Xint.io Named IDC Innovator for Agentic Penetration Testing
Today Xint.io announced that it was included in the IDC Innovators: Autonomous Penetration Testing for DevSecOps report. The report profiled seven emerging vendors providing autonomous AI agent-driven penetration testing for DevSecOps. Xint.io was recognized for behavioral testing focused on application logic, not being tied to a single AI model, and how it covers the entire attack surface – from source code to runtime production.
Also Read: Enterprise AI Readiness Assessment: A Practical Framework
AI-generated code and modern software practices are expanding the attack surface faster than traditional human-led penetration testing can scale up to protect it. Autonomous penetration testing fills this gap. Unlike traditional automated testing, which executes predefined security checks, agentic systems continuously reason about the environment, determine which attack paths to pursue, and adjust based on what they learn.
“This report helps show the need for autonomous penetration testing technology, and why it must produce usable outputs that fit into existing workflows,” said Kay Kyoung-ju Kwak, Head of Xint. “We’re grateful for this recognition of our approach of taking the expertise of the world’s most decorated white hat hackers and scaling it to the modern threat posed by AI-armed attackers.”
“The value of autonomous pentesting will depend less on finding volume and more on whether the output is validated, prioritized, and usable in existing DevSecOps workflows.”
– IDC Innovator: Autonomous Penetration Testing for DevSecOps, (Doc# US54175326), July 2026
Xint scales offensive security across source code and live applications, delivering confirmed vulnerabilities with full attack paths, reproduction steps, and suggested fixes in an audit-ready report in hours, not weeks. It is built on real penetration testing methodology to find complex multi-step attack chains, by the team behind record wins at DEF CON and Pwn2Own, along with wins at DARPA’s AIxCC and Zeroday.Cloud from Google Wiz. Customers include DARPA, Samsung, LG Electronics, Hyundai and many more. Xint’s technology uses LLMs combined with a proprietary orchestration engine to identify, reproduce, validate and understand critical security vulnerabilities in web application code. It can analyze millions of lines of source code, configuration files and binaries in less than 12 hours at the same depth and detail as a human penetration tester.
Also Read: IT Tech Pulse Exclusive Interview with Pete Johnson Field CTO, Artificial Intelligence at MongoDB
The Xint Platform includes Xint Code, which offers source code analysis, and Xint Web, which offers live web application testing. They also offer Xint Pulse, a one-time scan of a single web application by the full Xint Web engine, priced for small and medium-sized businesses and individual researchers.
Write to us [wasim.a@demandmediaagency.com] to learn more about our exclusive editorial packages and programmes.