# Revelion

> The Autonomous AI Pentester. Revelion is an autonomous AI penetration testing platform. It runs as often as you deploy and proves what is exploitable, not what is theoretically vulnerable.

Revelion runs a full offensive engagement against an authorised estate:
reconnaissance, enumeration, exploitation, validation and reporting. It reports
only findings it demonstrated, with reproduction steps and evidence attached.

Testing runs under declared scope, with guardrails enforced in the engine at
code level, further guardrails and context supplied by the customer, and a
documented Letter of Authorisation.

## Key facts

- Company: Revelion Limited, United Kingdom
- Audience: managed service providers, MSSPs, and enterprise security teams
- Entry pricing: MSP Basic at £99 per month, credit-based
- A typical mission costs roughly 30,000 credits
- Access is granted after review at https://www.revelion.ai/request-access, not self-serve

## Site map


### Platform
- [The Revelion platform](https://www.revelion.ai/platform): How autonomous testing works end to end
- [Methodology](https://www.revelion.ai/methodology): The phases a mission runs through
- [Safety and authorisation](https://www.revelion.ai/platform/safety): Scope control, guardrails, production safety
- [Reporting and evidence](https://www.revelion.ai/platform/reporting): What a validated finding looks like
- [Integrations](https://www.revelion.ai/platform/integrations): Slack, MCP server, API
- [Changelog](https://www.revelion.ai/changelog): What shipped, and when

### Solutions
- [For MSPs and MSSPs](https://www.revelion.ai/msp): Multi-tenant testing across your client base
- [For enterprise security teams](https://www.revelion.ai/enterprise): Recurring validation of your own estate
- [For internal IT](https://www.revelion.ai/for/it-teams): Test without a dedicated security function
- [For compliance](https://www.revelion.ai/for/compliance-teams): Evidence for SOC 2 and ISO 27001
- [For public sector](https://www.revelion.aihttps://www.360protect.co.uk): Delivered as 360 Protect, with Invision360
- [Recurring testing](https://www.revelion.ai/for/continuous-testing): Beyond the annual pentest

#### Applications
- [Network](https://www.revelion.ai/applications/network): Internal and external infrastructure
- [Web and web apps](https://www.revelion.ai/applications/web): Applications, portals and logic flaws
- [APIs](https://www.revelion.ai/applications/api): REST and GraphQL surfaces
- [Cloud](https://www.revelion.ai/applications/cloud): Misconfiguration and privilege paths
- [Active Directory](https://www.revelion.ai/applications/active-directory): Identity and lateral movement
- [IoT and embedded](https://www.revelion.ai/applications/iot): Connected and embedded devices

### Research
- [Revelion Labs](https://www.revelion.ai/research): Published research and attack analysis
- [Benchmarks](https://www.revelion.ai/research/benchmarks): Results, methodology and scoring
- [Methodology](https://www.revelion.ai/methodology): How a mission is actually run
- [Attack chains](https://www.revelion.ai/blog/how-ai-agents-chain-vulnerabilities): How weaknesses combine into access
- [SSTI to RCE](https://www.revelion.ai/blog/ssti-to-rce-in-47-seconds): A chain, walked end to end
- [Against scanning](https://www.revelion.ai/blog/ai-pentesting-vs-vulnerability-scanning): Where signature matching stops

### Resources
- [Where Revelion fits](https://www.revelion.ai/where-revelion-fits): Between scanning and the annual accredited pentest
- [Resource centre](https://www.revelion.ai/resources): Guides, briefings and tools
- [Blog](https://www.revelion.ai/blog): Writing from the team
- [Learn](https://www.revelion.ai/learn): Long-form explainers
- [Compare](https://www.revelion.ai/compare): How Revelion differs from the alternatives
- [Glossary](https://www.revelion.ai/glossary): Offensive security terminology
- [Documentation](https://www.revelion.ai/docs): Product and API docs
- [ROI calculator](https://www.revelion.ai/resources/roi-calculator): Model the commercial case
- [Applications](https://www.revelion.ai/applications): Every surface a mission covers
- [Changelog](https://www.revelion.ai/changelog): What shipped, and when

