Why Arcseer

Continuous penetration testing for an attack surface that never stops moving.

Arcseer was not built in a boardroom. It grew out of a shared conviction, held by a group of offensive security specialists who had spent years on the front line of enterprise security — and who believed AI was about to change the nature of penetration testing entirely. Our starting point was simple: continuous penetration testing had always been the right destination, and the industry had never quite been able to reach it. Traditional penetration testing gave organisations a snapshot, and the attack surface it described had usually moved before the report was even read.

Not whether testing happened. How often.

For as long as any of us had worked in the industry, there was broad agreement on where the discipline needed to go. The point-in-time model — a test scoped, run and reported once or twice a year — never matched the way modern applications and infrastructure actually behave. Code ships daily. Attack surfaces move constantly. A point-in-time penetration test is accurate on the day it is delivered and begins to decay the moment after. Periodic pentesting could confirm your security posture on a Tuesday in March; it could say nothing about the exposure introduced that Thursday.

The direction of travel was never seriously in dispute: security testing needed to become continuous, shifting from occasional pen tests to ongoing testing that kept pace with change.

The obstacle was never conviction. It was economics. Continuous testing done properly meant something close to continuous access to a trained and experienced penetration tester — and no tool had ever come close to that. Scanners could run around the clock, but scanning is not testing. Automated security measures could cover breadth, but not the judgement, the chaining of small weaknesses into real attack paths, or the instinct for which potential vulnerabilities are genuinely exploitable.

So for years, continuous pentesting remained the right answer almost no one could afford to deliver. Through 2023 and into 2024, we watched large language models develop with the particular attention of people who understood both their potential and their limits — waiting to see whether capability and economics would reach the point where real offensive security testing could be done properly, and often enough to be called continuous. For most of that period, the honest answer was no. By early 2025, that had changed.

Depth and Cadence: Where Continuous Pen Testing Sits

Depth and cadence quadrant for penetration testing A minimalist quadrant showing periodic vulnerability scanning, annual penetration testing, continuous scanning and ASM tools, and Arcseer continuous penetration testing highlighted in the upper-right. point-in-time continuous real testing — depth scanning — breadth Annual / periodic penetration testing Periodic vulnerability scanning Continuous scanning & ASM tools Continuous penetration testing ARCSEER

The economics that had held continuous testing back for a decade were finally giving way.

The Tipping Point

From too expensive
to irresistible.

The early cost of LLM-powered AI made serious, production-grade penetration testing effectively prohibitive. Running assessments of real depth, at the token volumes required, was not a viable commercial proposition — and running them repeatedly, as continuous pentesting demands, was further still out of reach. We were not willing to build something that only worked on paper, or only worked once.

What changed the calculation was not a single breakthrough but a compounding of several. Model capability improved exponentially while inference costs fell substantially. Reasoning quality — the ability to work through a multi-step problem with the structured logic offensive work demands — crossed the threshold where testing, not just scanning, became tractable for a machine. And as the cost of each assessment fell, something more important followed: repetition became affordable. A pen test you can justify only once a year is a point-in-time test; a pen test you can justify running whenever the estate changes is the beginning of a continuous one.

Initial experiments moved us from interested to genuinely excited — not because the technology was perfect, it was not, but because the direction was clear, and we began a serious development effort.

The Development Journey

What continuous penetration
testing actually means.

It is easy to say continuous. It is much harder to mean it. Plenty of tools claim the word by running a scanner on a schedule — but a schedule of shallow checks is not continuous pen testing, it is continuous scanning, and the industry already knew the difference. If the word was going to mean anything, what repeated had to be a real test: the depth, reasoning and adversarial intent of a skilled human tester, re-run as the target changed rather than as the calendar turned.

That set the engineering problem. Building an AI-driven penetration testing capability a senior professional would trust — again and again, without losing depth — meant solving interconnected problems that do not yield to off-the-shelf answers. Multi-agent architectures let us decompose an assessment into parallel workstreams, running reconnaissance, exploitation and analysis together rather than in sequence, so coverage of the attack surface stayed broad without going shallow. Budget-managed assessment design let us control the scope and depth of each engagement with the precision enterprise work requires — the same control that makes it viable to test repeatedly. MCP adoption and tool access let the agents interact with real applications and infrastructure in the ways that matter, and memory techniques held coherent context across long assessments and across the repeated assessments continuous attack surface testing produces.

We also watched, at close range, the rise of what the industry came to call AI slop — the flood of low-quality, unverified, hallucination-prone output AI tooling was producing elsewhere. Bug bounty programmes were overwhelmed with automated noise. Reports were filed that had never been validated. Findings that looked real in a summary fell apart under scrutiny. This matters doubly for anything claiming to be continuous: a point-in-time test that is wrong is a bad report; a continuous stream that is wrong is a permanent source of noise. Cadence multiplies whatever it repeats.

