Skip to main content
Comparison · XBOW

B-52 and XBOW overlap on two classes of eleven

XBOW tests web applications and their APIs without a human driving the run, and fires that run from an API at your own release cadence. That is a real engineering capability, and this page concedes it by name before it argues anything. What follows is where the two products part: how many coverage classes one platform carries, whose signature the report ends up under, and what each side publishes a price for. Every statement about XBOW below was read on their own pages on 14 September 2026 and carries that date beside it.

Their published position was last read on 2026-09-14. Every claim below carries the page it came from and the date it was checked.

The divergence

One shared lane, and the two lanes on either side of it

Inside the shared lane — a web application and the APIs behind it, tested without a human driving the run — XBOW is good at this, and the concession block below says so by name and at length before this page argues anything else.

XBOW’s own documentation is where the first divergence is easiest to check, because it is written for people setting up a target rather than for people being sold to: XBOW currently supports testing web applications and their APIs, and support for other target types is on their roadmap. The same reference publishes the conditions under which a target cannot be tested at all — it has to be reachable from the public internet and able to allowlist their addresses, which rules out anything sitting behind a virtual private network or on an internal segment. Those are consequences of running as a multi-tenant service, not defects in it, and this page treats them that way. B-52 carries eleven coverage classes on one platform, and nine of them sit outside that lane. The second divergence is the one the search term arrives for. XBOW publishes a pricing page, in their primary navigation, and it carries no figure: the model is described as usage-based and scoped to your environment, and the two ways off the page are a quote and a demo. B-52 publishes $500 for one scan of one application or one target, and $299 for a paid trial, and takes a card for the five application classes. The one price figure still published on XBOW’s own site sits in a release from November 2025 whose buy link now resolves to their demo form; the figure, the page it is on and the date it was read are all in the table at the foot of this page.

Coverage

Eleven classes, read against the target types XBOW publishes today

Their column is what their documentation says is supported now, not what a marketing page implies. B-52 covers all eleven in all three of its delivery models, and the coverage does not change between them.

Coverage classOn XBOW, as publishedOn B-52
Web application Supported. Their documentation defines a web application as a website with interactive features such as forms, dashboards or user accounts. Covered, including the authenticated flows and the authorisation decisions behind each role, with a credential supplied per role. Reachable from the self-serve flow.
This is the shared lane, and the sentence that defines it was re-read on 2026-09-14 and is unchanged.
API Supported, named in the same sentence as web applications. Covered, and reachable from the self-serve flow.
Mobile application Not published as a supported target type. Their documentation places other target types on a roadmap. Covered, and reachable from the self-serve flow.
Thick client Not published as a supported target type. Covered, and reachable from the self-serve flow.
Secure code review Not published as a supported target type. Covered, and reachable from the self-serve flow.
External network Not published as a supported target type. A target has to be an application or an API reachable from the internet. Covered, with the perimeter worked out from announced ranges, resolving names and what answers on each address, then proposed back to you as the scope.
Internal network Not published as a supported target type, and their documented preconditions exclude targets behind a virtual private network or a blocking network configuration. Covered. This is the one class that needs something deployed inside your network, and on-premise and customer-VPC deployments are both available for it.
Active Directory Not published as a supported target type. Covered, as one class among eleven.
Cloud Not published as a supported target type. Covered.
Social engineering Not published as a supported target type. Covered, and scoped separately from the other classes.
LLM applications Not published as a supported target type. Covered on the platform.
Physical, hardware and wireless Not a question this page checked, and nothing is claimed about it. Out of scope for B-52 entirely, in every class. It is the one exclusion, and it is stated the same way on every page of this site.

Web application

On XBOW, as published
Supported. Their documentation defines a web application as a website with interactive features such as forms, dashboards or user accounts.
On B-52
Covered, including the authenticated flows and the authorisation decisions behind each role, with a credential supplied per role. Reachable from the self-serve flow.

This is the shared lane, and the sentence that defines it was re-read on 2026-09-14 and is unchanged.

API

On XBOW, as published
Supported, named in the same sentence as web applications.
On B-52
Covered, and reachable from the self-serve flow.

Mobile application

On XBOW, as published
Not published as a supported target type. Their documentation places other target types on a roadmap.
On B-52
Covered, and reachable from the self-serve flow.

Thick client

On XBOW, as published
Not published as a supported target type.
On B-52
Covered, and reachable from the self-serve flow.

Secure code review

On XBOW, as published
Not published as a supported target type.
On B-52
Covered, and reachable from the self-serve flow.

