Bugcrowd has launched Savant Pathseeker, an agentic penetration testing product for external web applications and APIs.
Pathseeker runs continuous tests across approved assets rather than waiting for a scheduled penetration test. It is designed to identify vulnerabilities, attempt exploitation, and provide evidence that security teams can use to prioritize fixes.
Moving beyond scanner findings
Bugcrowd is positioning Pathseeker as more than an automated vulnerability scanner. Traditional scanners generally run predefined checks and flag possible weaknesses, leaving security teams to determine whether those findings can be used in an actual attack.
Braden Russell, chief product officer at Bugcrowd, told MSSP Alert, “Pathseeker is not a scanner with an AI layer bolted on. Scanners run pre-defined checks and flag theoretical issues. Pathseeker uses purpose-built agentic systems that plan, probe, and attempt actual exploitation across web applications and APIs, delivering evidence-based findings with reproducible proof of exploitability, not just a list of potential flaws.”
The system uses a layer of proprietary security testing skills and orchestration built on third-party AI models. Bugcrowd said those capabilities were developed by its own offensive security practitioners and include autonomous API fuzzing, application testing, and attack-path reasoning.
Russell said the product’s technical differentiation also comes from its connection to the rest of the Bugcrowd platform.
“Findings from agents feed directly into the same risk surface and workflows as human results, so they can be correlated, prioritized by exploitability, and escalated without tool-switching,” he said.
Pathseeker connects with Bugcrowd’s penetration testing as a service, bug bounty, vulnerability disclosure, red team, and attack surface management offerings. That allows a finding uncovered through continuous testing to move into a deeper human-led investigation without being transferred to another system. Customers can define testing scope, apply operational guardrails, and use a manual kill switch to stop activity. The product also generates audit-ready reports, which can be used by security, compliance, and risk teams.
Where human pentesters step in
The agents handle reconnaissance, vulnerability mapping, exploitation attempts, and validation of common and moderately complex issues across web applications and APIs. Findings include proof of exploitability, giving security teams more information than a severity score or theoretical risk rating alone.
“The agents continuously test external web applications and APIs, handling reconnaissance, vulnerability mapping, exploitation attempts, and autonomous validation of common and moderately complex issues,” Russell said. “Findings come with proof of exploitability, providing broad, continuous baseline coverage across the entire external attack surface at a cadence and scale that human teams alone cannot match.”
Human researchers remain part of the process when a test requires more context or creativity. That includes complex business logic flaws, new exploit chains, zero-day vulnerabilities, and high-impact attack paths inside dynamic applications.
“Customers can escalate on demand through the same platform, the agents surface what is reachable, and the humans focus where depth matters most,” Russell said. “The goal is not replacement. It is letting each do what it does best.”
Bugcrowd said it does not use customer or researcher data to train or tune the models behind Pathseeker. The company uses external AI models with its own security testing layer built on top.
Measuring whether risk goes down
Bugcrowd plans to measure Pathseeker by whether customers reduce exposure and remediate exploitable weaknesses, rather than by the total number of findings the product generates.
“We measure outcomes around exploitable risk, not volume of findings,” Russell said. “Key indicators include reduction in the window of exposure, the time between a change being introduced and validated testing being completed, and a shift from theoretical scanner findings to confirmed, evidence-based exploitable issues that are actually remediated.”
The company will also track how many external applications and APIs are covered by continuous testing, along with whether fewer serious issues reach production or later appear through bug bounty programs and incident response work.
Because the product shares a platform with Bugcrowd’s human testing services, the company can also compare agent findings with vulnerabilities later identified by researchers. That should give customers a clearer view of where automated testing is reducing the amount of work that needs to be escalated.
MSSP service opportunity
Pathseeker also gives MSSPs a way to add continuous agentic testing to managed security and offensive security services.
Russell said the Bugcrowd platform already supports multitenant operations used by MSSPs for penetration testing, bug bounty, and related services. Providers can manage separate customer scopes, apply testing policies, and produce reports for each client through the same platform.
“MSSPs can offer tiered or hybrid managed services, for example, continuous agentic coverage as a baseline managed offering, with human escalation or deeper PTaaS and red team packages layered on for higher-value customers,” he said. “Findings arrive with evidence and audit-ready reporting that MSSPs can incorporate directly into their own client deliverables.”