Scope is declared before anything runs
Targets are defined and bounded up front. Revelion does not discover its way outside the estate you authorised.
Revelion is the autonomous AI pentester. It runs a full offensive engagement across your estate, as often as you deploy, and reports only what it managed to demonstrate.
Trusted by MSPs and enterprises globally
Public sector as

Map the estate
Identify exposure
Chain to access
Reproduce impact
Evidence and severity
The threat
Your perimeter is already being swept continuously by adversaries running at machine speed. Nothing tested once a year can answer that, and no amount of headcount closes the gap. The only defence that keeps pace works the same way the attack does.
The problem
Nothing about the way most organisations test has kept pace with the way they ship. The result is a posture that is accurate once a year and assumed for the other fifty-one weeks.
Adversary
Automated probing, around the clock.
Traditional pentest
One test, then a 364-day gap.
Revelion
52 scheduled tests. The gap closes to seven days.
Same twelve months, three cadences. The distance between the first two lanes is the exposure window, and no amount of headcount closes it. The third lane is what closing it looks like.
The platform
Revelion does not hand you a queue of alerts to triage. A root agent plans the engagement and directs specialist sub-agents through it end to end, then reports only what they managed to prove.
Everything above the last bar is discarded. A weakness that could not be demonstrated never becomes a finding, which is why the report is short and why every line in it holds up.
How it works
Revelion runs the whole engagement rather than handing you a queue to triage. Here is what happens between authorisation and report.
Targets are declared and bounded before anything runs. Revelion works inside the estate you authorised, and nowhere else.
The agent enumerates services, versions, exposures and weak configuration the way an attacker would, from the outside in.
Individually low-severity issues get combined into a route to real access. This is the step a scanner cannot perform.
Impact is reproduced and captured as evidence, then written up with severity rationale and a remediation path.
Everything above runs without you.
Everything below is what comes back.
Evidence
A vulnerability is a hypothesis until somebody demonstrates it. Revelion reports a finding only once it has chained the weakness into real access and reproduced the result.
Exposed template rendering endpoint discovered
Recon
Server-side template injection confirmed
Exploit
Injection escalated to remote code execution
Exploit
Impact reproduced and captured as evidence
Validate
A scanner would have flagged the endpoint and stopped. The finding that matters is the one that ends in access.
Who it is for
The same engine, pointed at two different problems. One is scale across many estates. The other is depth within one.
For MSPs and MSSPs
Run offensive testing across every client estate without adding headcount.
For enterprise security teams
Validate your own estate as often as you deploy, and take the annual engagement from the same provider.
Safety
The first question any security lead asks about an autonomous agent is whether it can break production, and who authorised it to try. Both answers are designed in, not bolted on.
Targets are defined and bounded up front. Revelion does not discover its way outside the estate you authorised.
Destructive and state-changing actions are refused at code level unless your declared scope permits them, and you layer your own guardrails and context on top.
Testing runs against a Letter of Authorisation, so the engagement is defensible to your board, your client and your auditor.
Reporting
A finding is only useful if someone else can act on it. Every report carries the reproduction steps, the impact, the severity rationale and the remediation path.
Category
Revelion is not a scanner with better marketing, and it is not a consultancy with an API. It is the recurring half of penetration testing, done by an agent.
| Capability | Revelion | Vulnerability scanning | Annual pentest |
|---|---|---|---|
| Runs as often as you deploy | — | ||
| Proves exploitability | — | ||
| Chains weaknesses into real access | — | ||
| Covers the estate after every change | — | ||
| Scales across many client estates | — | ||
| Cost is predictable in advance | |||
| Evidence suitable for audit |
Check the claims
The category we sit in, how we compare to what you already run, and the benchmark results with the methodology attached.
Revelion Labs
Our research arm documents attack chains, benchmark results and the methodology behind them. If a claim cannot be checked, it does not belong on this site.
Benchmarks
How Revelion performs against known benchmark environments, with the methodology written out so the numbers can be interrogated.
View benchmarksAttack research
Write-ups of real chains, including the reasoning that turned an isolated weakness into access worth reporting.
Read the researchPricing
Testing is billed against credits, so the cost of covering a client base is knowable in advance rather than quoted each time. Full tiers, including an enterprise path, are on the pricing page.
Start here
£0PAYG Free
10,000 free credits to start, then pay-as-you-go top-ups at £10 per 10,000. Monthly MSP plans begin at £99 when you want client workspaces and scheduled testing.
Questions
Access is granted after a short review, so we can make sure Revelion is pointed at the right problem before you start.
Request access