External network

On XBOW, as published
Not published as a supported target type. A target has to be an application or an API reachable from the internet.
On B-52
Covered, with the perimeter worked out from announced ranges, resolving names and what answers on each address, then proposed back to you as the scope.

Internal network

On XBOW, as published
Not published as a supported target type, and their documented preconditions exclude targets behind a virtual private network or a blocking network configuration.
On B-52
Covered. This is the one class that needs something deployed inside your network, and on-premise and customer-VPC deployments are both available for it.

Active Directory

On XBOW, as published
Not published as a supported target type.
On B-52
Covered, as one class among eleven.

Cloud

On XBOW, as published
Not published as a supported target type.
On B-52
Covered.

Social engineering

On XBOW, as published
Not published as a supported target type.
On B-52
Covered, and scoped separately from the other classes.

LLM applications

On XBOW, as published
Not published as a supported target type.
On B-52
Covered on the platform.

Physical, hardware and wireless

On XBOW, as published
Not a question this page checked, and nothing is claimed about it.
On B-52
Out of scope for B-52 entirely, in every class. It is the one exclusion, and it is stated the same way on every page of this site.

Three buyers

Where each of them lands, and the one where XBOW has the shorter path

The same two products, read from three different starting positions. One of these goes their way and it is written that way.

01 Has a card

The team that wants one application tested this week

On XBOW
A pricing page that publishes no figure, a model described as usage-based and scoped to your environment, and two ways off the page: request a quote, or get a demo. No sign-up, trial or checkout is published.
On B-52
$500 for one scan of one application or one target, $299 for a paid trial, and a card flow that reaches the five application classes — web, mobile, API, thick client and secure code review.
What it decides
Whether the first thing that happens is a run or a conversation. Anything wider than a single target is a scoping call on our side too, and the ladder above one scan is not published.
02 Has committed cloud spend

The enterprise buying through an agreement it already holds

On XBOW
Listed with Amazon Web Services, Google Cloud, Oracle and Microsoft, with the invitation to buy through agreements you already have and put committed spend to work. The listings are enterprise ones, so it is a private-offer path rather than a checkout — but for a buyer whose constraint is procurement rather than budget, it is short.
On B-52
No equivalent. There is no route to buy B-52 against a cloud commitment you already hold, and a purchase beyond the self-serve tier is a scoping call and a direct agreement.
What it decides
If the obstacle is that spend is already committed elsewhere, XBOW has the shorter path and this page is not going to pretend otherwise.
03 Has to file something

The buyer whose report needs a signature on it

On XBOW
Whose signature a report carries on their side is not a question this page checked. What they publish, and what this page concedes above, is Amazon Web Services Security Competency status in the Application Security distinction, July 2026.
On B-52
Two of the three delivery models — autonomous expert-verified and human-led — produce a report carrying a senior Security Brigade auditor’s verification, and Security Brigade has been CERT-In empanelled since 2008. The fully autonomous model carries the same coverage and the same proof per finding, and no auditor signature.
What it decides
Which delivery model you take, not which classes get tested. Coverage is identical across all three; only the signature differs.

In their own terms

What XBOW publishes, part by part

Their pages, their wording. Where a phrase is theirs it is quoted in the claims table at the foot of this page, with the page it was read on and the date.

PartWhat it is, as published
The platform An autonomous tester that explores applications and APIs the way an attacker would, chains defects into working attacks, proves exploitability for itself, and runs continuously rather than once a year. Their framing of the problem — that risk should be measured every day rather than estimated annually — is the correct critique of annual testing.
Supported target types Web applications and their APIs, with other target types published as roadmap. A target must be reachable from the public internet and able to allowlist their addresses, and end-of-life services, unsupported authentication methods and short fixed session timeouts are published as conditions under which they cannot test.
This sits in their documentation rather than their marketing, and it is the most quotable sentence they publish. Re-read 2026-09-14, unchanged.
Governance Scope the customer defines, production-safe challenges designed to avoid modifying data, non-destructive execution, audit trails, every agent action logged and reviewable, and human review before findings surface.
The public API In public preview since February 2026 and announced in March. Date-versioned, with assessments that can be started, paused, resumed and cancelled, findings retrieved, fix verification triggered, signed webhooks for assessment, finding and asset changes, and a full OpenAPI specification published for code generation.
Pipelines Served by that API rather than by a packaged integration: trigger a pentest on merge or pre-deploy, or from your own scheduler, on your own release cadence. No named pipeline system is published, so the glue is written by the customer.
Product integrations Two are published in their documentation: Jira, for creating work items from findings, and Microsoft, through a Sentinel connector with findings queryable in Security Copilot. Both are labelled public preview by them.
Pricing A page in the primary navigation carrying no figure. Usage-based, scoped to your environment, and converting to a quote or a demo. Procurement is also offered through Amazon Web Services, Google Cloud, Oracle and Microsoft against agreements a customer already holds.
Deployment Cloud only. Multi-tenant, with a United States region by default and a European region in Frankfurt; European data residency is in private preview for enterprise customers, a single-tenant hosted option is published as coming soon, and Singapore as in development. No on-premise or self-hosted option is published.
Track record Ranked number one on HackerOne in June 2025, the first autonomous system ranked on Microsoft’s researcher leaderboard, and a blog documenting named defects in third-party software including Exim, React2Shell, Akamai CloudTest and Palo Alto GlobalProtect.