So hallucination management became one of our core technical concerns. An AI system that invents vulnerabilities is worse than useless — it actively erodes the trust security assurance depends on. Our approach requires that every finding — critical vulnerabilities, exploitable vulnerabilities, and the attack paths that connect them — be grounded in evidence that can be traced, reproduced and reviewed. If it cannot be verified, it does not make the report. Whatever we built had to produce results that were verified, reproducible and defensible under expert review, every time it ran. That was not a marketing position; it was the precondition for using the word continuous honestly.

We believe the best offensive security work in the coming years will come from teams that know how to work with AI — not teams replaced by it.

Multi-agent assessment: parallel, not sequential

Multi-agent assessment: parallel, not sequential A minimalist Arcseer diagram showing one orchestrator branching into four specialist agents that run in parallel, then reconverge into verified findings. Orchestrator budget-managed scope Verified findings traceable · reproducible Reconnaissance Exploitation Analysis Validation ALL AGENTS RUN CONCURRENTLY

Automation handles the volume and velocity. Humans handle the judgement.

Our Philosophy

Human judgement
at machine cadence.

We had the technical ambition to build a fully automated platform. We chose not to take humans out of the process — and that is not a compromise, it is what lets continuous testing stay meaningful. The value of experienced offensive security professionals does not disappear when AI can automate reconnaissance or chain exploits at scale. It concentrates. Contextual judgement, pattern recognition built across hundreds of real engagements, the ability to tell when an anomaly is interesting rather than merely anomalous — these become more valuable in a continuous workflow, not less.

When tests run often, the human question is no longer only "is this finding real?" but "what has actually changed, and does it matter?" So our model keeps qualified security professionals present throughout: in review, supervision, the interpretation of complex findings, and direct contribution when an engagement calls for it. Continuous penetration testing, defined properly, is the depth of manual testing delivered at machine cadence — and it is the combination, not either half alone, that produces something worth relying on.

The Moment of Conviction

Why point-in-time testing
stopped being enough.

Internal excitement became commercial conviction as the evidence accumulated: continuous testing answered a problem CISOs were already living with — one that point-in-time penetration testing was structurally unable to solve. Attack surfaces expand faster than teams can test them. Releases are frequent; exposure appears between tests, not politely on the day one is scheduled. Effective attack surface management was becoming impossible on an annual cycle — a single snapshot measures a moving system at one instant and reports a result that is already ageing. The gap between the last test and the current reality is exactly where risk accumulates.

The benefits of continuous coverage follow directly. Regulatory demands are rising, and the skills market cannot fill the gap between what is needed and what is available. What we had built closed that gap in a way we could defend — technically, operationally and commercially. Arcseer was born from that conviction: to bring this research to market as an AI penetration testing platform, supervised by offensive security specialists, built to keep testing in step with estates that never stop changing.

Our Mission

Testing that tracks change, not the calendar.

Our mission is to provide an automated penetration testing platform — supervised by offensive security specialists — that keeps pace with the real-world challenge of defending complex estates, while supporting the compliance requirements enterprise and regulated clients must meet. That means treating testing as a proactive security measure rather than an annual audit: a proactive security posture built on evidence that stays current, not a snapshot that decays.

In practice, continuous means something specific. Not a scanner left running, but genuine penetration testing whose cadence is set by the estate itself — assessment that repeats as the attack surface changes, re-tests where material change occurs, and keeps coverage current across web application and infrastructure alike. It means findings that are verified and reproducible every time, outputs a board, auditor or regulator can engage with, and a scale and cost that make continuous a viable operational choice rather than an aspirational one. We are not trying to replace the security profession; we are trying to give it better tools.

What Comes Next

Continuous is a direction,
not a destination.

We do not believe we have finished building Arcseer — we believe we have started. Our research surfaces new capabilities with remarkable regularity, and much of it is aimed at the same goal: tightening the cadence, widening the range of attack scenarios a single assessment can explore, and shortening the distance between a change in the estate and the test that catches it. As AI reshapes offensive security practices, the practitioners who understand both domains — offensive security and AI capability — are among the most valuable people in the industry, and we have built a team around that intersection.

The threat landscape will keep evolving. Attacker tooling will keep incorporating AI. The demands on defenders will keep growing — and testing that happens once or twice a year will keep falling behind them. Genuine resilience against cyber threats depends on security practices that move at the speed of the estate they protect. We are building a platform designed to move with that landscape, at the cadence it actually moves at.

We believe AI's greatest impact on offensive security is not yet visible. We intend to be part of making it so.

See what we have built

Want to see what
we have built?

Request a Proof of Value engagement or speak with our team.