Uvy provides AI-native penetration testing that automatically attacks web applications and APIs using real‑world adversary techniques, delivering exploitable findings with working exploits and audit‑ready reports within days. The service runs in isolated, single‑use VMs to keep code and data private, and combines standard methodologies like OWASP Top 10 with AI agents that operate in parallel for deeper coverage.
Funding
Funding not disclosed
Founders
Product
Problem
Organizations often rely on annual manual penetration tests that are time‑consuming, costly, and provide limited evidence of exploitable vulnerabilities, leaving applications and APIs exposed to real‑world attacks between testing cycles.
Solution
Uvy delivers an AI‑native penetration testing platform that automates the full pentest workflow—from reconnaissance and surface mapping to exploit generation, validation, and reporting. Specialized AI agents run in parallel within isolated, single‑use VMs, executing OWASP Top 10, IDOR, business‑logic, injection, SSRF, and custom risk checks against your code (white‑box) or live endpoints (black‑box). Each candidate finding is re‑tested and confirmed with a working proof‑of‑exploit, ensuring only truly exploitable issues appear in the final output. The platform produces an audit‑ready report with severity ratings, impact analysis, reproducible steps, and precise remediation guidance, formatted for executives, engineers, and auditors. By leveraging open‑source models locally and invoking frontier models only for complex judgments, Uvy keeps costs flat and enables continuous retesting on every release.
Target Audience
Primary customers are software development teams, security engineers, and compliance officers at SaaS companies and enterprises that need fast, reliable penetration testing for web applications and APIs.
Features
- Parallel AI agents perform comprehensive OWASP Top 10, IDOR, broken auth, business‑logic, injection, SSRF, XSS, and custom risk testing
- Isolated, single‑use VM execution with strict scope enforcement; no code or data leaves the environment
- Automated discovery using white‑box code analysis or black‑box probing to map routes, parameters, roles, and auth boundaries
- Exploit generation and chaining by AI agents, followed by independent re‑testing to produce verified proof‑of‑exploit for each finding
- Audit‑ready reports containing severity, business impact, reproducible steps, root‑cause remediation, and evidence bundles for SOC 2/ISO 27001 compliance
- Continuous testing option that automatically retests on every deployment, providing trend and regression tracking
- Flat‑rate pricing model with included retests for 30 days and no additional cost for ongoing verification