Introducing Hacktron AI: An autonomous penetration test of Gumroad
How Hacktron secured Gumroad at the fraction of the cost of a traditional penetration test. We found and fixed critical security vulnerabilities.
Connect your GitHub repository. Deploy Hacktron agents into your CI/CD pipeline within minutes.
Our agents analyze your code, uncover vulnerabilities, and triage them by impact.
Every vulnerability gets a working proof-of-concept. If we report it, we can break it.
Receive actionable patches via a pull request, and merge them into your codebase.
Ex-Cure53 Senior Auditor. Featured on PortSwigger & Vice. BlackHat & DEF CON speaker. Previously founded €1.5M revenue security auditing company.
Ex-ProjectDiscovery. Top-ranked bug bounty hunter. Featured in Forbes for hacking Apple. Ekoparty & BSides speaker.
Cambridge CS dropout. Ex-TikTok and ex-military. DEF CON CTF runner-up (Blue Water) 2023-24. Credited for 15 CVEs. Topped Singapore's government and military bug bounties.
Security educator with 1M+ YouTube followers. Ex-Cure53 Senior Auditor. Previously founded leading cybersecurity education platform.
Ex-Millennium, ex-Binance. Full-stack engineer across government, fintech, and leading startups in Asia. Graduate of Asia's #1 computer science university.
Ex-ProjectDiscovery. Expert in web security, patch analysis, and automation. Speaker at multiple security conferences such as Ekoparty, Hacktivity and NoNamecon.
We’re looking for world-class researchers. Reach out to us if you think you fit the bill.
APPLY
How Hacktron secured Gumroad at the fraction of the cost of a traditional penetration test. We found and fixed critical security vulnerabilities.
Hacktron is the first company to be backed by Project Europe. We're incredibly excited to be part of their inaugural cohort with five other incredible teams!
Hacktron helped solve a fascinating CTF challenge that demonstrates how Python's overzealous zip file detection can be weaponized for code execution.
A primitive found by Hacktron helped score a $45,000 bounty during a live hacking event. The future of autonomous security research is here.