How it works Scope & safety Findings Review desk Pricing Blog Book a demo

Proof,
not alerts.

AI agents test your web apps, APIs, cloud and smart contracts on a schedule you set, and prove every finding with a proof of concept that runs, reproduced twice before it reaches you. On Growth and Scale, a researcher also tests by hand and signs the report.

See plans and pricing

From $349 a month, cancel any time. Or book a 30-minute demo first.

Meet Zaaf.

See a real finding

Zaaf is a team of AI agents that keeps testing what you ship, and a human review desk that refuses to forward anything it can't reproduce twice.

The Zaaf mark stamped in cyan and navy ink on paper

Every finding arrives with the exploit attached

The agent writes the proof of concept, runs it, keeps the full request transcript, then reruns it from a clean state. Two clean reproductions or it never becomes a finding.

Runs while
you ship.

Not a fortnight in October. Passes run on your schedule, inside your rate limits, and retest every fix the evening you deploy it.

The loop

Four surfaces, one desk above them.

Your attack surface laid out as one floor plan. A pass works across it, then carries whatever it proved up to the review desk.

01

Web applications

Signs up, fills the forms, holds fourteen sessions at once and compares what each one is allowed to see.

02

APIs and GraphQL

Walks the endpoints the docs forgot, then asks each one a question it should refuse to answer.

03

Cloud

Follows a role as far as it will go, storage, metadata, keys, and reports the chain, not the checkbox.

04

Web3 and contracts

Forks mainnet state and tries the accounting until a number comes out wrong, with the trace attached.

05

The review desk

A researcher re-runs the proof and signs it. Whatever fails here never reaches your dashboard.

Proved and signed this month.

read-only API key → full account session SSRF → cloud instance metadata cleartext password to an anonymous caller negative quantity zeroes the cart unsigned header picks the mutation subject one validator forges the 67% quorum SSO token leaks across every subdomain anonymous socket join rewrites shared state sub-site admin → network-wide file replace signature check skipped on every chain any session mints store credit unauthenticated database pagination read permission mints a write credential MFA validates the attacker’s own factor share link exposes the workspace roster oracle serving a ten-day-old price payment callback signature never checked session key escalates to super admin path traversal into the export archive unguarded webview → code execution login OTP returned to the caller world-writable root control socket

The same engine we sell is the one we run on public bug bounty programmes. Its record there is graded by strangers: a report is paid only when the security team on the other side reproduces it.

78

findings accepted by the security teams that triaged them

Public programmes, June to September 2026

$30,000+

paid out in bounties for those findings, at banks, unicorns and payment infrastructure

2026, paid by the programmes themselves

2of 2

clean reproductions before anything reaches you, then a researcher signs it

The review desk rule, every finding

Anatomy of a report

What you get

An illustration, we never publish a customer’s report. Every finding arrives as one object: the severity, the narrative, the impact, and a proof of concept you can paste straight into a terminal.

PROOF A runnable PoC with the full request and response transcript
SIGNED The researcher who re-ran it, by name, so you can ask them why
RETEST Ship the fix and the agent verifies it on the next pass
CRITICAL broken object-level authorisation

A signed-in user reads another tenant's invoices by swapping one id

A typical logic flaw, written the way our reports are written. The agent opens two accounts in separate organisations, generates an invoice in each, then asks for organisation A's invoice while holding organisation B's session. The route answers in full, billing address, line items, totals, because no role check runs on it, and the front end simply never links across tenants.

proof of concept · reproduced 2/2
$ curl -s https://api.example.com/v2/invoices/INV-8841 \
    -H "Authorization: Bearer <ORG_B_SESSION>"

HTTP/2 200
{
  "id": "INV-8841",
  "organization_id": "org_A_9d21",   <-- not the caller's org
  "billing_address": "[redacted]",
  "total_cents": 1284000,
  "line_items": [ ... 9 items ... ]
}

Before anything runs

You draw
the boundary

Agents that test your production systems have to be governed like contractors, not trusted like tools. So the scope is a document you sign, not a checkbox we tick.

A scope, not a licence
to roam

Onboarding is a call and a form. You describe the surface, name the hours, cap the request rate, and say which accounts we may create. Signed once, editable whenever, and the first pass doesn't start until you've said so.

Not a certified pentest, we say so on purpose

The review desk. Somebody's name is on every report.

From the founder

I got tired of reports where nobody had checked whether the bug was real.

I built the first version of this harness for myself, to hunt bounties faster. It worked, it found things I would have found, in an afternoon instead of a fortnight, and a few things I wouldn't have found at all.

Then it started producing volume, and I understood the real problem in this industry. Nobody needs more findings. Everybody needs findings they can believe. So the rule became: prove it twice, or don't tell anyone, and a person signs off before the customer sees it. That rule is slower, and it is the whole product.

, Founder, Zaaf

Questions we actually get

Straight
answers

Something not covered? Write to hello@zaaf.ai and a person answers.

Do I need a security team to use this?

No. Zaaf is built for founders and engineering leads, not CISOs. There's no agent to install and nothing to tune. Point us at your app and you get findings you can act on, each with the proof attached.

Is this the same as a certified penetration test?

