Skip to content
Early access
KAIX HAVOC

Human-AI Validated Offensive Cybersecurity

Orchestrate your pentests and red teaming with AI validated by experts.

KAIX HAVOC is a platform to run offensive security audits end to end: assets, findings, reports and retesting in a single flow. AI handles the heavy lifting; a human validates every finding before it reaches the report.

Engagement dashboard

The product

A look inside HAVOC

HAVOC ships with a platform where every audit lives in one place: from the engagement dashboard to the asset map, from the findings list to the collaboration between your experts and the AI agents. Every decision is recorded with full traceability.

Findings list

Severity, affected agent and status for every finding.

Asset map

The audited perimeter, asset by asset, with its exposure.

Human-AI collaboration

The expert validates and steers the agents in the loop.

Finding microreport

An actionable summary of each vulnerability, ready for the report.

Monitoring & budget

Events, model consumption and audit cost under control.

The platform

One platform for the entire offensive audit

From scope to retest: no scattered spreadsheets, no hand-built reports.

Operation orchestration

Run each engagement as one living record: phases, operators, scope and status in a single place.

Asset & scope

Inventory targets, lock rules of engagement, track exposure per asset.

Findings & triage

AI-proposed findings with human validation, severity, dedup and ownership.

Reports

Generate client-ready reports with PoCs and remediation from the record.

Retesting

Re-validate fixes on demand; watch fixed-vs-open trends across operations.

Monitoring & immutable audit log

Every operation, decision and tool_call captured immutably: full provenance an auditor can replay instead of a screenshot folder.

Architecture

How HAVOC works under the hood

Five layers that work together. To you it's a single product; underneath, each piece has a clear responsibility.

Web console

Your team, in control

Orchestration platform

Rules engine + scope guard

Isolated environment · VPN/SSH to targets

  • Recon
  • Web
  • Exploitation
  • Systems
  • Cryptography
  • Forensics
  • Reverse eng.
  • Validation

Evidence store

Traceable & reproducible

Agent timeline: every action, observation and tool, logged live.

Human-AI Validated

AI explores. Humans validate.

HAVOC's edge over fully automated pentesting: every finding goes through an expert before it enters the report.

  1. 01

    AI recon

    Agents map the scope, enumerate the attack surface and propose prioritized attack vectors.

  2. 02

    Assisted exploitation

    AI tests vectors and generates PoCs; the pentester steers and digs in where it really matters.

  3. 03

    Human validation

    An expert confirms every finding, rules out false positives and adjusts real severity and impact.

  4. 04

    Report & retest

    The report is generated and, after remediation, HAVOC re-verifies and documents the closure.

Exploitation chain with its evidence: how each result was obtained, reproducible.
Exploitation chain with its evidence: how each result was obtained, reproducible.

Comparison

HAVOC vs the alternatives

Scanners, manual pentesting, black-box autonomous tools and where HAVOC fits.

Coverage & depthContinuityValidated findingsHuman-AI collaboration & EU focus
Generic scannersBroad but shallow, no reasoning, high noiseContinuousNo — unvalidated output with many false positivesNone. No EU specificity
Manual pentestingDeep, expert-drivenPoint-in-time, doesn't scaleYes, but slow and costlyFully human, no AI leverage
Autonomous AI pentesters (e.g. XBOW)Deep on supported targetsContinuousPartial. Black-box operationNon-EU providers
KAIX HAVOCFull lifecycle over IT and AI systemsContinuous. Re-audits on change or new threatsYes. Every finding validated with a reproducible recipeNative human-agent collaboration, deterministic scope, European focus

European & compliant

Built to audit with guarantees

European sovereignty, reproducible evidence and results that speak the language of auditors and regulators.

European sovereignty

Runs on European models and EU infrastructure. The core always runs on infrastructure controlled by KAIX.

Reproducible evidence & retest

Every finding ships with a recipe that reproduces it step by step. Once your team fixes it, just hit «Retest» to re-validate the fix.

Compliance-ready

Data minimisation, traceability and human oversight from the start. Findings align with the frameworks that apply (NIS2, CRA, ENS…).

Early access

KAIX HAVOC is in early access

We're onboarding security teams and consultancies as early adopters. Join the waitlist and we'll let you know the moment your access opens.

Frequently asked questions

What is automated offensive security?

Automated offensive security uses AI agents to carry out the work of a pentest (reconnaissance, exploitation and validation) continuously and at scale, instead of relying on specialist hours alone. In HAVOC the agents investigate and test, and a person steers and validates every finding.

What is HAVOC?

KAIX HAVOC (Human-AI Validated Offensive Cybersecurity) is an AI-based penetration testing and security auditing platform, directed by your team. It orchestrates 15+ specialised agents that cover the full audit lifecycle (reconnaissance, exploitation, validation and reporting) across conventional IT and AI systems.

Who is HAVOC for?

For pentesting teams and consultancies that want to multiply their reach, and for organisations without an in-house team that need continuous, professional audits. Also for companies that build or run AI in production and need to audit both their IT and their AI systems.

How does HAVOC control the scope of an audit?

Scope (what can and cannot be touched) is enforced by deterministic layers of code at every step, never an agent's judgement. Agents operate in an isolated environment that reaches targets over VPN or an SSH jump host, connection secrets are never exposed to the agents, and sensitive actions require human approval.

Does HAVOC also audit AI systems?

Yes. Beyond conventional IT (web, systems and infrastructure), HAVOC audits AI systems in production (language models, assistants and agents) covering specific risks such as prompt injection, data leakage or tool misuse.

Is it available? Is it European and compliant?

KAIX HAVOC is in early access, with onboarding by waitlist. It's a European platform: it runs on European models and EU infrastructure, and its results align with frameworks such as NIS2, CRA or ENS.