Jul 28, 2026
Enterprise

Bugcrowd Savant Pathseeker launches for continuous agentic pentesting

Bugcrowd’s new agentic pentesting tool tests web apps and APIs continuously, with early access open and general availability planned later this year.

Dominic Okoye

By Dominic Okoye · Staff Writer

· 3 min read

Bugcrowd launched Bugcrowd Savant Pathseeker on Tuesday, an agentic penetration testing product for continuously probing external web applications and APIs. The company is positioning the tool as the first product in a new Agentic Offensive Testing line, combining automated testing with access to Bugcrowd’s human pentester community.

The launch puts Bugcrowd deeper into a security category where vendors are trying to move pentesting from scheduled projects to ongoing coverage. Pricing was not disclosed. The product is available through an early access program, with general availability planned later this year, according to the company.

What is Bugcrowd Savant Pathseeker?

Bugcrowd Savant Pathseeker is a continuous testing tool that uses purpose-built agents to look for exploitable vulnerabilities in external-facing applications and APIs. The company says each finding includes reproducible proof that the issue can be exploited, rather than leaving security teams with raw scanner alerts to verify manually.

Bugcrowd’s pitch is aimed at a familiar operational gap. Manual pentests can provide depth, but they happen periodically. Automated scanners can cover more assets, but they often produce findings that require triage before teams know whether they represent real risk. Bugcrowd says Pathseeker is meant to sit between those approaches by testing continuously and validating issues before they reach customers.

The company said the product includes audit-ready reporting for security teams, auditors and regulators. It also includes scope controls, built-in guardrails and a manual kill switch intended to keep testing within boundaries defined by the customer.

How Bugcrowd ties automation to human researchers

Bugcrowd is not presenting Pathseeker as a replacement for its researcher network. The company says the agents are meant to provide baseline, continuous coverage, while human testers handle work that automated systems tend to miss, including business logic flaws, chained exploits and zero-day vulnerabilities.

Customers can use Pathseeker alongside Bugcrowd’s existing services, including penetration testing as a service, bug bounty programs, vulnerability disclosure programs, red team as a service and attack surface monitoring. Bugcrowd says customers can escalate systems that need deeper review to human researchers within the same platform.

Braden Russell, Bugcrowd’s chief technology officer, said in the company’s announcement that the product was designed with customers around the role of human expertise, bringing agentic discovery, testing and validation into one workflow.

The company also said it does not use customer data or researcher data to train or tune the models behind Pathseeker. Bugcrowd says the product runs on frontier AI models and adds a proprietary skills layer developed by its in-house practitioners. It did not name the model providers.

Why agentic pentesting is drawing attention

Bugcrowd’s broader Savant effort is meant to combine autonomous testing, human-led engagements and attack surface visibility into a single view of exploitable risk. The company is entering a market where “agentic” security claims need scrutiny, because speed alone does not solve the validation and prioritization problem for security teams.

Chris Steffen, vice president of research at Enterprise Management Associates Inc., said in Bugcrowd’s announcement that security teams are caught between infrequent manual pentests and noisy scanners. He said the key test for agentic pentesting tools will be how well vendors combine machine speed with human judgment.

This story draws on original reporting from SiliconANGLE.

More from Enterprise

All Enterprise →