Novee is a continuous, AI-powered penetration testing platform that acts as an autonomous AI attacker. It maps application environments, uncovers exploit chains, and validates findings by generating working exploits. Its testing surface covers web applications, APIs, mobile apps (both APK and runtime), and LLM-powered AI systems.
The tool addresses the gap between how quickly application risk appears and how slowly it gets found and fixed. Annual manual pentests move too slowly for modern CI/CD release cycles, and conventional DAST scanners tend to generate noisy, false-positive alerts without business context. Remediation also often stalls due to manual handoffs and patches that are never re-verified.
Novee runs on a continuous four-step loop: Discover, Detect, Validate, and Remediate. It builds a persistent Asset Intelligence Model of an application’s workflows and business logic, then deploys independent AI agents to prove exploitability and produce a working proof-of-concept script for every finding. Its Agentic Fix capability routes stack-specific remediation guidance to a developer’s existing AI coding tools and automatically re-tests the system once a patch merges.
Novee’s core differentiator is a proprietary multi-model offensive AI system trained on offensive security tradecraft, rather than a simple wrapper around a single frontier model. Combined with multi-agent validation and a remediation pipeline that plugs into developer coding agents, this sets it apart from reporting-only pentest tools.
Pricing
Novee does not publish pricing on its website. There is no listed free plan, free trial, self-serve paid tier, or usage-based pricing, and enterprise pricing is not disclosed. Prospective buyers need to contact Novee directly to get a quote, and no public information is available on plan limitations or usage caps.
* Disclaimer: Please note that pricing information may not be up to date. For the most accurate and current pricing details, refer to the official website.
Key Features
- ✓
Continuous, change-triggered testing that runs as code ships
- ✓
Proprietary multi-model offensive AI paired with frontier LLMs
- ✓
Asset Intelligence Model mapping workflows, roles, APIs and logic
- ✓
Multi-agent validation with reproduction steps and Python PoC scripts
- ✓
Combined APK and runtime testing of mobile attack surfaces
- ✓
AI red teaming for prompt injection, jailbreaks and tool abuse
Use Cases
Scaling Web App Pentesting
Teams use Novee to continuously validate web applications for multi-step exploit chains and authorization gaps like BOLA and IDOR. It integrates with deployment cycles so testing context builds over time instead of waiting for an annual manual pentest.
Securing LLM-Powered Applications
AI and engineering teams test agents and chatbots for prompt injection, jailbreaks and sensitive data exposure. Novee’s planner agents generate AI-specific attack scenarios mapped to the OWASP AITG across different model architectures.
Comprehensive Mobile App Security
Security teams upload an APK to test the full mobile attack surface, including runtime behavior and intent manipulation. Findings are mapped to the OWASP MASVS so annual static tests are no longer the only coverage.
Streamlining Developer Remediation
Agentic Fix bridges the gap between finding a vulnerability and fixing its root cause. It generates stack-specific remediation briefs and routes them directly into AI coding tools such as GitHub Copilot or Cursor.
Continuous Compliance Evidence
Compliance and security leaders use Novee to generate verifiable evidence for certifications and customer due diligence. Continuous, logged execution traces and verified exploits are mapped to over 40 frameworks, including SOC 2, ISO 27001, HIPAA and GDPR.
Strengths & Weaknesses
Strengths
Eliminates false positives by providing a validated exploit and Python PoC for every finding.
Uses a proprietary offensive AI model trained for attacker tradecraft, not just a generic LLM wrapper.
Testing depth improves over time as the Asset Intelligence Model learns the target’s business logic.
Speeds up patching by routing context-rich remediation briefs directly to developers’ AI coding agents.
Guarantees customer data is never used for model training and offers on-premises deployment.
Weaknesses
Pricing plans, tiers and free trial options are not published on the website.
Getting the full benefit of Agentic Fix depends on the team already using a supported AI coding agent like Copilot or Cursor.
Strict guardrails against destructive payloads and data exfiltration mean it cannot fully simulate ransomware or destructive attack impact.
The published focus on web, mobile, API and AI targets suggests limited coverage of legacy systems or physical network hardware.
Who Is This For?
CISOs: Get continuous, evidence-backed proof of security posture and audit-ready compliance evidence without relying on annual point-in-time reports.
AppSec teams: Reduce alert fatigue from traditional DAST scanners by only reviewing findings backed by a working, reproducible exploit.
AI and ML engineering teams: Test LLM agents and architectures for prompt injection and abuse as part of their normal release workflow.
Software engineers and developers: Receive precise, codebase-specific remediation guidance inside the AI coding tools they already use.
Frequently Asked Questions
Does Novee train its AI models on my application data?
No. Novee states that its models are never trained on customer data.
Can Novee’s testing disrupt my production environment?
Novee uses controlled execution guardrails, including rate limits, defined testing boundaries, no destructive payloads, and no data exfiltration, to reduce the risk of operational disruption.
Do I need to install software to use Novee?
Novee can be consumed as a SaaS platform, through a Bastion Node, or deployed fully on-premises, depending on requirements.
Can Novee test AI chatbots and LLM-powered applications?
Yes. Novee includes an AI red teaming solution built to test LLM stacks, including OpenAI, Anthropic, and open-source models, for prompt injection, jailbreaks, and agent permission misuse.
How much does Novee cost?
Pricing is not publicly listed. Interested buyers need to contact Novee directly for plan and cost details.
What compliance frameworks does Novee support?
Novee provides audit-ready evidence mapped to more than 40 frameworks, including SOC 2, ISO 27001, ISO 42001, HIPAA, and GDPR.
What tools does Novee integrate with?
Novee integrates with Jira, GitHub, and ServiceNow for ticketing and remediation handoffs, and with AI coding agents such as Claude, GitHub Copilot, Codex, and Cursor for Agentic Fix.
Do I need to provide source code to start testing?
No. Testing can begin by providing a target web domain, an API, or an uploaded mobile APK, without a lengthy onboarding process.
How does Novee avoid false-positive findings?
Its multi-agent validation deploys independent AI agents to prove exploitability, so every finding is delivered with reproduction steps and a working Python proof-of-concept script.
Novee integrates with Jira, GitHub, and ServiceNow for issue tracking, workflow, and ticketing. Its Agentic Fix capability routes remediation briefs directly into AI coding agents, including Claude, GitHub Copilot, Codex, and Cursor, and its AI Red Teaming assessments support LLM stacks from OpenAI and Anthropic.