Perfai
    Perfai Security for Enterprise

    The security posture
    you can defend in front of a board.

    Perfai Security replaces drift-prone DAST suites and biannual pentest retainers with autonomous agents that re-map your surface, prove exploits, and ship the patch on every deploy. Built for the regulatory weight, paper trail, and procurement rigor enterprise security teams operate under.

    SSO, SCIM, RBAC VPC & self-hosted SOC 2 · ISO 27001 · GDPR Named TAM
    posture · acme-prod
    live
    Surface mapped
    1,284 routes
    Auth boundaries
    47
    Last full sweep
    12 min ago
    Open HIGHs
    0
    Compliance mapping
    SOC2 CC6.1SOC2 CC7.2ISO A.8.28ISO A.5.7PCI 6.2GDPR Art.32
    Last 24h
    14,221
    tests run
    3
    PRs opened
    3
    verified closed
    Operating inside the perimeters of
    Fortune 500 banksPublic-sector agenciesHealthcare networksGlobal insurersTier-1 fintechsCritical infrastructure
    The thesis

    The control gap that breaks enterprise AppSec is not coverage. It is cadence.

    Pentest reports are stale before they reach the GRC drive. DAST suites alert on probability and bury your team in triage. Perfai Security closes the gap with continuous, evidence-based testing on every deploy.

    Continuous attack surface validation

    Every deploy is re-mapped, re-attacked, and re-verified. No quarterly window. No drift between what your CMDB says and what the internet sees.

    Zero source-code requirement

    Perfai Security operates black-box against your running environments. Useful when the code lives in a JV, an acquired entity, or a contractor repo you do not control.

    Evidence over alerts

    Every HIGH ships with a deterministic exploit, an HTTP transcript, and a scoped patch. Your SOC stops triaging probability and starts closing proof.

    Patches, not tickets

    Fix Agent opens a pull request against the smallest safe surface and re-runs the exploit before marking the finding closed. Mean-time-to-remediate measured in hours.

    By stakeholder

    One platform. Different defensible outcomes.

    CISO
    Defensible posture, board-ready evidence.

    Continuous proof your perimeter holds — exportable to your GRC platform, mapped to your control framework, defensible in a regulator inquiry.

    CTO
    Velocity without a security tax.

    Security that lives inside the SDLC instead of blocking it. Findings arrive as merge-ready diffs, not a queue your platform team has to absorb.

    VP Engineering
    Predictable remediation, no surprise sprints.

    Severity gates in CI, scoped patches, and verified re-tests. Engineering owns fewer surprises and ships closer to plan.

    Head of GRC
    Evidence that survives an audit.

    Immutable test transcripts mapped to SOC 2 CC, ISO Annex A, and PCI requirements. One export, one audit binder.

    Architecture

    Engineered to pass the security questionnaire on the first pass.

    Deployment, identity, data handling, and network posture designed by people who have answered a SIG-Lite at 2am. No surprises in week three of procurement.

    Deployment options
    • Multi-tenant SaaS on AWS (us-east, us-west, eu-central, ap-south)
    • Single-tenant VPC dedicated instance
    • Self-hosted control plane on EKS, GKE, or AKS
    • Hybrid deployment — agents run in your own cluster, outbound-only
    • Regional and multi-cluster agent deployment
    • Air-gapped runners for classified or regulated environments
    Identity & access
    • SAML 2.0 / OIDC SSO with Okta, Entra ID, Ping, JumpCloud
    • SCIM 2.0 user and group provisioning
    • Role-based access control with custom roles
    • Hardware-backed MFA, short-lived tokens, no shared secrets
    Data handling
    • AES-256 at rest, TLS 1.3 in transit, customer-managed KMS keys
    • Findings and transcripts retained per your policy, default 90 days
    • PII redaction in evidence captures, opt-in only
    • Right-to-delete and export within 24 hours of request
    Network posture
    • Static egress IP ranges for allow-list firewalls
    • Private Link / PrivateLink and IP whitelisting for ingress
    • Outbound test traffic signed and identifiable in your WAF
    • Read-only by default, write operations gated by explicit allow-list
    Trust & compliance

    Audited, attested, and ready for your control framework.