### Company
- [About](https://www.revelion.ai/about): Why Revelion exists
- [Team](https://www.revelion.ai/team): Who builds it
- [Trust Centre](https://www.revelion.ai/trust): Security posture, data handling, Cyber Essentials
- [Partners](https://www.revelion.ai/partners): Distribution and white-label
- [Contact](https://www.revelion.ai/contact): Talk to us
- [Changelog](https://www.revelion.ai/changelog): What shipped, and when
- [Pricing](https://www.revelion.ai/pricing): Published tiers and credit allowances


## Guides

- [What is Autonomous AI Pentesting?](https://www.revelion.ai/learn/what-is-autonomous-ai-pentesting): A comprehensive guide to autonomous AI penetration testing: how intelligent agents perform reconnaissance, exploitation, and reporting without manual intervention, with real benchmark results.


## Comparisons

- [Pentera Alternative: Revelion vs Pentera Comparison](https://www.revelion.ai/compare/pentera): Looking for a Pentera alternative? Compare Revelion vs Pentera: pricing, features, and capabilities. Revelion starts free with 10,000 credits vs Pentera at ~$50,000/year.
- [Revelion vs XBOW](https://www.revelion.ai/compare/xbow): XBOW is an enterprise-only autonomous pentesting platform with pricing estimated at $50K-200K per year. Revelion starts free with 10,000 credits, with access on request and no sales process, from £10. See the full comparison.
- [Revelion vs Horizon3.ai NodeZero](https://www.revelion.ai/compare/horizon3-nodezero): Horizon3.ai NodeZero is an autonomous pentesting platform with enterprise pricing estimated at $30K-100K per year. Revelion starts free with 10,000 credits and access on request from £10. See the full comparison.
- [Revelion vs Cobalt](https://www.revelion.ai/compare/cobalt): Cobalt is a Pentest-as-a-Service platform using vetted human pentesters, with engagements starting around $10K-25K. Revelion is an autonomous AI pentesting platform starting from £10. See the full comparison.
- [Revelion vs HackerOne](https://www.revelion.ai/compare/hackerone): HackerOne is the largest bug bounty platform, connecting organisations with independent security researchers. Revelion is an autonomous AI pentesting platform starting from £10. See the full comparison.
- [Revelion vs Manual Pentesting](https://www.revelion.ai/compare/manual-pentesting): Traditional manual pentesting engagements cost £10K-30K and take 2-6 weeks to schedule. Revelion delivers autonomous AI pentesting from £10 in hours. See why the best security programmes use both.


## Solutions

- [White-Label Pentesting for MSPs](https://www.revelion.ai/for/msps): White-label penetration testing as a service for managed service providers. Add AI pentesting to your MSP stack with branded reports, client portal, and full API access.
- [AI Pentesting for Small Businesses](https://www.revelion.ai/for/small-business): Affordable AI penetration testing for small businesses. Start free with 10,000 credits, pay-as-you-go from £10, and get the same depth of testing as enterprise security teams.
- [AI Pentesting for IT Teams](https://www.revelion.ai/for/it-teams): On-demand AI penetration testing for in-house IT teams. Test internal networks via VPN tunnelling, validate patches after deployment, and maintain continuous compliance between annual engagements.
- [AI Pentesting Tools for Security Consultants](https://www.revelion.ai/for/pentesters): AI-powered pentesting tools for security consultants and researchers. Multiply your output with autonomous reconnaissance and exploitation while retaining full operator control.
- [AI Pentesting for Compliance and GRC Teams](https://www.revelion.ai/for/compliance-teams): AI penetration testing mapped to SOC 2, ISO 27001, PCI DSS, Cyber Essentials, and 5 other compliance frameworks. Generate audit-ready pentest evidence continuously, not just at assessment time.
- [AI Tools for Bug Bounty Hunters](https://www.revelion.ai/for/bug-bounty-hunters): AI-powered reconnaissance and exploitation tools for bug bounty hunters. Automate the systematic work, chain vulnerabilities for higher severity findings, and generate submission-ready proof-of-concept evidence.
- [Continuous Penetration Testing](https://www.revelion.ai/for/continuous-testing): Continuous penetration testing that finds vulnerabilities as they are introduced, not 11 months later. On-demand, scheduled, and post-deployment testing from a single platform.
- [Penetration Testing Compliance Evidence](https://www.revelion.ai/for/compliance-evidence): Generate audit-ready penetration testing evidence for SOC 2, ISO 27001, PCI DSS, Cyber Essentials, and 5 more frameworks. CVSS 3.1 scoring, CWE classification, and PoC evidence in every report.
- [Affordable Penetration Testing](https://www.revelion.ai/for/affordable-pentesting): Real AI penetration testing from £10. Not a vulnerability scan. Actual exploitation, vulnerability chaining, and proof-of-concept evidence at a fraction of traditional consulting costs.


