RunSybil
RunSybil is an AI-powered offensive security platform whose autonomous agents continuously test applications, APIs, cloud and infrastructure, then exploit and validate what they find so engineering teams receive only proven, reproducible vulnerabilities on every deployment.
What is RunSybil?
RunSybil Corp. is a Delaware-incorporated American company based in San Francisco, with a second hub in New York and a hybrid team. Its product is Sybil, a system of AI agents that performs offensive security testing: the company is RunSybil, the agent is Sybil. It was founded in 2023 by Ari Herbert-Voss, chief executive and OpenAI's first security hire, a core research contributor to GPT-3 and Codex, and Vlad Ionescu, chief technology officer, previously a red teamer at Mandiant and NCC Group, offensive security tech lead at Meta and founder of Red Team X. The wider team comes from OpenAI, Meta, Mandiant, NCC Group and Trail of Bits. The premise is that a point-in-time penetration test and a bug bounty both fail modern release cadence, one because it is stale on delivery, the other because its cost and coverage are unpredictable. Sybil replaces both with continuous testing across code, APIs, cloud and infrastructure, concentrating on the flaws that only exist where components meet. Teams choose their depth: black-box needs no source code or internal access, grey-box adds API documentation, architecture diagrams or a test account, and opt-in white-box adds source code for code-level root cause and remediation. Sybil authenticates itself, maps the application, then runs a hierarchy of specialised agents covering authentication, business logic and injection, chaining findings into real exploit paths. Six families are covered: access control, server-side, business logic, injection, client-side, and novel bugs matching no known signature. Every finding carries a CWE identifier, a CVSS 3.1 score, the HTTP request and response pair, reproduction steps, the full exploit chain, a validation log and contextualised business impact. Coverage is auditable rather than assumed: every action is logged, surface and coverage maps show what was tested and what was not, and a finding can be questioned directly. Engagements start on onboarding day, small applications finish same-day, large ones within twenty-four hours, and retests in under an hour. Named customers include Cursor, Turbopuffer, Notion, Baseten and Thinking Machines Lab. Access is by contract only, through a web application.
What it does
- Finds, exploits and validates real vulnerabilities across web applications, APIs, cloud and infrastructure
- Chains separate weaknesses into complete, reproducible exploit paths the way a human attacker would
- Authenticates on its own, from passwords and TOTP to magic links, email OTP, Okta and SSO, and builds its own test accounts
- Maps the application's purpose, technology stack and full attack surface before any testing begins
- Filters out false positives through a multi-agent pipeline of critique, clean-session reproduction, triage and deduplication
- Produces remediation precise enough for an AI coding assistant to apply, then retests to prove the fix holds
- Re-tests only what changed, triggered by a pull request, a manual run or a scheduled cadence
When to use RunSybil / When not to
A quick filter to help you decide if RunSybil is the right fit.
When to use RunSybil
- Security and engineering teams that ship several times a week, for whom an annual penetration test is already stale by the time the report lands
- Companies running multi-tenant SaaS, where cross-tenant data access, privilege escalation and broken authorisation are the failures that actually hurt
- Organisations preparing a SOC 2 Type II or ISO 27001 audit and needing findings already formatted with CVSS 3.1 scores and CWE identifiers
- Fast-growing startups that must hand a credible penetration test report to a prospect before a deal can close, as Cursor did
- Enterprises replacing an unpredictable bug bounty budget with continuous coverage at a contracted, predictable cost
When not to use RunSybil
- Individuals and small teams: there is no self-service sign-up and no public price, only a countersigned Service Order
- Anyone shopping for a cheap signature scanner or a static analysis tool, since RunSybil positions itself explicitly against both
- Teams whose priority is testing native mobile applications, as the stated scope covers web, APIs, cloud and infrastructure
- Buyers who need a signed data processing agreement, a published subprocessor list or a documented hosting country before they can commit
- Operators of systems where a temporary slowdown, an intrusion-detection alarm or a crash would be unacceptable, since the client contractually accepts those risks
How to use RunSybil
A typical end-to-end flow, from setup to results.