    Mapped controls export directly to OneTrust, Vanta, Drata, and Hyperproof. Audit transcripts are immutable and time-stamped.

    Request trust packet
    SOC 2 Type II
    Audited annually
    ISO 27001
    ISMS certified
    GDPR / DPA
    EU data residency
    HIPAA
    BAA available
    PCI DSS 4.0
    ASV-aligned scanning
    FedRAMP-aligned
    Roadmap H2
    Procurement

    Paper that closes deals, not stalls them.

    MSA
    Master Service Agreement with red-line support
    DPA
    Standard Contractual Clauses, EU + UK addenda
    Security review
    CAIQ Lite, SIG, custom questionnaires accepted
    Insurance
    $10M cyber liability, $5M E&O
    SLA
    99.9% uptime, 30-min P1 response, named TAM
    Indemnification
    IP, confidentiality, and data processing
    Rollout

    From MSA to continuous coverage in four weeks.

    Week 0
    Scoping & paper

    MSA, DPA, security review, data residency confirmed.

    Week 1
    Connection

    SSO, SCIM, static egress IPs, first environment onboarded.

    Week 2
    Baseline

    Vision Agent maps surface, Security Agent runs first authenticated sweep.

    Week 3
    Integration

    CI gating live, Jira/ServiceNow routing live, Slack/Teams routed by team.

    Week 4
    Steady state

    Continuous scanning, weekly TAM review, monthly board export.

    MTTR reduction
    73%
    Median across enterprise rollouts
    False-positive rate
    < 1%
    Every finding ships with a working exploit
    Surface coverage
    100%
    Re-mapped on every deploy, no spec drift
    Time to first finding
    < 20 min
    From SSO login to validated HIGH
    What you stop paying for

    Consolidate two line items. Add one defensible posture.

    Perfai Security displaces the annual pentest retainer and the DAST seat license most enterprises run side by side. The math is straightforward, the audit story is stronger, and the engineering team stops absorbing the slack between them.

    Replaces the pentest retainer
    Continuous, evidence-based testing replaces the biannual PDF that ages out in six weeks.
    Replaces brittle DAST
    Typed surface model replaces signature fuzzers, eliminating the false-positive triage budget.
    Extends to acquired entities
    Black-box onboarding for JVs, subsidiaries, and post-M&A environments without source access.
    Reduces cyber-insurance premium
    Continuous attestation evidence accepted by major carriers as a posture signal.
    FAQ

    Questions enterprise security teams actually ask.

    Can Perfai Security run inside our VPC with no outbound internet?+

    Yes. The control plane and test runners deploy into your AWS, GCP, or Azure account via Helm. Egress to perfai.ai is optional for license check-in and disabled in air-gapped mode.

    How do you handle production traffic and risk of impact?+

    Write operations are gated by explicit allow-list. Payloads are non-destructive by default. Rate limits respect your environment caps. Pre-prod is recommended for first runs; production scanning is opt-in per service with a kill switch tied to your SRE on-call.

    Do you support custom auth schemes — mTLS, SAML assertions, custom JWT claims?+

    Yes. mTLS with client certs, SAML, OIDC, OAuth client credentials, refresh-token flows, and custom login scripts. We have onboarded environments with header-signed tokens, Kerberos handoff, and legacy WS-Trust.

    Where is data stored and who can access it?+

    Findings, transcripts, and configuration live in the region you select at provisioning. Customer data is encrypted with KMS keys you can rotate or revoke. Perfai Security engineers access customer tenants only via break-glass with audit logging surfaced to you in real time.

    How does Perfai Security compare to traditional DAST and pentest retainers?+

    Legacy DAST fuzzes blindly and produces noise. Pentest retainers produce a PDF twice a year. Perfai Security produces a typed model of your API, deterministic exploits, scoped patches, and re-tests every commit. It replaces both line items in most enterprise budgets.

    What does enterprise pricing look like?+

    Annual contract priced on number of environments, surface size, and integration depth. Includes a named Technical Account Manager, quarterly business review, and unlimited Security Engineer office hours.

    Ship secure AI apps

    Try Perfai Security now

    Point us at a URL. First finding in under 20 minutes. No credit card.