## Articles

- [AI vs Manual Pentesting: 10 Things We Learned](https://www.revelion.ai/blog/ai-vs-manual-pentesting-10-things-we-learned): AI pentesting and manual pentesting are not a simple replacement story. Here are ten practical lessons on where each model wins, where each struggles, and how security providers should combine them.
- [The Margin Math on Managed Pentesting for MSPs](https://www.revelion.ai/blog/managed-pentesting-margin-math): A practical margin model for MSPs turning pentesting into a managed service: package pricing, platform cost, delivery time, and the economics behind recurring security assurance.
- [MSSPs vs Consultancies: Where Pentesting Fits](https://www.revelion.ai/blog/mssps-vs-consultancies-where-pentesting-fits): A practical guide to how MSSPs and security consultancies differ, where their scope overlaps, and how AI pentesting can help both models turn offensive security into a scalable service.
- [Why MSPs Lose Pentest Deals to Consultancies (And How to Win Them Back)](https://www.revelion.ai/blog/why-msps-lose-pentest-deals-to-consultancies): MSPs often refer pentest work to consultancies and watch the relationship drift. The reasons are structural, not technical. Here are the four operating-model gaps and the four counter-moves to bring the pentest line back inside the MSP relationship.
- [AI Pentesting vs Vulnerability Scanning: What Actually Changes](https://www.revelion.ai/blog/ai-pentesting-vs-vulnerability-scanning): Vulnerability scanners check for known signatures. AI pentesting thinks, adapts, and proves exploitability. Here's what actually changes, and why it matters for your security posture.
- [How AI Agents Chain Vulnerabilities: From Recon to Root](https://www.revelion.ai/blog/how-ai-agents-chain-vulnerabilities): How autonomous AI agents discover, correlate, and chain low-severity findings into critical attack paths, with three real-world patterns scanners miss.
- [SSTI to RCE: Template Injection Exploited in 60s](https://www.revelion.ai/blog/ssti-to-rce-in-47-seconds): Step-by-step: how Revelion discovered and exploited a Jinja2 SSTI to achieve RCE in 47 seconds, from initial probe to proven file system access.
- [Why Your Annual Pentest is Already Outdated](https://www.revelion.ai/blog/why-your-annual-pentest-is-outdated): Annual pentesting creates 11-month blind spots. Infrastructure changes daily; your testing does not. Why continuous AI pentesting is the new baseline.
- [The MSP Pentesting Playbook: Security as a Service](https://www.revelion.ai/blog/the-msp-pentesting-playbook): Turn AI pentesting into a high-margin managed service. The MSP playbook for pricing, positioning, and delivering continuous testing to SMB clients.
- [Penetration Testing for SOC 2 Compliance](https://www.revelion.ai/blog/pentesting-for-soc2): SOC 2 does not mandate pentesting, but auditors expect it. What they look for, how often to test, and why continuous AI pentesting beats annual tests.
- [Penetration Testing for ISO 27001 Certification](https://www.revelion.ai/blog/pentesting-for-iso27001): ISO 27001 Annex A requires technical security testing. Which controls mandate pentesting, what auditors expect, and how AI pentesting generates evidence.
- [Pentesting for Cyber Essentials and CE Plus](https://www.revelion.ai/blog/pentesting-for-cyber-essentials): Cyber Essentials Plus requires technical verification. CE vs CE Plus, what IASME assessors look for, and how AI pentesting covers CE Plus affordably.
