Operation orchestration
Run each engagement as one living record: phases, operators, scope and status in a single place.
Human-AI Validated Offensive Cybersecurity
KAIX HAVOC is a platform to run offensive security audits end to end: assets, findings, reports and retesting in a single flow. AI handles the heavy lifting; a human validates every finding before it reaches the report.

The product
HAVOC ships with a platform where every audit lives in one place: from the engagement dashboard to the asset map, from the findings list to the collaboration between your experts and the AI agents. Every decision is recorded with full traceability.
Findings list
Severity, affected agent and status for every finding.
Asset map
The audited perimeter, asset by asset, with its exposure.
Human-AI collaboration
The expert validates and steers the agents in the loop.
Finding microreport
An actionable summary of each vulnerability, ready for the report.
Monitoring & budget
Events, model consumption and audit cost under control.
The platform
From scope to retest: no scattered spreadsheets, no hand-built reports.
Run each engagement as one living record: phases, operators, scope and status in a single place.
Inventory targets, lock rules of engagement, track exposure per asset.
AI-proposed findings with human validation, severity, dedup and ownership.
Generate client-ready reports with PoCs and remediation from the record.
Re-validate fixes on demand; watch fixed-vs-open trends across operations.
Every operation, decision and tool_call captured immutably: full provenance an auditor can replay instead of a screenshot folder.
Architecture
Five layers that work together. To you it's a single product; underneath, each piece has a clear responsibility.
Web console
Your team, in control
Orchestration platform
Rules engine + scope guard
Isolated environment · VPN/SSH to targets
Evidence store
Traceable & reproducible
Human-AI Validated
HAVOC's edge over fully automated pentesting: every finding goes through an expert before it enters the report.
Agents map the scope, enumerate the attack surface and propose prioritized attack vectors.
AI tests vectors and generates PoCs; the pentester steers and digs in where it really matters.
An expert confirms every finding, rules out false positives and adjusts real severity and impact.
The report is generated and, after remediation, HAVOC re-verifies and documents the closure.

Comparison
Scanners, manual pentesting, black-box autonomous tools and where HAVOC fits.
| Coverage & depth | Continuity | Validated findings | Human-AI collaboration & EU focus | |
|---|---|---|---|---|
| Generic scanners | Broad but shallow, no reasoning, high noise | Continuous | No — unvalidated output with many false positives | None. No EU specificity |
| Manual pentesting | Deep, expert-driven | Point-in-time, doesn't scale | Yes, but slow and costly | Fully human, no AI leverage |
| Autonomous AI pentesters (e.g. XBOW) | Deep on supported targets | Continuous | Partial. Black-box operation | Non-EU providers |
| KAIX HAVOC | Full lifecycle over IT and AI systems | Continuous. Re-audits on change or new threats | Yes. Every finding validated with a reproducible recipe | Native human-agent collaboration, deterministic scope, European focus |
European & compliant
European sovereignty, reproducible evidence and results that speak the language of auditors and regulators.
Runs on European models and EU infrastructure. The core always runs on infrastructure controlled by KAIX.
Every finding ships with a recipe that reproduces it step by step. Once your team fixes it, just hit «Retest» to re-validate the fix.
Data minimisation, traceability and human oversight from the start. Findings align with the frameworks that apply (NIS2, CRA, ENS…).
Early access
We're onboarding security teams and consultancies as early adopters. Join the waitlist and we'll let you know the moment your access opens.
Automated offensive security uses AI agents to carry out the work of a pentest (reconnaissance, exploitation and validation) continuously and at scale, instead of relying on specialist hours alone. In HAVOC the agents investigate and test, and a person steers and validates every finding.
KAIX HAVOC (Human-AI Validated Offensive Cybersecurity) is an AI-based penetration testing and security auditing platform, directed by your team. It orchestrates 15+ specialised agents that cover the full audit lifecycle (reconnaissance, exploitation, validation and reporting) across conventional IT and AI systems.
For pentesting teams and consultancies that want to multiply their reach, and for organisations without an in-house team that need continuous, professional audits. Also for companies that build or run AI in production and need to audit both their IT and their AI systems.
Scope (what can and cannot be touched) is enforced by deterministic layers of code at every step, never an agent's judgement. Agents operate in an isolated environment that reaches targets over VPN or an SSH jump host, connection secrets are never exposed to the agents, and sensitive actions require human approval.
Yes. Beyond conventional IT (web, systems and infrastructure), HAVOC audits AI systems in production (language models, assistants and agents) covering specific risks such as prompt injection, data leakage or tool misuse.
KAIX HAVOC is in early access, with onboarding by waitlist. It's a European platform: it runs on European models and EU infrastructure, and its results align with frameworks such as NIS2, CRA or ENS.