The platform

What it is, as published
An autonomous tester that explores applications and APIs the way an attacker would, chains defects into working attacks, proves exploitability for itself, and runs continuously rather than once a year. Their framing of the problem — that risk should be measured every day rather than estimated annually — is the correct critique of annual testing.

Supported target types

What it is, as published
Web applications and their APIs, with other target types published as roadmap. A target must be reachable from the public internet and able to allowlist their addresses, and end-of-life services, unsupported authentication methods and short fixed session timeouts are published as conditions under which they cannot test.

This sits in their documentation rather than their marketing, and it is the most quotable sentence they publish. Re-read 2026-09-14, unchanged.

Governance

What it is, as published
Scope the customer defines, production-safe challenges designed to avoid modifying data, non-destructive execution, audit trails, every agent action logged and reviewable, and human review before findings surface.

The public API

What it is, as published
In public preview since February 2026 and announced in March. Date-versioned, with assessments that can be started, paused, resumed and cancelled, findings retrieved, fix verification triggered, signed webhooks for assessment, finding and asset changes, and a full OpenAPI specification published for code generation.

Pipelines

What it is, as published
Served by that API rather than by a packaged integration: trigger a pentest on merge or pre-deploy, or from your own scheduler, on your own release cadence. No named pipeline system is published, so the glue is written by the customer.

Product integrations

What it is, as published
Two are published in their documentation: Jira, for creating work items from findings, and Microsoft, through a Sentinel connector with findings queryable in Security Copilot. Both are labelled public preview by them.

Pricing

What it is, as published
A page in the primary navigation carrying no figure. Usage-based, scoped to your environment, and converting to a quote or a demo. Procurement is also offered through Amazon Web Services, Google Cloud, Oracle and Microsoft against agreements a customer already holds.

Deployment

What it is, as published
Cloud only. Multi-tenant, with a United States region by default and a European region in Frankfurt; European data residency is in private preview for enterprise customers, a single-tenant hosted option is published as coming soon, and Singapore as in development. No on-premise or self-hosted option is published.

Track record

What it is, as published
Ranked number one on HackerOne in June 2025, the first autonomous system ranked on Microsoft’s researcher leaderboard, and a blog documenting named defects in third-party software including Exim, React2Shell, Akamai CloudTest and Palo Alto GlobalProtect.

Reading their site

The one thing we checked twice, because it is easy to get wrong

It is the route that used to sell a self-serve pentest. Fetching it is misleading: the page renders, it looks like live content, and what has actually happened is a server-side redirect to their demo form. It was confirmed here at the protocol level rather than by appearance, and the neighbouring routes return 404. That is the whole of what this page says about it. The offering was real, it was announced, and what they publish today is a quote and a demo — describing that as anything more than a change of route would be us editorialising on somebody else’s roadmap.

Conceded, first

XBOW’s API is the real thing, and so is proving the exploit

Two concessions before any point of difference, because both go to the centre of what B-52 is for and a reader who has used XBOW will know if we skip them.

XBOW publishes a date-versioned REST API that starts, pauses, resumes and cancels an assessment, retrieves findings, triggers a fix verification, and pushes signed webhooks when an assessment, a finding or an asset changes, with a full OpenAPI specification published so a client can be generated rather than hand-written. It went into public preview in February 2026 and versions have been shipped through August. That is not a marketing bullet with an endpoint behind it; it is a built interface, and a team that wants a pentest to fire on merge or before a deploy can write that glue against it today. They built it well. The second concession is the model itself. XBOW aims to chain defects into a working attack and prove exploitability independently, so what reaches the queue is a demonstrated attack rather than a list of things that might be true. That is the right thing to aim at, and it is the difference between a finding a developer can act on and a candidate somebody has to spend a morning disproving.

