Skip to content
Revelion
revelion@ai $ think offensive

Prove what is exploitable

Revelion is the autonomous AI pentester. It runs a full offensive engagement across your estate, as often as you deploy, and reports only what it managed to demonstrate.

Trusted by MSPs and enterprises globally

Public sector as360 Protect
The Revelion command centre, showing security posture and active missions across multiple client environments
  1. 01 Recon

    Map the estate

  2. 02 Enumerate

    Identify exposure

  3. 03 Exploit

    Chain to access

  4. 04 Validate

    Reproduce impact

  5. 05 Report

    Evidence and severity

  • Built in the UK
  • Published testing methodology
  • Every finding backed by reproducible evidence
01

The threat

Fight automated attack with automated testing

Your perimeter is already being swept continuously by adversaries running at machine speed. Nothing tested once a year can answer that, and no amount of headcount closes the gap. The only defence that keeps pace works the same way the attack does.

Attackers automated first
Reconnaissance, exploitation and target selection are being run by machines. The economics of attacking a small estate stopped being prohibitive, which means everyone is now worth probing.
The gap is time, not talent
An adversary that never stops testing against a defence that tests once a year is not a fair contest. It is a scheduling mismatch, and the schedule is losing.
Human-speed testing cannot close it
You cannot hire your way out of a machine-speed problem. The only thing that keeps pace with automated attack is automated validation, run as often as the estate changes.
02

The problem

The annual pentest describes a day that has already passed

Nothing about the way most organisations test has kept pace with the way they ship. The result is a posture that is accurate once a year and assumed for the other fifty-one weeks.

It tests one week in fifty-two
A point-in-time engagement describes the estate on the day it ran. Everything you deploy afterwards is untested until the next one comes round.
Scanners report theory, not impact
A CVE list tells you what might be exploitable. It cannot tell you which weaknesses actually chain together into access in your environment, which is the only question that matters.
It does not scale to a client base
Manual testing is priced per engagement. For anyone responsible for dozens of estates, the model breaks on cost long before it breaks on coverage.
Testing cadence, one year

Adversary

Automated probing, around the clock.

Traditional pentest

One test, then a 364-day gap.

Revelion

52 scheduled tests. The gap closes to seven days.

Same twelve months, three cadences. The distance between the first two lanes is the exposure window, and no amount of headcount closes it. The third lane is what closing it looks like.

03

The platform

A team of agents that runs the whole engagement

Revelion does not hand you a queue of alerts to triage. A root agent plans the engagement and directs specialist sub-agents through it end to end, then reports only what they managed to prove.

They choose their own route
Revelion is not running a fixed script against a checklist. The root agent decides what to try next, and which specialist to hand it to, based on what the estate has already told it.
They run the engagement unattended
No queue of alerts to triage. The agents work the whole engagement end to end and come back when there is something worth your attention.
Every action stays inside your scope
You set the boundary before anything runs. Every action any agent takes is logged, attributable and replayable, which is what makes autonomy safe to authorise.
What survives a mission
  1. Surfaces enumerated
  2. Candidate weaknesses
  3. Exploits attempted
  4. Proven and reportedReported

Everything above the last bar is discarded. A weakness that could not be demonstrated never becomes a finding, which is why the report is short and why every line in it holds up.

How it works

One mission, start to finish

Revelion runs the whole engagement rather than handing you a queue to triage. Here is what happens between authorisation and report.

01

Scope the mission

Targets are declared and bounded before anything runs. Revelion works inside the estate you authorised, and nowhere else.

Phase 01 — Scope the mission
02

Map the attack surface

The agent enumerates services, versions, exposures and weak configuration the way an attacker would, from the outside in.

Phase 02 — Map the attack surface
03

Chain the weaknesses

Individually low-severity issues get combined into a route to real access. This is the step a scanner cannot perform.

Phase 03 — Chain the weaknesses
04

Prove it, then report

Impact is reproduced and captured as evidence, then written up with severity rationale and a remediation path.

Phase 04 — Prove it, then report

Everything above runs without you. Everything below is what comes back.

04

Evidence

Proof, not adjectives

A vulnerability is a hypothesis until somebody demonstrates it. Revelion reports a finding only once it has chained the weakness into real access and reproduced the result.

Example chain
  1. 1

    Exposed template rendering endpoint discovered

    Recon

  2. 2

    Server-side template injection confirmed

    Exploit

  3. 3

    Injection escalated to remote code execution

    Exploit

  4. 4

    Impact reproduced and captured as evidence

    Validate

A scanner would have flagged the endpoint and stopped. The finding that matters is the one that ends in access.

05

Who it is for

Built for MSPs. Ready for enterprise.

The same engine, pointed at two different problems. One is scale across many estates. The other is depth within one.

For MSPs and MSSPs

Run offensive testing across every client estate without adding headcount.

  • Multi-tenant testing across your client base
  • White-label reporting under your own brand
  • Published pricing and a clear margin model
  • A repeatable service line, not a bespoke engagement

For enterprise security teams

Validate your own estate as often as you deploy, and take the annual engagement from the same provider.

  • Recurring validation of your production estate
  • The annual human-led pentest as a managed service
  • Evidence mapped to SOC 2 and ISO 27001 controls
  • Scope control and an explicit authorisation workflow
06

Safety

Autonomous does not mean unsupervised

The first question any security lead asks about an autonomous agent is whether it can break production, and who authorised it to try. Both answers are designed in, not bolted on.

Scope is declared before anything runs

Targets are defined and bounded up front. Revelion does not discover its way outside the estate you authorised.

Guardrails are enforced in the engine

Destructive and state-changing actions are refused at code level unless your declared scope permits them, and you layer your own guardrails and context on top.

Authorisation is documented

Testing runs against a Letter of Authorisation, so the engagement is defensible to your board, your client and your auditor.

07

Reporting

Evidence you can hand to an auditor

A finding is only useful if someone else can act on it. Every report carries the reproduction steps, the impact, the severity rationale and the remediation path.

Reproducible by your engineers
Each finding includes the exact chain that produced it, so remediation starts from fact rather than from interpretation.
Mapped to your frameworks
Evidence lines up with SOC 2 and ISO 27001 control requirements, so it survives contact with an audit.
Ready for a client
Reports are written to be read by the people who commissioned the test, not only by the people who ran it.

Category

Where Revelion sits

Revelion is not a scanner with better marketing, and it is not a consultancy with an API. It is the recurring half of penetration testing, done by an agent.

CapabilityRevelionVulnerability scanningAnnual pentest
Runs as often as you deploy
Proves exploitability
Chains weaknesses into real access
Covers the estate after every change
Scales across many client estates
Cost is predictable in advance
Evidence suitable for audit

Pricing

Start free, then priced per estate

Testing is billed against credits, so the cost of covering a client base is knowable in advance rather than quoted each time. Full tiers, including an enterprise path, are on the pricing page.

Start here

£0PAYG Free

10,000 free credits to start, then pay-as-you-go top-ups at £10 per 10,000. Monthly MSP plans begin at £99 when you want client workspaces and scheduled testing.

Questions

Common questions

Find out what an attacker would reach first.

Access is granted after a short review, so we can make sure Revelion is pointed at the right problem before you start.

Request access