No, and we will not pretend otherwise. AI agents run the engagement and a security researcher verifies every finding before it reaches you, so nothing is reported that we could not reproduce. It is not an engagement from an accredited pentest firm. If your buyer's checklist specifically requires a certified pentest, tell us: we will say so plainly instead of letting you hand over the wrong document.

How is this faster than a pentest?

A traditional engagement spends 2–4 weeks on scoping and scheduling before anyone touches your app, because it is waiting on a senior tester's calendar. Ours is waiting on compute, so testing starts once scope is agreed. If you later need a formal manual pentest for compliance, our findings make that engagement shorter and cheaper.

What can you test?

Web applications and the APIs behind them, cloud and infrastructure configuration, smart contracts and the web3 app layer, and connected devices including their firmware and the cloud service they talk to. If your surface is something else, ask, we will tell you plainly whether we can test it rather than take the engagement and find out.

Is a human involved at all?

Yes, on Growth and Scale, and in the Review Pack. On every plan the agent does the automated testing and proves each finding twice, from a clean state, with the evidence attached. Growth and Scale add hands-on expert reviews on a schedule (two a year, or four; twelve on Enterprise), where a security researcher tests by hand, signed in, and signs the report. Starter is the automated tier: exploit-verified monitoring, without the human review.

Isn't running agents against production risky?

That is exactly why scope is a signed document rather than a checkbox. You name the hours, cap the request rate, and say which accounts we may create. The first pass does not start until you have said so, and every pass stays inside those limits.

What happens after I fix something?

The agent retests it on the next pass and the finding closes with the evidence that it is closed. You do not have to book anything or ask for a re-scan.

Is there a contract?

No. Plans are monthly, billed by Paddle, our merchant of record, and you can cancel any month from your account. The Enterprise Review Pack is a one-time purchase and is fully refundable until testing starts.

My deal needs it next week. Can you move that fast?

Usually, yes. Turnaround is measured in days, not weeks, because the testing does not queue behind a person's calendar. Tell us your timeline and we will confirm before you promise anything to your buyer.

Pricing

One price a month.
Nothing per finding.

A vendor paid per bug reports noise. Every plan proves each finding twice, from a clean state, before it reaches you. Growth and Scale add a human review desk on a schedule. No contract: cancel any month.

Starter

$349per month

Automated, exploit-verified monitoring for one product that has to stay review-ready.

StandoutMachines that prove it. A finding reaches you only after a live reproduction, twice, from a clean state, with the request, the response and a screenshot attached.

  • 1 domain, full attack-surface discovery
  • Weekly external passes, surface depth: the high and critical issues an attacker reaches first
  • Every finding exploit-verified and reproduced twice
  • Each fix retested on the next pass
  • PDF dossier and share links, public or password-protected
  • Weekly posture digest; an alert only when a new verified finding appears
  • Support tickets answered by a person
Choose Starter

You sign in first; payment happens inside your account, billed monthly by Paddle, our merchant of record. Cancel any time.

Scale

$2,499per month

The deepest testing, a researcher every quarter, and a person who knows your stack.

StandoutA named researcher, every quarter. 4 hands-on expert reviews a year by the same person, who knows your stack rather than whoever picks up the queue.

  • Everything in Growth, up to 10 domains
  • Daily passes, deep depth: the full template set at every severity
  • 4 hands-on expert reviews a year, one each quarter, signed
  • Rules of engagement per domain: test windows, rate caps, accounts, exclusions, honoured in every review
  • Per-finding evidence download for your auditor
  • Each fix retested on the next pass
  • Weekly posture digest and new-finding alerts
Choose Scale

You sign in first; payment happens inside your account, billed monthly by Paddle, our merchant of record. Cancel any time.

Enterprise

$4,900per month, and up

For a portfolio beyond ten domains, or a buyer with its own rules.

StandoutA researcher every month. 12 hands-on expert reviews a year, a private runner if your policy needs one, and rules of engagement written with your security team.

  • Everything in Scale, domains priced per asset
  • Daily deep passes on every domain
  • 12 hands-on expert reviews a year, one a month, signed
  • Private runner and data-residency options
  • Quarterly review call with your researcher
Talk to us

Scoped and quoted in writing. Invoiced by Paddle, our merchant of record, or by bank transfer.

Enterprise Review Pack

$3,500one-time

For the deal that needs evidence next week, without a subscription.

  • 1 hands-on expert review: a researcher tests one domain by hand, signed in, at deep depth
  • Scope agreed first, and you prove you control the domain before anything runs
  • A dossier your buyer's reviewer can file, with the proof for every finding
  • One retest of your fixes, included
Buy the Review Pack

You sign in first; payment happens inside your account, billed once by Paddle, our merchant of record. Fully refundable until testing starts.

Not sure which fits? Write to us with your domain count and we say which plan, in one reply. Zaaf is not a certified penetration test and holds no compliance certification of its own; if your buyer's checklist requires a certified pentest, we say so before you pay.

Bring us one scope.
We'll show you what's in it.

A 30-minute call: you describe your surface, we run a pass, and we walk through whatever comes back, including the case where the answer is that you're in good shape.

Need to send this to someone else? Share zaaf.ai/book

Not ready for a call

Write it down instead

Tell us what you are shipping and what worries you about it. We scope the review, then quote it. Most teams hear back the same working day, from a person, at a real address.

Or email hello@zaaf.ai