Also conceded

Six more, including two things XBOW does that we do not do at all

Each was read on their own pages on 14 September 2026. The table at the foot of this page records which page, and what it said.

Track record

Evidence on scoreboards nobody controls

Ranked number one on HackerOne in June 2025, the first autonomous system ranked on Microsoft’s researcher leaderboard, and a public blog of specific named defects in real third-party software — Exim, React2Shell, Akamai CloudTest, Palo Alto GlobalProtect. That evidence sits on scoreboards they do not run and in software they do not own, so it is checkable by anybody, and waving it away would be the least credible thing this page could do.

Governance

An autonomous agent built for production

Customer-defined scope, production-safe challenges designed to avoid modifying data, non-destructive execution, audit trails, every agent action logged and reviewable, and human review before a finding surfaces. Shipping an autonomous attacker into enterprise production is the hard part of this problem and XBOW has addressed it explicitly, so nothing on this page implies their runs are reckless.

Fan-out

Parallel breadth across a sprawling portfolio

Agents attacking in parallel across an estate of applications that arrived by acquisition or by time, at a fan-out their platform page describes and human-led delivery is genuinely hard pressed to match. For an organisation whose problem is the number of web properties rather than the depth of any one of them, that is the strongest thing they have.

Procurement

Buying through an agreement you already hold

Listed with Amazon Web Services, Google Cloud, Oracle and Microsoft, so committed spend can be put to work rather than a new agreement negotiated — plus Amazon Web Services Security Competency status in July 2026, in the Application Security distinction. We have no equivalent to either.

Turnaround

A stated delivery commitment, in writing

Their November 2025 announcement published complete, expert-level pentest results within five business days. That is a firm operational commitment, in writing, and it is the turnaround a buyer will hold us to as well.

Capital and reach

Not a thin startup, and a comparison that treats them as one will not be believed

A raise in March 2026 at a valuation their newsroom publishes, a further round in May from strategic investors including Accenture Ventures, Samsung and SentinelOne, an embed into the Microsoft security ecosystem, a Sentinel connector, a Samsung SDS cooperation and a general manager for South Korea. Those investors are distribution as much as capital. The figures are in the claims table.

What each side can show

Six questions a buyer asks at this stage, answered in both directions

Including the ones where the honest answer is that we have nothing to show. Their column is sourced in the claims table below; ours is what this site publishes everywhere else.

The questionXBOWB-52
Third-party validation of the testing platform Amazon Web Services granted Security Competency status in July 2026, in the Application Security distinction, and XBOW joined the AWS ISV Accelerate Program in May 2026. Nothing at platform level. Security Brigade has been CERT-In empanelled since 2008 and is ISO 27001 certified.
Evidence of finding defects nobody had found A public rank on HackerOne, a place on Microsoft’s researcher leaderboard, and named defects in third-party software documented on their blog. Externally checkable, and conceded above. No named customer references. Every engagement described on this site is an anonymised composite, and that is the limit of what we publish.
What arrives with a finding A demonstrated attack rather than a candidate, surfaced after review, per their platform page. The request as sent and the response as returned, the steps that reproduce it, a CVSS v4.0 vector and a CWE — on every finding, in every class, in all three delivery models.
Where the work runs, and where the data sits Cloud only, multi-tenant, with a United States region by default and a European region in Frankfurt. European residency is in private preview for enterprise customers, a single-tenant option is published as coming soon and Singapore as in development, and no on-premise option is published. The target itself must be reachable from the internet and able to allowlist their addresses. Nothing is required inside your network for external and application testing, and a deployment only for internal. On-premise and customer VPC are both available today, with residency in India, the European Union, the United States and Singapore.
Firing a test from a pipeline Their API, called from your own scheduler or continuous-integration system, on merge or before a deploy. No named pipeline system is published, so the glue is yours to write. Four continuous-integration systems in production — GitHub Actions, GitLab CI, Jenkins and Azure DevOps — and a result can fail a build against a severity threshold you set.
A measured comparison against human testers Not a comparison this page checked on their side, so nothing is claimed about it. B-52 and Security Brigade’s expert assessment team worked the same targets in parallel, findings pooled with each item counted once. B-52 reached 90–95% of that pooled set. The method is set out below.

