About Ryvx
Autonomous AI penetration testing
Ryvx runs autonomous LLM agents that recon a target, hunt for vulnerabilities, validate each one with a working proof-of-concept, CVSS-score it, and suggest a concrete code fix: for source code, local apps, live URLs you're authorised to test, or a whole bug bounty programme's scope.
The actual bet isn't "more autonomous than the next tool." It's three things held together: every finding is gated behind a working exploit, not an unconfirmed suspicion; exploitation against a production-tagged target pauses for a live human unless that specific scan was submitted with auto-approve explicitly turned on, which is recorded against the scan itself, not granted by any package; and every tool call any agent makes is written to an append-only audit log, so a scan's actions can be defended after the fact.
What it refuses to do
Two rules don't bend.
The tool that files findings hard-rejects anything without a working proof-of-concept ("PoC or it didn't happen"), though what that PoC proves depends on whether the scan had a live target to test against (see Verification).
Either a human says yes in the moment, or the scan was submitted with auto-approve turned on up front, a choice recorded against the scan row itself, never a default any plan grants. Neither approval present, run non-interactively: it auto-denies rather than silently proceeding or hanging.
Where it came from
Ryvx started as research into existing open-source agentic pentesters, and the core architecture (a root orchestrator that never touches the target itself, a subagent graph that does the actual work, PoC-gated reporting, CVSS scoring) follows the shape that work established. Everything past that point is Ryvx's own: the human approval gate, the audit trail, cost budgeting, bug bounty scope mode, and the dashboard.
What's proven, and what only compiles
A tool built around "PoC or it didn't happen" should hold its own claims to the same standard, so we publish what we haven't verified as readily as what we have. A capability audit checks every area against the actual code rather than the plan: most modules pass their own self-check and the automated smoke suite is green, but "passes its tests" and "has worked for a real user" are different claims.
Ticket-tracker integrations
Finished and tested, never run against a real ticket tracker yet.
RE auto-solve tier
One of the three reverse-engineering tiers, finished and tested, never run against a real sample yet.
Bug bounty scope mode
Finished and tested, never run against a real bounty programme yet.
Hosted/billing path
A step ahead of the three above: one scan has gone through it end to end and been charged exactly its posted price, but that was our own test, not a paying customer's.
The clearest example: we published benchmark recall numbers against known vulnerable apps, then withdrew them. An internal audit found every run behind those numbers had been cut short before its agents finished investigating, so the scores were floors, not measurements. And in at least one case, the credited and missed findings didn't even match what that run had actually produced. They stayed withdrawn until a complete, untruncated run existed. One now does, and the published figure comes from that run's own artifacts, with the runs we excluded and the claims we still can't make listed beside it.
Contact
Questions about the product: support@ryvx.dev