Loading…
Loading…
The same P1/P2 hunting methodology our analysts use by hand — running on demand against the targets you describe in plain English. Subdomain enumeration, attack-surface mapping, vulnerability discovery, board-ready reporting.
First scan free with code FIRSTSCAN — no card required.
Every Coastline engagement is validated, evidence-backed, and written up like a human consultant would.
Each finding is gated by a proof-of-exploitation check and, where a distinct validator is available, a second independent model runs an adversarial false-positive pass — only demonstrated, evidence-backed findings reach you.
Every finding ships the exact request/response or PoC that proves it. Reproducible, not theoretical.
Every finding carries a CVSS v4.0 score and CWE classification, severity triaged on the industry-standard VRT scale — ready to triage and track.
Concrete, configuration-level fix steps written for each finding.
A Coastline-branded report: executive summary, matrix of findings, detailed write-ups, methodology.
Exactly what was tested vs only enumerated — a straight answer to "did you test this host?"
Paste your scope in plain English — domains, IPs, what's in and out.
Subdomain enumeration, attack-surface mapping, and active exploitation across 25+ vulnerability classes.
Every candidate finding must pass a proof-of-exploitation gate, backed by a second-model adversarial pass where available, before it's reported.
Download a board-ready report the moment the engagement completes.
Every finding in your report carries severity, CWE, CVSS, the affected asset, impact, a reproducible proof, and remediation. This is the exact structure of the DOCX you download.
Create a free account and redeem FIRSTSCAN for a complete engagement — no card required: the same full-depth pentest, validated findings, verbatim PoC evidence, and full report paying customers get. Nothing watermarked, nothing redacted. Then keep going from $895/mo. 1 credit = 1 pentest.
30-day money-back guarantee — no actionable findings, full refund.
Subscriptions are always the cheapest per scan (from $199.66 on Agency) — packs are pay-as-you-go top-ups for any plan. Subscriptions renew monthly; cancel anytime. Unused budget on under-scope scans is auto-refunded. Prices in USD.
| Package | Price | Credits | Per scan | Best for |
|---|---|---|---|---|
| Single Scan | $895 | 1 | $895 | One-off / first test |
| Starter Pack | $2,245 | 5 | $449.00 | Quarterly testing |
| Pro Pack | $6,495 | 20 | $324.75 | Monthly across apps |
| Team Pack | $13,745 | 50 | $274.90 | Continuous / MSP |
| Coastline | Traditional pentest | Vuln scanner | |
|---|---|---|---|
| External pentest price | from $199/scan | $5,000–$15,000 | $100–$300/mo |
| Turnaround | Hours | 2–4 weeks | Minutes |
| Validated findings (no false-positive dump) | ✓ | ✓ | ✗ |
| Verbatim PoC evidence | ✓ | ✓ | Partial |
| Professional report (exec + matrix + remediation) | ✓ | ✓ | ✗ |
| Run on-demand & repeat | ✓ | No (re-quote) | ✓ |
| Cost to re-run | 1 credit | Full re-engagement | Included |
Scanner speed and price, with the validation and reporting of a real pentest.
What autonomous penetration testing is, how it differs from a vulnerability scanner, and how a Coastline engagement is scoped, run and reported.
Autonomous penetration testing is a security engagement in which software performs the reconnaissance, exploitation and reporting work a human penetration tester would normally do by hand. Coastline Cyber Security's autonomous penetration testing platform runs the same P1/P2 hunting methodology Coastline analysts use manually — subdomain enumeration, attack-surface mapping and vulnerability discovery — on demand against targets you describe in plain English, and returns a board-ready report.
A vulnerability scanner matches known signatures and reports what might be vulnerable; autonomous penetration testing attempts to exploit the issue and reports only what it proved. Every Coastline finding must pass a proof-of-exploitation gate before it reaches your report, and ships with the verbatim request and response that demonstrate it, plus a CVSS v4.0 score, a CWE classification and configuration-level remediation steps.
A Coastline engagement runs in four stages. You describe the target in plain English, including domains, IP ranges and what is out of scope. The agent then performs subdomain enumeration, attack-surface mapping and active exploitation across 25+ vulnerability classes. Every candidate finding must pass a proof-of-exploitation gate before it is reported. The board-ready report is available to download the moment the engagement completes.
Autonomous penetration testing performs active testing against live systems, so every Coastline engagement is bounded by an explicit scope and a signed authorization. Rules of Engagement must be accepted once per tenant before the first scan, including an emergency contact and a warrant that you are authorized to test the assets you submit. Acceptance is timestamped, IP-logged and versioned, and out-of-scope carve-outs override anything an in-scope entry would otherwise match.
A Coastline autonomous penetration test completes in hours, against the two to four weeks a traditional external engagement typically needs to schedule, execute and write up. The report can be downloaded the moment the engagement completes. Runtime scales with scope: a single host finishes faster than a root domain whose subdomains are enumerated and tested, and budget can be topped up mid-run if a deep scope needs more runtime.
Coastline prioritizes the P1 and P2 classes that cause real breaches: remote code execution, authentication bypass, exposed admin portals and privileged IDOR at P1, then classes such as CSRF, sandboxed template injection and OAuth account takeover at P2 — 25+ vulnerability classes in total. Subdomain enumeration and attack-surface mapping run first, so testing reaches forgotten hosts and undocumented endpoints, not only the URL you supplied.
Every candidate finding is gated by a proof-of-exploitation check before it can be reported, and where a distinct validator is available a second independent model runs an adversarial false-positive pass. Findings that survive ship with the exact request and response, or the proof of concept, that demonstrates them. Each report also carries a coverage appendix stating what was actually tested versus only enumerated.
