Skip to content

Frequently Asked Questions

How does Sable work?

You log into app.vulnetic.ai, start a pentest, and walk away. Sable takes the same approaches as an expert human, performing detailed enumeration and exploitation of the target while executing its commands and tools in a sandboxed Docker container. Sable continues attacking until it hits the time limit or runs out of in-scope targets to exploit.

What makes Vulnetic different than others?

At Vulnetic, we believe in full transparency and user control. While other solutions claim to use AI, you are often handing your credentials and targets to a black box. With Sable, you can see every command, thought, and task as it executes and throttle the level of autonomy to be as hands-off or hands-on as you want. Sable supports assessments across Active Directory, web applications, and Android mobile apps.

How long does an AI penetration test take?

It varies, but 6-8 hours is typical for a web application penetration test. The assessment can continue as long as you give the system additional tasks to complete, or it can stop itself when Sable decides the target has been fully exploited.

How is Vulnetic different than DAST scanners?

DAST scanners run predefined checks against known vulnerability signatures. They scan; they do not think. Sable operates like an actual penetration tester: it enumerates, reasons about what it finds, chains exploits together, and adapts its approach based on the target's responses. A DAST scanner might flag a missing header; Vulnetic will find the business logic flaw that lets an attacker escalate privileges.

Does Vulnetic need access to my source code?

No. By default, Vulnetic operates as a black-box or gray-box tester, attacking your application the same way a real adversary would. You provide a target URL or IP and credentials, if applicable, and Sable handles the rest. If you want a white-box assessment, you can give Sable access to source code for deeper coverage, but it is never required.

Is Sable just a GPT wrapper?

No. Vulnetic is a purpose-built offensive security platform with a proprietary architecture built from the ground up. LLMs are fundamental to our stack, but they sit inside a patent-pending system with a custom dynamic runtime that orchestrates multi-stage attack chains, manages sandboxed execution environments, and adapts in real time.

What type of technologies can Vulnetic test?

Vulnetic supports web applications, REST and GraphQL APIs, cloud infrastructure, internal networks, Active Directory environments, and Android mobile applications. If your team pentests it today, Sable can likely test it too.

Does Vulnetic satisfy the pentest requirement for SOC 2 compliance?

Yes. Vulnetic produces detailed penetration test reports with findings, severity ratings, evidence, and remediation guidance: the same deliverables auditors expect. Our reports are accepted by SOC 2 auditors as evidence of penetration testing controls. You get continuous testing coverage instead of a once-a-year engagement.

How is Vulnetic different than traditional Breach and Attack Simulation vendors?

BAS platforms simulate known attack patterns against your defenses. They test whether your controls catch predefined TTPs. Vulnetic goes further: Sable actually discovers and exploits real vulnerabilities in your environment, just like a skilled attacker would. BAS tells you if your alarm works; Vulnetic tells you if someone can actually break in.

What type of controls do I have to manage a Vulnetic pentest?

Full control. You define the scope, set the autonomy level, and can watch every command and thought Sable executes in real time. You can pause, stop, or redirect the assessment at any point. Autonomy throttling lets you choose between fully autonomous operation or a more hands-on approach where Sable asks for approval before executing commands.

Next