Find what's vulnerable.
Prove what's real.
Autonomous agents find, reproduce and explain real security risks, then gate every result behind a working proof of concept, so you get verified findings, not a list of maybes.
Free instant peek, no sign-up needed. Create a free account for the full report, or get the free desktop app.
- Reproduced against the real target, not assumed
- A working proof of concept with every finding
- Built for compliance, not just testing
Scanners give you findings. You want proof.
Most security tools stop at the list. Ryvx keeps going until each item is either proven real or thrown out.
A list, not a verdict
A scanner tells you something might be wrong. It doesn't tell you whether it actually is.
Someone still has to check it
Every flagged issue needs a person to verify it by hand before anyone can act on it.
Compliance wants evidence
An insurer or auditor asks for proof, not a list of things that might be a problem.
No proof, no priority
Without a working proof of concept, you're guessing at what to fix first.
A finding without proof isn't a finding.
Every result runs through the same gate before it reaches a report: reproduce it against the real target and attach a working proof of concept, or it's discarded. Nothing is filed on a guess.
This is also why some results never make it: see below for the real run where two of ten came back and didn't survive this exact check.
Security testing for every stage.
Four different reasons people come to Ryvx, four products built for each one, not one tool wearing four names.
Ryvx Compliance
Prove your website is secure. In plain English, every two weeks.
- Thirteen automated checks, twice a month, including every script on your payment page
- A dated one-page certificate you can send to an insurer or payment provider
- An email the day your checkout page changes
Ryvx Compliance is not a PCI Approved Scanning Vendor and does not issue compliance certification.
Learn more →Ryvx Strike
Autonomous penetration testing with proof attached.
- Agents map the attack surface, then test and exploit what they find
- Nothing is filed without a working proof of concept
- CVSS scored, CWE tagged, exported as SARIF, PDF or Markdown
Ryvx Agent
Red-team your AI before someone else does.
- Eleven attack categories run live against your agent
- Mapped to the OWASP LLM Top 10, with the two unreachable risks stated as gaps
- A coverage report, not just a list of findings
Ryvx Forge
Take a binary apart.
- Static triage, symbolic solving, decompilation
- Runs inside an isolated VM, not a container
- Free in the desktop app and CLI
Verified. Not just detected.
Ten findings came back. Two didn't survive the check.
On 2026-09-14 we ran an unattended pentest of ryvx.dev, human approval gate switched off, and read every finding by hand against the real target before any of it went on this page.
This isn't here to say we're secure. It's here to show what checking looks like: ten findings came in, eight held up, two didn't, and below is exactly what we did about the eight that were real.
SQL injection auth bypass
/rest/user/login (email field) · CWE-89
Filed with a working proof of concept attached, or it doesn't get filed: the same gate every Ryvx finding runs through.
See the full record, PoC and audit trail →Seven of eight, one shared cause
All seven were the same problem, in four shapes: software reaching you with nothing to prove it came from us.
- An installer that shipped unsigned
- The CLI, installed from a raw URL with no hash to check it against
- The scan sandbox, pinned to a mutable :latest tag
- A guest image, documented as verified against a manifest that didn't exist
MEDIUMthe eighth, a separate and unrelated finding.
- A login endpoint that doesn't exist. A made-up sibling path returned the identical 401 the real one does.
- A route the signup form never calls. The real one returns 202 and works.
Nothing here is softened for the story. A finding either holds up against the real target, or it's in this list instead of the one above it.
Five fixed. Three open.
- Signing copy corrected
- Real SHA-256 digests published, with the commands to check them
- A hash-pinned CLI install documented
- Digest pinning documented for the sandbox image
- The dead guest-image download removed, instead of quietly 404ing
- A code-signing certificate needs buying
- A macOS build needs shipping
- A decision needed on a second publishing identity for the downloads repo
POST https://<hallucinated-domain>/login/
out of scope, that domain is not in this run's scopeOne of eleven refusals in that run. The approval gate was off. The scope guard wasn't.
One engine. Four products built on top of it.
Every product runs the same pipeline: recon and OSINT, then hunting for weaknesses, then a proof-of-concept gate that rejects anything it cannot back up, then deterministic CVSS scoring, then a report. Compliance, Strike, Agent and Forge are four surfaces over that one pipeline, not four separate codebases.
See the full technical detail →How Ryvx keeps your site safe
- We only test sites you've proved you control.
- Nothing is switched on that could break your site unless you say so.
- Every result comes with proof you can check yourself, not just our word.
- A domain-control check runs before any scan touches a live target.
- Checks are read-only by default. Strike's exploitation testing is a separate, explicit opt-in per scan, never on by default.
- Government and public-sector sites are refused outright, whatever the account asks for.
- Data handling is covered in full on our privacy page.
- Verification is a domain-control challenge over HTTPS, using a file placed on the target, checked before any live test and enforced separately for every target.
- Any finding without a working proof of concept is rejected outright. Nothing is reported on a guess.
- Any exploit attempt against a target marked production needs a live human's approval first, and is refused, never left waiting, if nobody is available to approve it.
One full, untruncated run scored 8 of 8 on OWASP Juice Shop's own scoreboard, graded by the target, not by our report.
See the run, the exclusions and what we withdrew →Need something built? We take on custom software, AI automation and security work too.
See our servicesStart with a free check.
The desktop app and the CLI are free forever, and the CLI needs no account at all. Hosted runs, on any of the four products, run on credits, and a hosted account starts with zero. The one free hosted thing is a read-only health check of a website you own, once a month.