malicious and vulnerable package detection, and an audit-ready SBOM. - [Sentinel — AI Security Code Review](https://www.parameter.ai/sentinel): Reviews GitHub, GitLab and Bitbucket pull requests for real, exploitable vulnerabilities before they merge. ## Penetration testing How the pentesting agents apply to specific needs. Each page defines the term, explains the workflow, and answers the common questions. - [Web application penetration testing](https://www.parameter.ai/pentesting/web-application-penetration-testing): SPAs, server-rendered apps, and their APIs tested for the vulnerabilities attackers use. - [API security testing](https://www.parameter.ai/pentesting/api-security-testing): REST, GraphQL, and gRPC endpoints tested for broken auth, IDOR, and logic flaws. - [Red team as a service](https://www.parameter.ai/pentesting/red-team-as-a-service): Adversarial testing that does not stop: agents chain real attack paths and prove every step. - [External attack surface management](https://www.parameter.ai/pentesting/external-attack-surface-management): Everything reachable from the internet, mapped continuously and then tested. - [Managed vulnerability scanning](https://www.parameter.ai/pentesting/managed-vulnerability-scanning): Scanning as an outcome: every finding validated, ranked by reachability, and delivered with a fix. - [Android penetration testing](https://www.parameter.ai/pentesting/android-penetration-testing): The APIs, auth flows, and source behind your Android app, tested on every release. ## Industries The same agents explained for one regulated vertical: what breaks there, which frameworks the buyer answers to, and what evidence a run produces. - [Fintech](https://www.parameter.ai/use-cases/fintech): Payment flows, partner APIs, cloud, and code pentested as they change, with evidence for PCI DSS and SOC 2. - [Healthcare](https://www.parameter.ai/use-cases/healthcare): The code, cloud, and dependencies behind patient data pentested on every release, with evidence for HIPAA, SOC 2, and HITRUST. ## Compliance What SOC 2, ISO 27001, PCI DSS, and FedRAMP each ask of penetration testing, clause by clause, and what a run produces for it, including where each still expects a qualified human or accredited assessor. - [SOC 2 penetration testing](https://www.parameter.ai/compliance/soc-2-penetration-testing): What a SOC 2 auditor expects from penetration testing, clause by clause, and how a run on every release supplies it. - [ISO 27001 penetration testing](https://www.parameter.ai/compliance/iso-27001-penetration-testing): What ISO 27001 controls expect from penetration testing, clause by clause, and how continuous runs supply the evidence. - [PCI pentest](https://www.parameter.ai/compliance/pci-pentest): What PCI DSS v4.0 Requirement 11.4 asks, what a QSA wants, and where continuous testing fits alongside the annual test. - [FedRAMP penetration testing](https://www.parameter.ai/compliance/fedramp-penetration-testing): What FedRAMP requires of penetration testing, the 3PAO's role, and how continuous testing supports continuous monitoring. ## Alternatives How Parameter compares with the pentesting vendors buyers evaluate it against. Each page states what the other product is, where the two differ, and where each fits. - [Cobalt alternative](https://www.parameter.ai/alternative/cobalt): Scheduled, human-led pentest engagements, compared with agents that test on every release and prove every finding. - [Horizon3 alternative](https://www.parameter.ai/alternative/horizon3): Autonomous network pentesting from Horizon3, compared with agents built for the application layer: code, cloud, and dependencies. - [NodeZero alternative](https://www.parameter.ai/alternative/nodezero): Horizon3's NodeZero, compared with Parameter at the product level: attack surface, deployment, validation, and where findings land. - [Pentera alternative](https://www.parameter.ai/alternative/pentera): Pentera's automated security validation of the network, compared with agents that pentest the application layer on every release. - [Bugcrowd alternative](https://www.parameter.ai/alternative/bugcrowd): A crowdsourced researcher program, compared with agents that test everything continuously and deliver findings already proven. - [HackerOne alternative](https://www.parameter.ai/alternative/hackerone): Bug bounty and community-delivered pentests, compared with agents that test on every release and prove every finding. - [XBOW alternative](https://www.parameter.ai/alternative/xbow): XBOW's autonomous black-box pentests, compared with agents that test code, cloud, and dependencies on every release. - [Aikido alternative](https://www.parameter.ai/alternative/aikido): Aikido's self-serve scanner platform and AI pentest, compared with agents that pentest on every release and prove every finding. ## Free tools Interactive tools that need no account. Each runs entirely in the browser. - [CVSS calculator (v3.1)](https://www.parameter.ai/tools/cvss-calculator): Score a vulnerability against the FIRST specification, with base, temporal and environmental metrics and the definition of every value on screen while you choose it. ## Company - [About](https://www.parameter.ai/about): What Parameter is building and why. - [Security](https://www.parameter.ai/security): How Parameter secures its own platform and handles customer data. - [Careers](https://www.parameter.ai/careers): Open roles in San Francisco. - [Book a call](https://www.parameter.ai/book-a-call): Talk to the team and see first findings in 24 hours. ## Blog - [13 Benefits of Penetration Testing Every Business Should Know](https://www.parameter.ai/blog/benefits-of-penetration-testing): Security leaders gain 13 benefits of penetration testing that stop breaches, audit failures, and reputational damage before they happen. - [The bug is rarely in the diff: reviewing 5,000 PRs per day](https://www.parameter.ai/blog/agentic-code-review-explained): How Sentinel, our agentic PR review bot, catches exploitable security bugs before they merge by following execution paths across a pull request, not just scanning the diff. - [We ran 2,300 pentests in 3 weeks. Here's what our AI finds](https://www.parameter.ai/blog/what-ai-pentests-find): In three weeks our agents ran 2,300 autonomous AI penetration tests. ~37% of findings were high or critical, mostly authorization, IDOR, and business-logic bugs scanners miss. - [Hex Security is now Parameter](https://www.parameter.ai/blog/we-are-now-parameter): Hex Security has a new name and a new home. The company behind it, Anytool, Inc., is unchanged, and so is the product. Here is what changed, what didn't, and where to verify it, including in person at Black Hat USA 2026. - [It's the harness, not the model: +26% on CryptanalysisBench's hard set](https://www.parameter.ai/blog/cryptanalysisbench-harness-not-model): Fix the model to Claude Opus 4.8, keep the paper's protocol, change only the harness, and the scaffold lifts Tier-2 from 31/140 (22.1%) to 39/140 (27.9%). - [Continuous penetration testing vs. annual pentests: what actually changed](https://www.parameter.ai/blog/continuous-penetration-testing-vs-annual-pentests): The annual pentest was built for a world that shipped software twice a year. Here's what continuous penetration testing means, where the market's definitions fall apart, and how to tell real coverage from a scanner in a trench coat. - [SSRF to cloud takeover: how one URL field becomes credential theft](https://www.parameter.ai/blog/ssrf-to-cloud-credentials): Server-side request forgery turns an innocent 'fetch this URL' feature into a path straight to your cloud's metadata endpoint, and the temporary credentials behind it. Here's the full chain and how to break it. - [Security at the speed of development](https://www.parameter.ai/blog/security-at-the-speed-of-development): Security can't be the team that says no once a quarter. It has to move at the cadence engineering already runs at: every commit, every deploy. ## Videos Short explainer videos from the team, one vulnerability per episode. Each has a page here with the video, its description, and a link to the upload on YouTube. - [Broken Access Control (IDOR)](https://www.parameter.ai/videos/broken-access-control-idor): What an insecure direct object reference (IDOR) is, how a missing permission check exposes private records, and why servers must authorize every request.