Naqid
/ˈnɑː.qɪd/ · Arabic: the critic. The one who probes.
An agent-driven testing platform that probes your web, API, and cloud surfaces. Senior engineers review and approve each action: the AI scales the probing, the team scales the judgment. Every step logged, reproducible, and tied to a finding chain you can hand to auditors. In preview with fintech and healthcare engagements today.
The shift
Pentesting at full attack-chain depth.
Naqid simulates the full attack lifecycle: reconnaissance, initial access, privilege escalation, lateral movement, exfiltration. Senior engineers review every step before it runs.
Coverage
What Naqid tests.
Application surface
Authentication, authorization, session, injection, business-logic flaws, modern SPA quirks. OWASP top-10 as the floor, with modern SPA and business-logic depth on top.
Service surface
Contract drift, broken authorization, rate-limit bypass, mass assignment, server-side request forgery. REST, GraphQL, and gRPC.
Infrastructure surface
IAM misconfigurations, public-exposure detection, secret leakage, drift from secure baselines, supply-chain checks across AWS-native services.
How it works
Behind each Naqid run.
Attack-chain simulation
Real attacks unfold across phases: reconnaissance, initial access, privilege escalation, lateral movement, exfiltration. Naqid simulates the full chain end to end.
Offensive agentic AI
Frontier models probe permutations a human can't enumerate. The agent maps the surface, hypothesises an attack path, runs the probes, and chains successful steps.
Auditable & reproducible
Every finding is validated, reproduced, and documented. Naqid produces a full audit log and step-by-step repro your team can re-run independently.
Human-in-the-loop
Agents are fast. Senior engineers are what makes the speed useful. Each action is reviewed and approved before it runs.
Output
Findings, in plain English.
Every validated finding lands in a written report with reproduction steps, suggested remediation, CVSS score, and a mapping to the relevant compliance control. Findings can be routed into your tracker on request. The audit-grade chain is the deliverable.
Teams remediate faster because the finding ships with the evidence to act on it.
Engagement model
Two ways Naqid runs in your engagement.
Same operator, same audit-grade output. The choice is topology: runs in your AWS, or in ours.
Naqid runs in your AWS account
Operated by our senior engineers as part of the engagement. Findings, audit log, and the evidence chain stay inside your perimeter.
Naqid runs in ours
We host Naqid in our environment and run it against your surface under your approval gates. Faster to start; the audit chain is delivered to you at engagement close.
Access
Request access to Naqid.
Drop your email. We'll send a confirmation link and reach out as access opens up to new accounts.
Case study
See how a client uses Naqid in production.
Drop your email. We'll send you a link to the PDF. The link expires in 24 hours.
Naqid FAQ
Common questions about agentic pentesting.
How is Naqid different from a vulnerability scanner?
Does Naqid replace annual penetration tests?
What attack surfaces does Naqid cover?
How do findings come back?
Can we start in staging before opening up production?
Ready to put Naqid on your surfaces?
Drop your email below. We'll confirm and reach out as access opens up.