Raxaid creates coordinated AI agents that continuously attack, defend, and harden your systems, the way a real red team would. Autonomously, 24/7, with no cybersecurity operator required.
Partially inspired by Sakana AI's papers (2512.04695, 2512.04388) which laid the underlying framework for our Fugu-style agent team. Raxaid doesn't replay and reuse pre-written scripts. Its agents reason about every discovery and intelligently reason what to try next, adapting to any environment, any tech stack, any level in real time.
flowchart TD
DEPLOY(["Deploy Raxaid"]) --> TARGET["1 · Target
Define authorized scope"]
TARGET --> RECON["2 · Recon
Map attack surface
47 endpoints · 12 services"]
RECON --> THINK["3 · Think
AI reasons about vulnerabilities
Plans attack vectors in real time"]
THINK --> EXECUTE["4 · Execute
Autonomous exploitation
Adapts to any tech stack"]
EXECUTE --> VERIFY["5 · Verify
Exploits confirmed & captured
100% audit trail"]
VERIFY --> REPORT["6 · Report
Findings with full evidence
Ready for your team"]
REPORT -.->|"Continuous loop"| THINK
THINK -.->|"Thought → Action → Observation"| THINK
SUPERVISOR["Supervisor Agent
Enforces budgets, scope & guardrails"] -.- THINK
An AI system that reasons, plans, and finds vulnerabilities on its own. It runs a Thought, Action, Observation loop with no operator, and no room for misuse.
DEPRECATED
Detects attacks as they happen and hardens the exposed surface automatically, patching in real time as the red team probes.
Every simulated attack permanently strengthens defense. A supervisor keeps the agents on-mission and enforces budgets and guardrails.
Work in Progress
The category is crowded, but most tools are dangerous in the wrong hands, rigidly scripted, or blind to context. Raxaid was designed around those gaps.
Powerful, but easily misused, and it needs a skilled human operator for every engagement.
Fully autonomous with safety guardrails built in. No operator, and no room for misuse.
Automated, but rigid and poorly coordinated. Its agents don't work well together.
Orchestrates multiple AI agents, red team, blue team, and a supervisor, that coordinate as a real team.
Inflexible, pre-scripted scenarios that can't react to what they find.
AI reasoning that adapts to any environment in real time, deciding what to try next as it learns.
Automated, AI-driven attacks hit the smallest teams and the largest enterprises alike. Continuous validation shouldn't need a security department to run it.
We are a team of professionals dedicated to revolutionising cybersecurity through automated systems creating a solution available to anyone.
Marketing professional with a track record of bringing technical products to market. Roland drives Raxaid's strategy, brand, and go-to-market execution, ensuring that autonomous security testing is understood and adopted by teams of every size.
Hi! I’m William, the founder of Raxaid along with Maryam and Roland. I am a self-taught pen tester and I was always interested in how systems worked, and especially how they fell apart. I studied at UCL and I have spent many months and many hours of my time working on Raxaid. I never really cared about titles credentials or certifications and all I wish to do is to build a system that works well and make it the best I can.
Full-stack developer with a focus on building resilient, scalable systems. Maryam engineers the platform that powers Raxaid's multi-agent orchestration, ensuring reliability, performance, and a seamless experience from deployment to reporting.
We're pre-launch and building in the open. Request early access, or just follow along.