Hex Security is now ParameterWe're at Black Hat USA 2026

Parameter

Backed by Y Combinator

Penetration testingon autopilot.

Autonomous AI agents that outperform humans at machine speed. Get an audit-grade SOC 2 or ISO 27001 report in hours, not weeks.

Start your pentest

See first findings in 24 hours

Top 3

in the US on HackerOne

24h

to first findings

24/7

continuous coverage

Built by the team that secured:

Apple
Google
Microsoft
U.S. Department of Defense
T-Mobile
Henkel
Epic Games
AT&T
Yahoo

[ how it works ]

01

Probe

Agents map your real attack surface, every endpoint, parameter, and auth flow, from your code, your OpenAPI specs, or just the live app.

02

Exploit

Hundreds of agents work real attack paths in parallel. They try to break expected behavior the way an attacker would, not run down a checklist.

03

Verify

Every issue is reproduced from a clean state. Unproven findings are dropped; what's left ships with impact, repro steps, and a fix.

[ reports ]

Every report yourstakeholders need.

The same pentest produces the right document for each audience. No rewriting, no extra work.

Executive summary

Risk posture and the findings that matter, for leadership.

Customer-facing report

Proves your security posture without exposing your stack.

Auditor report

Findings with technical detail and mapped to SOC 2 and ISO 27001.

Remediation report

What's fixed, what's left, and what changed, ready to share.

Download sample report

Pauses on real risk

When an agent finds something exploitable, it stops and shows you the full attack analysis before going any deeper.

Safe by default

Parameter confirms a finding and holds. It won't chain exploits or escalate unless you opt in.

Escalate on your terms

Choose a deeper follow-up on any finding. Results are tracked in place, on the same finding.

[ capabilities ]

Finding to fix.Fully automatic.

Point Parameter at your code and it runs the full loop on its own. Find, exploit, verify, and fix, with almost no false positives along the way.

Whitebox, greybox, or blackbox

Point us at a repo, an OpenAPI spec, or just a URL. Agents reason at scale with full context.

Watch it work, live

Launch in minutes and follow agents as they hunt. Re-test the moment you ship a fix.

Fixes, not just findings

High-confidence pull requests, generated and ready to merge and re-test.

Under 1% false positives

Every finding clears a separate validation pass before it ever reaches you.

[ coverage ]

Everything an attacker can reach.Tested before they get there.

Point us at your stack and agents map every endpoint, API, and auth flow, the same surface a real attacker would probe.

Web apps

SPAs, server-rendered apps, and everything in between.

Infrastructure

Cloud misconfigurations and exposed services.

APIs

REST, GraphQL, and gRPC, authenticated or not.

Auth flows

Sessions, OAuth, SSO, and multi-tenant boundaries.

Source code

Pull-request scanning that catches issues pre-merge.

AI / LLM apps

Prompt injection, tool abuse, and data exfiltration.

[ FAQ ]

Frequently asked questions

[ pricing ]

Pricing that scales.Priced to your app, not per seat.

From a one-off audit to always-on coverage, pricing tracks the size and complexity of what you’re testing. No seats, no surprises.

Single App

Fixed scope

A time-boxed pentest of one application and its primary APIs, with a full audit report.

Audit-ready SOC 2 / ISO 27001 report

One app and its APIs

Whitebox, greybox, or blackbox

Same-day results

Free re-testing

Get a quote

Rightsized

Scoped for you

We size the test from your repos, endpoints, and roles. Small app, small price. Complex platform, full coverage.

Everything in Single App

Scope set automatically from your repos

Multi-service and multi-repo

Built for complex platforms

Get a quote

Continuous

Custom

Always-on offensive security that runs on every release. New code ships, new tests run.

Everything in Rightsized

Pentest on every deploy

Enterprise SLA and support

Dedicated success manager

Talk to sales

Start testing today.

A URL and credentials is all it takes.

First findings land within 24 hours.