SEWORKS provides AI‑driven offensive security platforms that automate vulnerability discovery and credential‑leak detection for enterprise applications. Its Pentoma service uses the proprietary GAMAN® engine to generate and prioritize attack payloads, while LeakJar continuously aggregates leaked credentials and issues real‑time alerts with remediation guidance. Both solutions integrate via REST APIs, webhooks, and SIEM connectors to support DevSecOps workflows and automated compliance reporting.
Funding
$10M raised to dateRaised to date based on public sources. This may differ from the amount the company actually raised and is based only on what is publicly available on the internet.
Founders
Product
Problem
Enterprises face lengthy, expensive penetration testing cycles that often miss emerging attack vectors, while credential leaks across the internet expose employee and customer accounts to takeover and fraud. Traditional security tools lack continuous, automated monitoring and rapid response capabilities needed to protect modern digital assets at scale.
Solution
SEWORKS delivers AI-driven offensive security services that automate vulnerability discovery and credential leak detection. Pentoma uses the proprietary GAMAN® engine to scan target applications, generate attack payloads, and prioritize findings, with expert analysts validating results to eliminate false positives. LeakJar continuously aggregates leaked credential data from diverse sources, applies AI matching algorithms, and issues real‑time alerts with actionable remediation steps. Both solutions integrate via REST APIs, webhooks, and SIEM connectors, enabling seamless embedding into existing DevSecOps and incident‑response workflows. The platform also supports automated compliance reporting for frameworks such as SOC 2, ISO 27001, PCI DSS, and NIST.
Target Audience
The primary customers are enterprise security and compliance teams, DevSecOps engineers, and risk managers responsible for vulnerability management, credential protection, and regulatory adherence across large organizations.
Features
- GAMAN® AI engine combines unsupervised learning and environment intelligence to generate high‑precision attack simulations
- Automated four‑step testing workflow (analyze, test, verify, report) with human expert validation to reduce false positives
- Continuous credential‑leak scanning across public breach feeds, dark‑web sources, and human‑intelligence networks
- Real‑time alerting via dashboard, email, API, and webhook with severity scoring and remediation guidance
- RESTful API and SIEM integration for automated ticketing, orchestration, and compliance evidence collection
- Support for multiple regulatory frameworks (SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR, NIST) with exportable audit reports
- Scalable pricing model based on per‑test execution and per‑credential‑monitoring volume, enabling cost‑effective usage for large enterprises