Third-party validation of the testing platform

XBOW
Amazon Web Services granted Security Competency status in July 2026, in the Application Security distinction, and XBOW joined the AWS ISV Accelerate Program in May 2026.
B-52
Nothing at platform level. Security Brigade has been CERT-In empanelled since 2008 and is ISO 27001 certified.

Evidence of finding defects nobody had found

XBOW
A public rank on HackerOne, a place on Microsoft’s researcher leaderboard, and named defects in third-party software documented on their blog. Externally checkable, and conceded above.
B-52
No named customer references. Every engagement described on this site is an anonymised composite, and that is the limit of what we publish.

What arrives with a finding

XBOW
A demonstrated attack rather than a candidate, surfaced after review, per their platform page.
B-52
The request as sent and the response as returned, the steps that reproduce it, a CVSS v4.0 vector and a CWE — on every finding, in every class, in all three delivery models.

Where the work runs, and where the data sits

XBOW
Cloud only, multi-tenant, with a United States region by default and a European region in Frankfurt. European residency is in private preview for enterprise customers, a single-tenant option is published as coming soon and Singapore as in development, and no on-premise option is published. The target itself must be reachable from the internet and able to allowlist their addresses.
B-52
Nothing is required inside your network for external and application testing, and a deployment only for internal. On-premise and customer VPC are both available today, with residency in India, the European Union, the United States and Singapore.

Firing a test from a pipeline

XBOW
Their API, called from your own scheduler or continuous-integration system, on merge or before a deploy. No named pipeline system is published, so the glue is yours to write.
B-52
Four continuous-integration systems in production — GitHub Actions, GitLab CI, Jenkins and Azure DevOps — and a result can fail a build against a severity threshold you set.

A measured comparison against human testers

XBOW
Not a comparison this page checked on their side, so nothing is claimed about it.
B-52
B-52 and Security Brigade’s expert assessment team worked the same targets in parallel, findings pooled with each item counted once. B-52 reached 90–95% of that pooled set. The method is set out below.

How the benchmark was run

The one number on this page that is ours

The 90–95% figure, and what sits inside it As of 2026-09-14
  • The same targets were worked at the same time by B-52 and by Security Brigade’s expert assessment team, with neither side able to see the other’s output while the work ran.
  • The two sets of findings were pooled into a single denominator, each item counted once, so a defect both sides reached counts once and not twice.
  • B-52 reached 90–95% of that pooled set. Some of what it reached was missing from the team’s own output, which is why the pooled set is larger than either side produced by itself.
  • Every engagement Security Brigade has run since the firm started in 2006 was worked inside Lemon, and that record is what trained the models the platform runs on.
  • Turnaround is a separate measurement and a narrower one: an observed median of one to three business days, on the fully autonomous model only. It is a median taken from real runs rather than a service level, and no equivalent figure exists for the expert-verified or human-led models.

Deliberately excluded

  • It is a proportion of a findings set, not a comparison of two products, and it is not a statement about XBOW, who publish no equivalent figure that this page found.
  • Physical, hardware and wireless testing, which are out of scope for B-52 in every class.
  • No turnaround figure is stated for the expert-verified or human-led models anywhere on this site, because none has been measured.

Every claim, sourced

What was read, and when

Competitive claims go out of date, and this page has a date on every one of them so you can tell how far. Where a row has aged past what you would rely on, check it against their own site — that is where each of these was read.