- Request a demo through the booking form, the only entry point: there is no self-service sign-up
- Negotiate and countersign a Service Order, which fixes the services, the tests, the features and the fees
- Create the organisational account and appoint at least one administrator to open sub-accounts and assign permissions
- Define the scope at the level of detail you would give a third-party penetration testing firm
- Warn your own security and engineering teams before testing starts, and obtain a signed authorisation letter for any third-party system in scope
- Point Sybil at a live URL; it starts exploring immediately and handles authentication on its own
- Optionally supply credentials for pentest-equivalent depth, or source code for white-box coverage and code-level remediation
- Connect GitHub or GitLab so findings reach engineers in the workflow they already use
- Trigger tests by pull request, by hand, or on a recurring weekly, monthly or quarterly schedule
- Apply the Fix with AI flow through Codex, Claude Code or Cursor, then launch a retest to confirm the fix holds
Pros & Cons
Pros
- Validates exploitability instead of flagging patterns: nothing surfaces until it has been independently reproduced
- False positives reduced by more than ninety percent against conventional scanners, according to the company's March 2026 announcement
- Real cadence: findings on every pull request and retests in under an hour, with no scheduling
- No source code required to start, since credentials and source code are both optional
- Coverage you can audit, including the ability to ask an agent what it did and did not test
- Output pre-formatted with CVSS 3.1 and CWE, which customers have used in SOC 2 Type II and ISO 27001 audits
- Credible backing: a founding team from OpenAI, Meta, Mandiant and Trail of Bits, named reference customers and forty million dollars raised
Cons
- No public pricing at all: there is no pricing page and every figure sits inside a negotiated Service Order
- No published privacy policy, a notable gap for a tool that reaches into customer systems and source code
- No subprocessor list, no data processing agreement and no disclosed hosting country or region
- The stance on model training is undeclared: the licence covers improving RunSybil's products without saying whether models learn from customer data
- SOC 2 Type 2 is claimed on the trust centre but the document sits behind an access request, so the certification could not be observed
- An API exists but no public documentation describes it
- Commercially binding: twelve-month auto-renewing term, non-refundable fees, mandatory arbitration and contractually accepted testing risks
Pricing & Plans
RunSybil publishes no pricing. There is no pricing page on the site, the structured data describing the product carries an offer with neither a price nor a currency, and no starting price point can therefore be stated. Neither a permanent free plan nor a free trial is advertised, and neither is expressly ruled out. Commercial terms are set individually in a Service Order countersigned by both parties, which fixes the fees and the usage entitlements such as the number of tests. Subscriptions run for an initial twelve months and renew automatically for successive twelve-month periods unless either party gives thirty days' written notice, and RunSybil may adjust renewal fees on thirty days' notice. Usage beyond the agreed entitlements is billed at the Service Order rate or at standard rates, unused entitlements do not carry over, and fees are invoiced in United States dollars, payable within thirty days and non-refundable. One customer describes the price as competitive and on a par with top penetration testing firms.
Data, GDPR & hosting
A consolidated view of how RunSybil handles your data.
GDPR overview
The acronym GDPR appears nowhere on the site. What exists is narrower: both the Platform Agreement and the Reseller Agreement state that, for the purposes of EU privacy laws, the client is the data controller and RunSybil is at all times the data processor, and both place on the client the warranty that it complies with applicable data protection law and has obtained any consent required from the individuals whose data appears in the materials. Beyond that allocation of roles, nothing. No data processing agreement is published or offered, no Article 27 EU representative is designated, no data protection officer is named, no privacy contact address exists, no standard contractual clauses or international transfer mechanism is mentioned, and no hosting country is disclosed. Governing law is Californian and disputes go to arbitration in San Francisco.
Who owns the data?
The client keeps ownership. Client Materials, meaning the systems, test environments, data and intellectual property handed to RunSybil or obtained during testing, remain the client's, and RunSybil receives only a licence to use them. RunSybil assigns to the client all rights in the reports it delivers, keeping only its pre-existing technology and its logos. Any finding that a vulnerability exists on the client's systems is expressly the client's Confidential Information. Two things flow the other way: feedback, whose intellectual property rights the client assigns to RunSybil, and the client's name and logo, which RunSybil may use as a commercial reference until asked in writing to stop.
Reuse rights
The client may reuse the reports freely: RunSybil assigns all rights in the delivered reports, except its own pre-existing technology and logos, so no permission is needed to circulate them internally or hand them to an auditor or a prospect. In the other direction, the client grants RunSybil a royalty-free licence to use and process Client Materials for three stated purposes: to perform, support and improve its products and services; to maintain quality control and compliance records; and to make or support regulatory filings. That licence may be extended to contractors working for RunSybil or its affiliates. The word improve is never defined, and with no privacy policy published, the site never says whether it covers training AI models.
