Bugcrowd Launches Savant Pathseeker for Agentic Pentesting 2026
News | 31.07.2026
Security teams face an uncomfortable trade-off: crown-jewel assets sit exposed for months between infrequent manual pentests, while everything else drowns in scanner noise flagging theoretical flaws without confirming real risk. Meanwhile, attackers now use AI to probe continuously, leaving defenders working from point-in-time snapshots. Bugcrowd Savant Pathseeker is designed to close that gap by delivering continuous, evidence-based pentesting across the external attack surface, backed by on-demand human expertise.
What was announced
On July 28, 2026, Bugcrowd introduced Savant Pathseeker, the first solution in its Agentic Offensive Testing portfolio. The product delivers agentic-scale pentesting across every external web application and API, not just the assets that make it onto a pentest schedule, and pairs findings with reproducible proof of exploitability and audit-ready reporting.
Savant Pathseeker integrates with Bugcrowd's existing services including Penetration Testing as a Service (PTaaS), Bug Bounty and Vulnerability Disclosure Program (VDP), Red Team as a Service (RTaaS), and attack surface monitoring. The solution is available today through an early access program, with general availability planned for later in 2026.
Point solutions that only give you part of the picture aren't good enough anymore. We built Savant Pathseeker with our customers, designed around that human edge: bringing agentic discovery, testing, and validation into one place so every layer of offensive security works seamlessly
Why this matters
For CISOs, CIOs, and IT directors, the shift from periodic point-in-time pentesting to continuous agentic coverage changes both operational cadence and compliance posture. Instead of choosing between deep manual testing on a narrow scope and noisy scanners on everything else, security leaders gain a validated view of exploitable risk across the full external surface.
Autonomous validation removes noise so teams focus on findings that matter. Audit-ready reporting supports regulatory and internal governance requirements, while on-demand access to Bugcrowd's global community of pentesters and researchers preserves human judgment for complex business logic flaws, exploit chains, and zero-days that automated tools are not built to find.
Technical details
- Coverage: continuous testing of external web applications and APIs across the full attack surface
- Autonomous validation: findings validated and delivered through a single platform with reproducible proof of exploitability
- Guardrails: built-in scope controls and a manual kill switch keep testing within defined boundaries
- Human escalation: on-demand access to Bugcrowd pentesters, researchers, and red team operators
- Platform integration: works alongside PTaaS, Bug Bounty, VDP, RTaaS, and attack surface monitoring
- AI privacy: customer and researcher data is not used to train or tune the underlying models
- Reporting: audit-ready output suitable for regulators and internal auditors
Softprom and Bugcrowd
Softprom is the official distributor of Bugcrowd. Enterprise customers can access Savant Pathseeker and the broader Bugcrowd platform through Softprom's specialists, who provide licensing, proof-of-concept support, and implementation guidance.
Request early access and a technical consultation on Savant Pathseeker via Bugcrowd.
This content was prepared as part of the Softprom DistriFlow project — an automated system for monitoring and adapting vendor news. Original source: original article.