What XBOW publishesVerified
"XBOW currently supports testing web applications and their APIs." Web applications are defined as "websites with interactive features such as forms, dashboards, or user accounts." 2026-09-14
Read at https://docs.xbow.com/console/reference/target-types/
"Support for penetration testing of other target types is on our roadmap." No mobile, thick-client, secure-code-review, external network, internal network, cloud or infrastructure-as-a-service, Active Directory, social-engineering, or AI and language-model target type is published as currently supported. 2026-09-14
Read at https://docs.xbow.com/console/reference/target-types/
Published conditions under which XBOW cannot test a target: applications not publicly reachable from the internet, targets that cannot allowlist XBOW IP addresses, anything behind a virtual private network or a blocking network configuration, end-of-life servers, services or certificates, hosts without modern Chrome support, unsupported authentication methods, and fixed session timeouts that expire too quickly. 2026-09-14
Read at https://docs.xbow.com/console/reference/target-types/
A /pricing page exists and sits in the primary navigation. It publishes no figure. The stated model is "Usage-based pricing that scales with your coverage, not a fixed annual engagement" and "Pricing is scoped to your environment." The only conversion actions on the page are "Request a Quote" and "Get a Demo". 2026-09-14
Read at https://xbow.com/pricing
Procurement is offered through the Amazon Web Services, Google Cloud, Oracle and Microsoft cloud marketplaces: "Buy through agreements you already have and put your committed spend to work." The linked listings are enterprise stock-keeping units — the Google listing slug is xbow-enterprise and the Oracle listing is xbow-enterprise-po — that is, committed-spend and private-offer procurement rather than card checkout. 2026-09-14
Read at https://xbow.com/pricing
https://xbow.com/pentest issues a server-side 301 redirect to https://xbow.com/demo, confirmed with a redirect-following request that reported one redirect, a final URL of /demo and a 200 response. /lightspeed and /pentest-on-demand both return 404. 2026-09-14
Read at https://xbow.com/pentest
The 13 November 2025 press release announcing XBOW Pentest On-Demand is still published and still listed in their news index. It states "Pricing for XBOW Pentest On-Demand starts at $4,000", a "fully self-service experience without scoping calls or kickoff meetings", "a few clicks at a significantly lower price point", and "delivers complete, expert-level pentest results within five business days". Its call to action links to www.xbow.com/pentest, the route that now redirects to /demo. There is no deprecation banner or correction on the page. 2026-09-14
Read at https://xbow.com/news/announcing-xbow-pentest-on-demand-for-security-at-machine-speed
Autonomy, in their words: "Full Autonomy, Governed for Production"; "XBOW explores your applications and APIs like a real attacker, chaining vulnerabilities into working attacks and independently proving exploitability"; "runs the entire pentest autonomously and continuously"; "Thousands of agents attack in parallel"; "Point it at a URL. Get back working exploits"; "Risk is measured every day, not estimated once a year". 2026-09-14
Read at https://xbow.com/platform
Guardrails and governance: "Scope You Control", with user-defined testable targets; "Safe Validation" — "production-safe challenges designed to avoid modifying data"; "Observable and Auditable" — "every action the agents take is logged and reviewable"; and "Non-destructive execution, audit trails, and review before findings surface". 2026-09-14
Read at https://xbow.com/platform
Deployment is cloud-only: multi-tenant software as a service with a United States region by default and a European region on Amazon Web Services Frankfurt (eu-central-1). European data residency is "now available in Private Preview for Enterprise customers", a single-tenant "Managed Hosted" option is "coming soon", and Singapore is "in development". No on-premise or self-hosted option is published anywhere on their site. 2026-09-14
Read at https://xbow.com/blog/xbow-available-eu-data-residency
Public API: entered public preview on 1 February 2026 and was announced on 30 March 2026. It is date-versioned, with 2025-11-01, 2026-02-01, 2026-04-01, 2026-06-01, 2026-07-01 and 2026-08-01 published alongside next and unstable, and the reference is still labelled "Preview". Operations: create and configure assets, start, pause, resume and cancel assessments, retrieve findings, and trigger fix verification. Webhook events: assessment.changed, finding.changed and asset.changed, with subscription management, delivery-signature verification and delivery history. A full OpenAPI specification is published for code generation, and authentication is by bearer token with the API version pinned by header. 2026-09-14
Read at https://xbow.com/blog/introducing-the-xbow-public-api
Continuous-integration coverage is served by that API rather than by a packaged pipeline integration: "Trigger a pentest on merge or pre-deploy and surface exploit-proven issues before a release ships", "Trigger per-asset pentests from your own scheduler or CI, across a large estate of sprawling or acquired applications, without adding headcount", and "on your own release cadence". No GitHub Actions, GitLab, Jenkins or other named pipeline integration is published. 2026-09-14
Read at https://xbow.com/api
The only named product integrations published in their documentation are Jira, for creating work items from findings with field mapping, and Microsoft, through an XBOW Sentinel Connector that allows findings to be queried in Security Copilot and assessments to be run directly. Both are marked "Public preview". No other security-information or ticketing integration is published. 2026-09-14
Read at https://docs.xbow.com/integrations/
Third-party validation of the platform: Amazon Web Services Security Competency status, 7 July 2026. XBOW "demonstrated and successfully met AWS technical and quality requirements for providing customers with a deep level of software expertise in Application Security", recognised in the Application Security distinction. XBOW also joined the AWS ISV Accelerate Program on 13 May 2026. 2026-09-14
Read at https://xbow.com/news/xbow-achieves-aws-security-competency-status
Published offensive track record: ranked number one on HackerOne in June 2025; "first autonomous system ranked on Microsoft’s MSRC leaderboard"; "14k+ zero days in customer applications". Their blog documents specific named findings including remote code execution in Exim (CVE-2026-45185), React2Shell (CVE-2025-55182), an Akamai CloudTest XML external entity defect, a Palo Alto GlobalProtect cross-site scripting defect, an Apache Druid proxy issue and Chef Automate SQL injection, plus three remote code execution defects reported to Microsoft. 2026-09-14
Read at https://xbow.com/
Funding and scale: "XBOW Raises $120M to Scale its Autonomous Hacker" on 18 March 2026, "Valued at over $1B", followed by "$35M from Strategic Investors" on 6 May 2026 including Accenture Ventures, DNX Ventures, Liberty Global, NVentures, Samsung and SentinelOne. The legal entity is XBOW USA Inc., founded 2023. 2026-09-14
Read at https://xbow.com/news
Ecosystem and regional expansion published in 2026: XBOW embedded into the Microsoft security ecosystem on 23 March 2026, a Samsung SDS cooperation on 11 June 2026, a General Manager for South Korea appointed on 21 January 2026, and a Fast Company 2026 World Changing Ideas award on 16 June 2026. No India presence is published. 2026-09-14
Read at https://xbow.com/news
Current conversion architecture: every primary call to action across the homepage, /platform, /pricing and the redirected /pentest resolves to "Get a Demo" or "Request a Quote". No self-serve sign-up, trial or checkout is published, and app.xbow.com does not resolve. 2026-09-14
Read at https://xbow.com/demo

