Black box
$7,000 USD
Typical single-API scope
No internal access. We test the exposed API and its reachable attack surface as an external attacker would.
Unlike general-purpose models from OpenAI and Anthropic that can refuse penetration-testing requests, Helix models are tuned to complete authorized security work. Your code, prompts, traces, and findings stay on inference infrastructure you control and are never sent to a third-party model provider.
Continuous code security review and AI penetration testing that don’t stop at a report. Every finding is validated in a sandbox, explained, and carried through to a merged fix.
Every commit and pull request is reviewed by security agents that read your code the way an attacker would — logic flaws, injection paths, leaked secrets, broken auth. Not pattern matching. Understanding.
Findings are reproduced in sandbox desktops before you ever see them. If it can't be demonstrated, it doesn't page you — signal instead of a wall of false positives.
Severity, blast radius, and the exact code path — written for engineers and auditors alike. A continuous, compliance-ready record of your security posture.
Agents don't stop at finding issues. They write the patch, run the tests, and open a pull request. You review and merge — humans stay in the loop.
Scope testing for an audit, customer request, or internal risk review. Helix covers web applications, APIs, cloud infrastructure, networks, source code, and AI applications, not only SOC 2 evidence.
Scope reports for SOC 2 Type I or Type II, ISO 27001, PCI DSS, a customer security review, or an internal risk assessment. Each report records methodology, coverage, findings, severity, and remediation status.
Test web applications, APIs, cloud infrastructure, internal and external networks, source code, and AI or LLM applications. Agents learn how your product should work before exercising routes, roles, and permission boundaries.
Run open models on inference infrastructure you control. Your code, prompts, findings, and LLM calls are never sent to OpenAI, Anthropic, or another third-party model provider.
Agents discover what you run, wire into the monitoring you already have, and stand up a security data lake with detections built for your company — then watch it, around the clock.
Agents map your attack surface the way an intelligence organisation would — domains, services, cloud accounts, repositories, people and processes. A living picture of what needs defending.
Monitoring and alerting wired into the infrastructure you already run — Prometheus, Grafana, PagerDuty, your SIEM. No rip-and-replace. Helix envelops what exists.
A data lake for security events across your whole estate — every login, deploy, and anomaly in one queryable place. The memory your defence is built on.
Detections designed for your company, not copied from a generic rulebook — your business logic, your crown jewels, your failure modes. Alerts that mean something when they fire.
Agents watch around the clock — identifying threats as they emerge, rectifying weaknesses before they're exploited, and purging attackers who make it inside.
Security work needs models that engage with it. Helix runs powerful open models on infrastructure you control — not nerfed closed AI systems that refuse the job halfway through.
Identify threats. Rectify weaknesses. Purge attackers. An AI SOC that runs continuously — not an annual pentest report gathering dust.
Webhooks become a living security system. Events land in a queryable data lake, agents reconcile what should be true with what is true, and a coordinator spawns specialists to hunt anomalies and repel attacks in parallel.
One signal can wake a team. The coordinator keeps the work bounded, shares memory between agents, verifies the result, and turns every response into evidence for the next decision.
Pilot pricing
Black box API engagements are $7,000 USD, gray box engagements are $10,000 USD, and white box work starts at $10,000 USD. We confirm the scope before testing begins.
Black box
$7,000 USD
Typical single-API scope
No internal access. We test the exposed API and its reachable attack surface as an external attacker would.
Gray box
$10,000 USD
Typical single-API scope
Limited credentials and context give us deeper coverage while preserving realistic attacker constraints.
White box
From $10,000 USD
Priced after review
Pricing depends on codebase size, repository count, dependencies, architecture, and the depth of review required.
Black and gray box prices cover a typical, well-bounded single API. White box pricing depends on codebase size, repository count, dependencies, architecture, and review depth. Larger applications, remediation, and retesting are scoped separately.
Request a scope →Delivery starts when scope, written authorization, and access are confirmed. Findings are validated before reporting; remediation and confirmation testing follow as separate steps.