Today Xint.io announced that it was included in the IDC Innovators: Autonomous Penetration Testing for DevSecOps report. The report profiled seven emerging vendors providing autonomous AI agent-driven penetration testing for DevSecOps. Xint.io was recognized for behavioral testing focused on application logic, not being tied to a single AI model, and how it covers the entire attack surface – from source code to runtime production. Download an excerpt from the report featuring Xint.io here.

AI-generated code and modern software practices are expanding the attack surface faster than traditional human-led penetration testing can scale up to protect it. Autonomous penetration testing fills this gap. Unlike traditional automated testing, which executes predefined security checks, agentic systems continuously reason about the environment, determine which attack paths to pursue, and adjust based on what they learn.

“This report helps show the need for autonomous penetration testing technology, and why it must produce usable outputs that fit into existing workflows,” said Kay Kyoung-ju Kwak, Head of Xint. “We’re grateful for this recognition of our approach of taking the expertise of the world’s most decorated white hat hackers and scaling it to the modern threat posed by AI-armed attackers.”

“The value of autonomous pentesting will depend less on finding volume and more on whether the output is validated, prioritized, and usable in existing DevSecOps workflows.”

– IDC Innovator: Autonomous Penetration Testing for DevSecOps, (Doc# US54175326), July 2026

Xint scales offensive security across source code and live applications, delivering confirmed vulnerabilities with full attack paths, reproduction steps, and suggested fixes in an audit-ready report in hours, not weeks. It is built on real penetration testing methodology to find complex multi-step attack chains, by the team behind record wins at DEF CON and Pwn2Own, along with wins at DARPA’s AIxCC and Zeroday.Cloud from Google Wiz. Customers include DARPA, Samsung, LG Electronics, Hyundai and many more. Xint’s technology uses LLMs combined with a proprietary orchestration engine to identify, reproduce, validate and understand critical security vulnerabilities in web application code. It can analyze millions of lines of source code, configuration files and binaries in less than 12 hours at the same depth and detail as a human penetration tester.

The Xint Platform includes Xint Code, which offers source code analysis, and Xint Web, which offers live web application testing. They also offer Xint Pulse, a one-time scan of a single web application by the full Xint Web engine, priced for small and medium-sized businesses and individual researchers.

Download an excerpt from the report featuring Xint.io here.

About IDC Innovators

An IDC Innovators report presents a set of vendors – under $100M in annual revenue at the time of selection – chosen by an IDC analyst within a specific market that offer a new technology, a groundbreaking solution to an existing issue, and/or an innovative business model. It is not an exhaustive evaluation or a comparative ranking of all companies, but rather a document that highlights innovative companies in a specific market segment. IDC INNOVATOR and IDC INNOVATORS are trademarks of International Data Group, Inc.

About Xint.io

Xint.io is the award-winning autonomous pentesting platform built by the security researchers at Theori, the most decorated team of white hat offensive security researchers in the world. Xint offers both black-box as well as white-box pentesting with results in 12 hours or less, on average, including: full trigger conditions and step-by-step reproduction pathing, exploit impacts, and suggested remediations so teams can quickly triage and patch the most critical vulnerabilities. Xint is working with organizations with the highest defensive security needs, including DARPA and Samsung.

About Theori

Theori is an offensive cybersecurity firm dedicated to solving the industry’s most complex security challenges. Founded in 2016 by Carnegie Mellon alumni, our elite team of white hat hackers is trusted by global technology leaders and government agencies, backed by 70+ international hacking competition wins including a record four consecutive DEF CON CTF championships.

The company offers a comprehensive security ecosystem: Xint (AI-powered application security testing), aprism (LLM security guardrail) and offensive security consulting. Certified to ISO/IEC 27001:2022 and ISO/IEC 27017:2015.

Media gallery

About The Author