"XBOW currently supports testing web applications and their APIs." Web applications are defined as "websites with interactive features such as forms, dashboards, or user accounts."

Verified
2026-09-14

Read at https://docs.xbow.com/console/reference/target-types/

"Support for penetration testing of other target types is on our roadmap." No mobile, thick-client, secure-code-review, external network, internal network, cloud or infrastructure-as-a-service, Active Directory, social-engineering, or AI and language-model target type is published as currently supported.

Verified
2026-09-14

Read at https://docs.xbow.com/console/reference/target-types/

Published conditions under which XBOW cannot test a target: applications not publicly reachable from the internet, targets that cannot allowlist XBOW IP addresses, anything behind a virtual private network or a blocking network configuration, end-of-life servers, services or certificates, hosts without modern Chrome support, unsupported authentication methods, and fixed session timeouts that expire too quickly.

Verified
2026-09-14

Read at https://docs.xbow.com/console/reference/target-types/

A /pricing page exists and sits in the primary navigation. It publishes no figure. The stated model is "Usage-based pricing that scales with your coverage, not a fixed annual engagement" and "Pricing is scoped to your environment." The only conversion actions on the page are "Request a Quote" and "Get a Demo".

Verified
2026-09-14

Read at https://xbow.com/pricing

Procurement is offered through the Amazon Web Services, Google Cloud, Oracle and Microsoft cloud marketplaces: "Buy through agreements you already have and put your committed spend to work." The linked listings are enterprise stock-keeping units — the Google listing slug is xbow-enterprise and the Oracle listing is xbow-enterprise-po — that is, committed-spend and private-offer procurement rather than card checkout.

Verified
2026-09-14

Read at https://xbow.com/pricing

https://xbow.com/pentest issues a server-side 301 redirect to https://xbow.com/demo, confirmed with a redirect-following request that reported one redirect, a final URL of /demo and a 200 response. /lightspeed and /pentest-on-demand both return 404.

Verified
2026-09-14

Read at https://xbow.com/pentest

The 13 November 2025 press release announcing XBOW Pentest On-Demand is still published and still listed in their news index. It states "Pricing for XBOW Pentest On-Demand starts at $4,000", a "fully self-service experience without scoping calls or kickoff meetings", "a few clicks at a significantly lower price point", and "delivers complete, expert-level pentest results within five business days". Its call to action links to www.xbow.com/pentest, the route that now redirects to /demo. There is no deprecation banner or correction on the page.

Verified
2026-09-14

Read at https://xbow.com/news/announcing-xbow-pentest-on-demand-for-security-at-machine-speed

Autonomy, in their words: "Full Autonomy, Governed for Production"; "XBOW explores your applications and APIs like a real attacker, chaining vulnerabilities into working attacks and independently proving exploitability"; "runs the entire pentest autonomously and continuously"; "Thousands of agents attack in parallel"; "Point it at a URL. Get back working exploits"; "Risk is measured every day, not estimated once a year".

