Sprocket Security, the firm behind a continuous penetration‑testing platform, announced the availability of Apex, its first autonomous AI agent designed to probe web applications for exploitable flaws. The solution, introduced on June 30 2026, merges machine‑speed testing with the contextual knowledge accumulated by Sprocket’s platform since its inception in 2018.
AI meets continuous testing
Apex operates without authentication credentials, scanning target web applications in a fully automated, context‑aware manner. Rather than relying on generic scripts, the agent builds a hypothesis around each potential weakness, attempts exploitation, and only reports findings that survive a secondary verification step. The goal is to surface vulnerabilities that are truly exploitable, not merely theoretical.
How Apex leverages contextual data
The platform’s long‑term data collection gives Apex a distinct advantage. By pulling in every asset, technology stack, and historical test result tied to a customer, the agent can:
- Avoid duplicate alerts – prior findings are automatically filtered out, reducing noise for security teams.
- Detect regressions – if a previously fixed issue reappears, Apex flags it as a high‑priority regression.
- Prioritize severity – the severity rating is calibrated against the specific environment, reflecting real‑world risk rather than a one‑size‑fits‑all score.
These capabilities stem from the same knowledge base that powers Sprocket’s continuous testing engine, allowing each new run to build on the last and progressively refine the attack surface model.
Human‑in‑the‑loop validation
Despite its autonomous nature, Apex does not operate in a vacuum. Sprocket’s seasoned penetration testers review every result before it reaches a client’s dashboard. This double‑check—first by the AI, then by a human expert—ensures that only verified, actionable findings are delivered.
“Apex is built on everything Sprocket has learned running continuous penetration tests since 2018,” said Casey Cammilleri, Founder and CEO of Sprocket Security. “That history is the context that makes this agent good: every asset, test, and finding captured on our platform. Apex runs autonomously and our team supervises every result, so what reaches a customer is real, prioritized, and ready to act on.”
Technical architecture and data handling
Apex is engineered to run inside Sprocket’s SOC 2‑compliant environment, adhering to a zero‑data‑retention policy. The agent is mounted on a model‑agnostic harness that can swap in newer, more capable models as they become available, without exposing customer data to training pipelines. According to the company, no client data is ever used to improve the underlying AI models.
The agent’s output includes an Attack Narrative—a detailed log that records each step of the testing process, the specific vectors attempted, and whether a finding was produced. This narrative aids security teams in understanding the context of each vulnerability and streamlining remediation.
Implications for enterprise security
The introduction of Apex reflects a broader shift in the cybersecurity market toward AI‑augmented, continuous testing. Traditional penetration tests, often performed annually or semi‑annually, struggle to keep pace with the rapid release cycles of modern web applications. By automating the discovery phase while retaining expert validation, Apex promises faster detection cycles and a more accurate risk picture.
Enterprises that already employ Sprocket’s platform will likely see immediate value, as Apex can ingest existing asset inventories and testing histories without additional configuration. For organizations evaluating a move to AI‑driven security, the solution offers a concrete example of how generative AI can be harnessed for offensive security without sacrificing compliance or data privacy.
Roadmap and future developments
Full technical specifications are available in the publicly released Apex overview. Sprocket has indicated that additional AI agents—targeting other attack surfaces such as APIs, cloud workloads, and network infrastructure—are slated for rollout throughout 2026.
Power Tomorrow’s Intelligence — Build It with TechEdgeAI












