Kissaki Docs

What is Kissaki

Agentic web and API pentesting that proves every finding, EU-hosted and audit-ready.

Kissaki is an agentic web and API pentesting platform. You point it at an asset (a repository, domain, container image, cloud account or host), prove you own it, and bounded AI agents run a campaign using deterministic open-source tools. The result is a set of proven, deduplicated findings correlated to your code, with a draft fix and a report.

How it works, in one breath

  1. Add an asset and prove you own it (ownership verification).
  2. Kissaki runs a scan (a connector pass) or an agentic campaign.
  3. Connectors emit raw results; Kissaki normalises them into findings.
  4. Every high or critical exploitation finding carries reproducible proof; deterministic detections (SCA, secrets, misconfig, licences) are the proof themselves.
  5. You read, triage and export - and optionally gate pull requests on the verdict.

What makes it different

  • The OSS tools do the work; the LLM decides and interprets. Model calls are minimised and only ever go through a single EU-resident router.
  • Proof-driven. No HIGH or CRITICAL exploitation finding is handed over without a reproducible proof of exploit.
  • Hard guardrails. Nothing is scanned outside an authorised perimeter: ownership proof, rules of engagement, scope-lock, non-destructive by default, a kill-switch, and a full audit trail.

Where to go next

On this page