Verified
2026-09-14

Read at https://xbow.com/platform

Guardrails and governance: "Scope You Control", with user-defined testable targets; "Safe Validation" — "production-safe challenges designed to avoid modifying data"; "Observable and Auditable" — "every action the agents take is logged and reviewable"; and "Non-destructive execution, audit trails, and review before findings surface".

Verified
2026-09-14

Read at https://xbow.com/platform

Deployment is cloud-only: multi-tenant software as a service with a United States region by default and a European region on Amazon Web Services Frankfurt (eu-central-1). European data residency is "now available in Private Preview for Enterprise customers", a single-tenant "Managed Hosted" option is "coming soon", and Singapore is "in development". No on-premise or self-hosted option is published anywhere on their site.

Verified
2026-09-14

Read at https://xbow.com/blog/xbow-available-eu-data-residency

Public API: entered public preview on 1 February 2026 and was announced on 30 March 2026. It is date-versioned, with 2025-11-01, 2026-02-01, 2026-04-01, 2026-06-01, 2026-07-01 and 2026-08-01 published alongside next and unstable, and the reference is still labelled "Preview". Operations: create and configure assets, start, pause, resume and cancel assessments, retrieve findings, and trigger fix verification. Webhook events: assessment.changed, finding.changed and asset.changed, with subscription management, delivery-signature verification and delivery history. A full OpenAPI specification is published for code generation, and authentication is by bearer token with the API version pinned by header.

Verified
2026-09-14

Read at https://xbow.com/blog/introducing-the-xbow-public-api

Continuous-integration coverage is served by that API rather than by a packaged pipeline integration: "Trigger a pentest on merge or pre-deploy and surface exploit-proven issues before a release ships", "Trigger per-asset pentests from your own scheduler or CI, across a large estate of sprawling or acquired applications, without adding headcount", and "on your own release cadence". No GitHub Actions, GitLab, Jenkins or other named pipeline integration is published.

Verified
2026-09-14

Read at https://xbow.com/api

The only named product integrations published in their documentation are Jira, for creating work items from findings with field mapping, and Microsoft, through an XBOW Sentinel Connector that allows findings to be queried in Security Copilot and assessments to be run directly. Both are marked "Public preview". No other security-information or ticketing integration is published.

Verified
2026-09-14

Read at https://docs.xbow.com/integrations/

Third-party validation of the platform: Amazon Web Services Security Competency status, 7 July 2026. XBOW "demonstrated and successfully met AWS technical and quality requirements for providing customers with a deep level of software expertise in Application Security", recognised in the Application Security distinction. XBOW also joined the AWS ISV Accelerate Program on 13 May 2026.

Verified
2026-09-14

Read at https://xbow.com/news/xbow-achieves-aws-security-competency-status

Published offensive track record: ranked number one on HackerOne in June 2025; "first autonomous system ranked on Microsoft’s MSRC leaderboard"; "14k+ zero days in customer applications". Their blog documents specific named findings including remote code execution in Exim (CVE-2026-45185), React2Shell (CVE-2025-55182), an Akamai CloudTest XML external entity defect, a Palo Alto GlobalProtect cross-site scripting defect, an Apache Druid proxy issue and Chef Automate SQL injection, plus three remote code execution defects reported to Microsoft.

Verified
2026-09-14

Read at https://xbow.com/

Funding and scale: "XBOW Raises $120M to Scale its Autonomous Hacker" on 18 March 2026, "Valued at over $1B", followed by "$35M from Strategic Investors" on 6 May 2026 including Accenture Ventures, DNX Ventures, Liberty Global, NVentures, Samsung and SentinelOne. The legal entity is XBOW USA Inc., founded 2023.

Verified
2026-09-14

Read at https://xbow.com/news

Ecosystem and regional expansion published in 2026: XBOW embedded into the Microsoft security ecosystem on 23 March 2026, a Samsung SDS cooperation on 11 June 2026, a General Manager for South Korea appointed on 21 January 2026, and a Fast Company 2026 World Changing Ideas award on 16 June 2026. No India presence is published.

Verified
2026-09-14

Read at https://xbow.com/news

Current conversion architecture: every primary call to action across the homepage, /platform, /pricing and the redirected /pentest resolves to "Get a Demo" or "Request a Quote". No self-serve sign-up, trial or checkout is published, and app.xbow.com does not resolve.

Verified
2026-09-14

Read at https://xbow.com/demo

See what a run returns, starting at $500

A scan is one application or one target, and the entry price is $500. A paid trial is $299. The card flow reaches the five application classes — web, mobile, API, thick client and secure code review — and anything wider than a single target is a scoping call rather than a listed tier.