No. Autonomous penetration testing changes how often you can test, not whether expert judgment matters. Coastline automates the P1/P2 hunting methodology its analysts use by hand, which makes external testing cheap enough to run every release rather than once a year. Complex business logic, chained attacks and unusual targets still benefit from a consultant, and Coastline delivers both automated engagements and human-led testing and consulting.
Scope is written in plain English — for example, run a black-box external pentest against acme.com, focus on the auth endpoints, and exclude anything under /admin. Coastline's planner converts that prompt into a structured spec with editable in-scope and out-of-scope host lists, which you review before any budget is spent. A scope file exported from an SOW or scope document can also be uploaded as CSV, TXT, JSON or Markdown.
Coverage has three layers, and credits buy depth rather than a fixed asset count. Every in-scope host is enumerated and inventoried, with no cap. Liveness probing then reaches up to roughly 2,600 hosts in a single scan. Deep testing with the full per-host probe suite covers about 268 hosts on a one-credit scan, around 1,429 at five credits, and up to 2,000 at ten or more; headless browser rendering scales with the same allocation, so a larger pack buys proportionally more of it. A rate limit in your rules of engagement lowers these figures, because the engine paces itself to the limit you declare. Whatever the numbers work out to on your estate, the report's coverage appendix names exactly which assets were tested and which were only enumerated, so coverage is never something you have to take on trust.
Each report includes an executive summary, a matrix of findings, detailed write-ups, the methodology used, and a coverage appendix showing what was tested versus only enumerated. Every finding carries a CVSS v4.0 score, a CWE classification, VRT-scale severity, the affected asset, its impact, a reproducible proof of concept with verbatim request and response, and concrete remediation steps. Reports download as a Coastline-branded document.
Coastline prices autonomous penetration testing in credits, where one credit equals one complete pentest. The first scan is free with code FIRSTSCAN and no card is required. Monthly plans start at $895 per month, and pay-as-you-go starts at $895 for a single scan with lower per-scan pricing on larger packs. Only credits actually burned are consumed; unused budget rolls back to your balance when the scan finishes.
Yes. A re-test re-runs the same scope to check whether a previously reported finding is still exploitable, and stays linked to the original engagement for a closed-loop view. Re-running costs one credit rather than a new engagement quote. Engagements can also be scheduled to repeat on a daily, weekly or monthly cadence, and a continue-deeper run spawns a focused child engagement on a single lead.
Create your free account and run your first scan — redeem FIRSTSCAN for a free engagement. No card required.
Already have an account? Sign in
Stuck? Reset auth state
Subscribe for a monthly credit allowance at a lower per-scan price. Cancel anytime; the pay-as-you-go packs below top up any plan (including Free).
Loading plans…
Each credit buys one full pentest engagement. Credits never expire, and unsatisfactory runs are refundable for 30 days.
Loading packages…
New accounts: redeem a code for a free scan.
Admin-only dev grant — bypasses billing for testing.
A project bundles related engagements under one umbrella so you can track an asset over time, compare scans, and share access with specific teammates.
Click + New project above to start.
Org-wide visibility. Add members to restrict.
Everything the agent has ever discovered in your footprint, deduplicated across every engagement. A "new" asset appears for the first time in a scan; a re-confirmed asset was already on file. First-seen and last-seen timestamps drive the delta-pentest view.
No assets discovered yet. Run an engagement to populate the inventory.
| Type | Value | Seen | First | Last |
|---|---|---|---|---|
Roles control what each member can do. Owners + Admins manage members, billing, and notifications; Operators run scans + triage; Viewers read reports. Owner/Admin can flip per-member notification toggles below — each member can also control their own from Settings.
Loading members…
| Role | Notifications | Last sign-in | ||
|---|---|---|---|---|
| you suspended |
No pending invites. Use the form below to invite a teammate.
| Role | Invited by | Expires | ||
|---|---|---|---|---|
| expired |
We'll send them an email with a single-use link to join this org. Invites expire in 14 days. Only owners can invite admins.
Use these for CI/CD integrations. Send as
Authorization: Bearer cstk_….
Tokens are only shown once on creation — store them securely.
No API tokens yet. Create one below to integrate Coastline with your CI/CD or scripted tooling.
revoked
expired
Notifications go to .
Your account identity. Email is managed by Auth0 — to change it, update your Auth0 profile and log back in.
Most-recent RoE acceptance per member of . Current canonical version: . Older versions render in amber; unsigned members are flagged so an admin can chase them before a vendor due-diligence review.
| Name | Accepted version | Accepted at | Signer IP | User-Agent | |
|---|---|---|---|---|---|
| unsigned | — | server-only | server-only |
This is your attack surface: every in-scope live host we found, which ones we have probed, and which are still waiting. Amber rows are discovered-but-not-yet-probed gaps. Hover any number for what it counts.
| Vuln class | Probes | Vulnerable | Clean |
|---|---|---|---|
| Host : Port | Status | Last test result | Vuln classes attempted |
|---|---|---|---|
| Not yet tested. No findings on this asset. Probe blocked at network layer. |
|
||
| No assets match the current filter. | |||
| Repo | PR | Title | Opened |
|---|---|---|---|
| Kind | Label | Planted where | Hits | Last hit |
|---|---|---|---|---|
No findings reported yet.
Recurring engagements run automatically on the cadence you set. Each run is queued shortly after its scheduled time and only actually-burned credits are charged — unused budget rolls back to your balance.
| Target | Cadence | Next Run | Status | Actions |
|---|---|---|---|---|
|
|
Acceptance of the current Rules of Engagement is required before launching a scan. Please review the document below and sign — or cancel to return to the dashboard.
Required once per tenant before your first engagement. Provide an emergency contact and accept the Gold Standard Safe Harbor.
Tick the acknowledgement box above to continue. Enter your emergency contact email and full name to continue.