- [The 7 Best AI Pentesting Tools in 2026 Compared](https://www.revelion.ai/blog/best-ai-pentesting-tools-2026): Independent comparison of the top autonomous AI pentesting tools in 2026, covering pricing, capabilities, deployment models, and best fit.
- [Do Small Businesses Need Penetration Testing?](https://www.revelion.ai/blog/do-small-businesses-need-pentesting): AI is making small businesses viable attack targets at scale. Why pentesting matters for every size of business, and how AI has made it affordable.
- [How IT Providers Can Offer Pentesting to Clients](https://www.revelion.ai/blog/it-providers-offer-pentesting): Clients are asking about security testing. AI pentesting lets IT providers offer professional testing as a high-margin service without hiring pentesters.
- [What Does a Penetration Test Actually Check?](https://www.revelion.ai/blog/what-does-a-pentest-check): A jargon-free guide to what a pentest actually examines: websites, email, networks, cloud. Written for owners and non-technical managers.
- [What is Penetration Testing as a Service (PTaaS)?](https://www.revelion.ai/blog/what-is-penetration-testing-as-a-service): PTaaS delivers on-demand security testing via a platform, not one-off consulting. How it works, who uses it, and why AI PTaaS is replacing the old model.
- [How Much Does a Pentest Cost in 2026?](https://www.revelion.ai/blog/how-much-does-a-pentest-cost): Traditional pentesting costs £5,000 to £30,000 per engagement. Full cost breakdown, what drives pricing, and how to get pentest-quality results from £10.
- [Vulnerability Assessment vs Penetration Testing: What is the Difference?](https://www.revelion.ai/blog/vulnerability-assessment-vs-penetration-testing): Vulnerability assessments classify weaknesses; pentests prove exploitability. How they differ, when to use each, and how AI pentesting bridges the gap.
- [Continuous Security Testing: Why Annual Pentests Are Not Enough](https://www.revelion.ai/blog/continuous-security-testing-guide): Annual pentesting leaves a 364-day blind spot. Continuous security testing validates every deployment, every change, every new threat. How to implement it.
- [MSP Cybersecurity: The Complete Guide for IT Providers](https://www.revelion.ai/blog/msp-cybersecurity-complete-guide): MSP cybersecurity: delivering security services to clients. What services to offer, how to build a stack, and where AI pentesting fits the gap.
- [External Penetration Testing: A Complete Guide](https://www.revelion.ai/blog/external-penetration-testing-guide): External pentesting attacks your org from the outside: web apps, APIs, and public infrastructure. How it works, what gets tested, how often to run it.
- [The MSP's Guide to Adding Pentesting as a Service](https://www.revelion.ai/blog/msp-guide-adding-pentesting-service): A step-by-step guide for MSPs adding pentesting as a service: choosing a platform, pricing, white-label reports, and scaling across client environments.
- [Automated Pentesting vs Manual Pentesting: A Comparison](https://www.revelion.ai/blog/automated-vs-manual-pentesting): Automated pentesting uses AI for speed. Manual uses humans for depth. Most orgs need both. How they compare and when to use each.

## Machine-readable resources

- Sitemap: https://www.revelion.ai/sitemap.xml
- API catalogue: https://www.revelion.ai/.well-known/api-catalog
- MCP server card: https://www.revelion.ai/.well-known/mcp/server-card.json
- Agent skills index: https://www.revelion.ai/.well-known/agent-skills/index.json
- Security contact: https://www.revelion.ai/.well-known/security.txt
- Feed: https://www.revelion.ai/feed.xml

## Contact

- Access requests: https://www.revelion.ai/request-access
- General: support@revelion.ai
