Brutor

/ AI pentester · web security

Your AI pentester,
always on.

Brutor is an AI pentester that scans your live website around the clock — exactly like a real attacker would — so you find what's exposed before they do. Zero access to your code, repos, or internal systems.

See pricing
  • No code access
  • No repo connection
  • No agents
  • Just a domain
brutor / external scanlive
$ brutor scan acme.com

[scan] enumerating subdomains ...... 17 found
[scan] resolving dns ............... ok
[scan] probing external endpoints .. 2,481 found
[scan] checking liveness ........... 16/17 alive
[----] tls 1.3 ..................... ok
[----] security headers ............ ok
[warn] expired cert @ legacy.acme... medium
[warn] exposed staging.acme.com .... high
[CRIT] dangling cname → s3-bucket .. takeover
[CRIT] admin panel indexed by goog . critical

4 findings · 0 internal access used · view report →

Sample output. Scans run continuously in the background. No code or repo access required.

/ The problem

Your real attack surface lives outside your firewall.

Most security tools live inside your perimeter. Attackers don't. The things that get sites breached the fastest — dangling DNS, forgotten staging environments, exposed admin panels — are all visible from the public internet and invisible to internal scans.

[01]

Dangling DNS records

Forgotten CNAMEs pointing at deprovisioned services become subdomain-takeover targets in under an hour. You don't see them. Attackers do.

[02]

Hidden public surface

Old staging boxes, leaked admin panels, exposed APIs, abandoned subdomains — the assets you forgot existed are still indexed and reachable.

[03]

Internal tests can't see this

Pentests of your codebase miss what's only visible from the outside. Real attackers don't get a code tour — they get a domain. So do we.

/ How it works

Four steps. Zero internal access.

Every Brutor scan runs from the outside in. We never see your code, your repository, or anything behind your login.

  1. 01

    Enter your domain

    Add a root domain. We discover every reachable subdomain automatically. No agents, no DNS records, no GitHub connection.

  2. 02

    We scan externally

    Brutor probes your live site exactly like a real attacker would — from the outside, with zero access to your code or infrastructure.

  3. 03

    Get clear reports

    Every finding ships with severity, a clear explanation, and proof. Email and Slack alerts when something new appears.

  4. 04

    Fix with guidance

    Each issue includes step-by-step remediation written for humans. We re-test automatically and confirm when it's fixed.

/ What you get

Everything an attacker would test. Nothing they wouldn't.

Every plan includes the full black-box toolkit — no upsells, no locked features. Works on WordPress, Shopify, custom stacks, and anything else that answers on port 443.

[01]

Brutor DNS Guard

Continuously watches every subdomain for orphaned CNAMEs and dangling records that lead to subdomain takeovers.

[02]

Brutor AI Vulnerability Scanner

Active black-box testing of your live site: injection, auth, misconfiguration, exposure, headers, TLS, and more.

[03]

Brutor Uptime Monitor

Multi-region uptime monitoring with response-code and content checks. Know the moment something breaks.

[04]

Brutor AI Reports

Findings translated by AI into reports anyone on your team, or your client, can actually read and act on.

[05]

Brutor Alerts

Continuous re-scans on a schedule, with email and Slack notifications the moment a new issue, takeover, or outage appears.

[06]

Brutor Quick Start

Type a domain, hit scan. No installation, no DNS verification dance, no devops ticket. Brutor starts scanning the moment you sign up.

/ Always on

Security isn't a snapshot. It's a feed.

A one-time scan is stale the day after you run it. Brutor scans on a schedule — weekly on Pro, daily on Agency — so your coverage keeps pace with new threats and every change you ship.

[01]

Always-on attack surface

Your live surface is re-tested against newly disclosed CVEs and emerging threats on every scheduled scan — new exposures get flagged the moment they appear.

[02]

Runtime-validated findings

Every finding ships with a working proof-of-concept and clear reproduction steps, proven against your live environment. No theoretical noise, no false-positive chasing.

[03]

Context-aware testing

Brutor's AI maps your stack, structure, and behavior from the outside and tailors each test to what your site actually exposes — never a generic checklist.

[04]

Every scan builds on the last

Brutor remembers past findings and the fixes you shipped, so each scan picks up where the last left off — confirming remediations and catching regressions.

/ Why black-box only

We don't want your code.
And we never will.

Most scanners ask for repository access, agent installs, or cloud credentials. Brutor doesn't — by design. Less access for us means less risk for you and your clients.

Zero internal access · zero data shared
  • No code access. Ever.

    Brutor never asks for your source code, your GitHub, or your repository. We have no integrations that touch your codebase.

  • No infrastructure access.

    We don't connect to your servers, cloud accounts, CI/CD, or admin panels. Nothing inside your perimeter is touched.

  • Safe for client websites.

    Agencies can scan client sites without ever asking for sensitive access. Just point us at the domain you already manage.

  • Sees exactly what attackers see.

    Because we operate from the public internet — like an attacker — every finding is something a real adversary could find too.

/ Safe by design

Safe to run on production. By default.

Every default scan is 100% passive and read-only. Brutor watches like an attacker would, but never tampers — so you can point it at live client sites and revenue-generating production without a second thought.

[01]

Passive & read-only

By default, Brutor only observes. We don't submit forms, brute-force logins, or touch state-changing routes — nothing that could alter your data.

[02]

Non-destructive by design

When we confirm a vulnerability is real, we prove exploitability without changing data or affecting availability. Every request is rate-limited.

[03]

Your data stays yours

We never store or expose sensitive data we come across. Findings tell you where the issue is, never leak what sits behind it.

[04]

Production-safe

Built to run against live, revenue-generating sites. No downtime, no data loss, no surprise traffic spikes — point us at production with confidence.

/ FAQ

Common questions.

Still curious? Get in touch. We reply fast, without the security-speak.

  • What is an AI pentester?

    An AI pentester is an autonomous agent that performs penetration testing the way a human ethical hacker would — probing your live website for vulnerabilities, then proving and explaining what it finds. Brutor is an AI pentester that runs continuously from the outside, so your attack surface is tested around the clock instead of once a year.

  • Does Brutor need access to my code, GitHub, or hosting?

    No. Brutor is 100% black-box. We only need a domain. We never request, store, or accept access to your source code, repositories, cloud accounts, servers, or admin panels.

  • Is it safe to scan my clients' websites?

    Yes. Because we only operate from the outside, scanning a client site is no more invasive than a search engine visiting it. You don't need to ask the client for any credentials or internal access.

  • What does Brutor actually find?

    Dangling DNS records, subdomain takeovers, exposed admin panels, common web vulnerabilities, TLS and header misconfigurations, leaked staging environments, and downtime. Anything visible to an attacker on the public internet.

  • How often do scans run?

    The Pro plan receives weekly scans. The Agency plan receives daily scans. Every plan re-tests fixed issues automatically and alerts you the moment something new appears.

  • Will scans slow down or break my website?

    No. Default scans are passive and read-only — we don't submit forms, brute-force endpoints, or touch state-changing routes. Everything is rate-limited and non-destructive, so it's safe to run against production without affecting data or availability.

  • Can I cancel anytime?

    Yes. Both plans are month-to-month with no contract. Cancel from the dashboard in one click. Annual plans are refunded pro-rata for unused months.

Scanner online · ready

Protect your business.
Before attackers find the gap.

Point Brutor at a domain. We start scanning immediately and ping you the moment something appears. No card, no code, no install.

Or see pricing