Data retention & training
Hosting summary
Nothing is disclosed. No hosting country and no hosting region appears anywhere: not on the product or company pages, not in the Platform Agreement or the Reseller Agreement, and not on the trust centre. What the contract does establish is that RunSybil may use affiliates, suppliers and subcontractors while remaining responsible for their performance, and that confidential information stored securely through third-party applications is not treated as a disclosure. Third-party infrastructure is therefore contemplated, but none of it is named. The security commitment is stated in general terms only: policies, procedures and technical, physical and administrative safeguards designed to protect confidential information against reasonably foreseeable threats. On jurisdiction, the company is incorporated in Delaware and operates from San Francisco, the agreements are governed by Californian law, and disputes are arbitrated in San Francisco, so United States jurisdiction governs the relationship even though the physical location of the data is unstated. The website's own IP address resolves to a Cloudflare anycast node, which says nothing about where customer data is held.
Things to keep in mind
Risks and trade-offs to weigh before adopting RunSybil.
- The client contractually accepts every risk of testing: temporary data changes, intrusion-detection alarms, log floods, degraded performance, and systems that hang or crash
- The destructive testing option will disrupt a vulnerable system if enabled, and recovery may require manual intervention
- Forgetting to warn your own security team means they will spend real time and money fighting an authorised test, and the contract makes that your cost
- Testing a third-party system without the owner's signed authorisation letter shifts legal exposure onto you, since the contract deems the work authorised under US computer misuse law on your representation alone
- Opacity on data handling: no privacy policy, no processing agreement, no subprocessor list, no hosting country, and no answer on whether models are trained on your data
- No warranty that vulnerabilities will be found: the service is supplied as is, liability is capped at twelve months of fees, and a clean report is not proof of a secure system
- Automation can breed complacency, and treating continuous coverage as a substitute for security review, threat modelling and human judgement is a failure mode the tool cannot catch
Setup & Integrations
Technical difficulty
Technically light, contractually heavy. Getting started needs only a live URL: no source code, no internal access, and Sybil handles authentication itself, from TOTP to Okta and SSO, creating its own test accounts. Testing begins the day you onboard. Deeper options exist (credentials, source code, custom login instructions), and connecting GitHub or GitLab takes little effort. The real cost of entry lies elsewhere: a countersigned Service Order, a scope defined as precisely as for a third-party firm, accounts and permissions to administer, internal teams to warn, and authorisation letters for any third-party system.
Deployment
Integrations
Behind RunSybil
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
What does Sybil actually test?
Do I have to hand over my source code?
How does RunSybil keep false positives out?
How long does an engagement take?
Is there an API?
What does RunSybil cost?
Does RunSybil train its models on customer data?
Which integrations are available today?
Is RunSybil itself certified?
What risks come with running an offensive test?
Should you pick RunSybil?
RunSybil is technically credible. The founding team comes from OpenAI, Meta, Mandiant, NCC Group and Trail of Bits, the reference customers are named and verifiable, and forty million dollars of funding sits behind the roadmap. The core proposition, proving exploitability continuously rather than flagging patterns periodically, is carried consistently through every product page, from the validation pipeline to the coverage maps that let a team ask what was not tested. The reservation is transparency, and for this category it matters. A tool that authenticates into production systems and, in white-box mode, reads source code publishes no privacy policy at all. There is no data processing agreement, no subprocessor list and no disclosed hosting country, while the contract explicitly permits subcontractors and third-party storage. The licence granted over client materials covers improving RunSybil's products and services without ever defining what improving means, so whether models learn from customer data is simply unanswered. SOC 2 Type 2 is claimed on the trust centre, but the evidence sits behind an access request and could not be observed. Buying is committing. Prices are negotiated, the default term runs twelve months and renews automatically, fees are non-refundable, disputes go to arbitration in San Francisco, and the client contractually accepts that testing may trigger alarms, flood logs, degrade performance or crash a system. The fit is clear: organisations that deploy quickly, carry a real security budget and want validation rather than another queue of findings. Small teams are out of scope, priced out and unserved by a contract-only motion. Before signing, ask for the exact Service Order scope, a written commitment on model training, the SOC 2 report itself, and the list of subprocessors.
- Choosing a selection results in a full page refresh.
- Opens in a new window.