CAI Technology
Menu ☰
artemis Live scanope.com ↗

ARTEMIS — AI Pentest · Hunt · Reveal · Strike

For companies that want periodic pentest without paying 5-20K€ per audit. Continuous recon, CVSS classifier, ReAct exploit, attack chain graph, digitally-signed PDF report — in a single pipeline.

The problem

Traditional pentest costs 5-20K€ per audit and takes weeks. Mid-market companies skip or get superficial reports done in 2 days on a generic checklist. Auto-pentest tools (Nessus, OpenVAS) are scanners, not pentest with reasoning.

How it works

  1. 1

    You define scope (domain, IP, range, CIDR) and sign the scriptic agreement in 30 seconds. Preflight check verifies reachability and exclusion list before launch.

  2. 2

    You pick the audit type: Site (2 credits), Network (10), Web App OWASP (20), Code (15), Compliance NIS2/GDPR (5) or Full Audit (40, with 7-credit discount).

  3. 3

    The 5 AI agents work in pipeline: Recon → Classifier → Exploit → Chaining → Report. You see progress live via SSE streaming, finding by finding.

  4. 4

    You receive the digitally-signed PDF report — executive summary, CVSS 3.1 per finding, attack path graph, prioritized remediation. 5-year audit log for NIS2/GDPR.

Capabilities

5 AI agents with distinct roles

Recon (discovers attack surface), Classifier (CVSS 3.1 + categorization), Exploit (ReAct reasoning, non-destructive only), Chaining (combines vulnerabilities into exploitation graph), Report (executive + technical + remediation).

ASM Watcher 24/7

subfinder · httpx · naabu · katana · dnsx · gau run continuously on your perimeter. Daily snapshot + diff: see exactly what new subdomains appear, what ports open, what CT logs publish certificates.

6 audit types · you pay the scan

1 credit = 1 EUR. No subscription trap. Site (2€) · Network (10€) · Web App OWASP Top 10 (20€) · Code Static + AI Review (15€) · Compliance NIS2/GDPR/ISO 27001 (5€) · Full Audit all-inclusive (40€, -7€ discount).

Attack Path Engine with visual graph

Combines individual vulnerabilities into an exploitation graph (cytoscape viz) with clear business impact. No more reading 100 pages of findings — you see exactly the chain "CVE-X → privilege escalation → data exfil".

Multi-LLM with automatic failover

Qwen 3.5 (35B) local default · Gemma 4 · DeepSeek-v3 · Claude. Automatic failover + per-scan budget. You control which LLM runs on your scope — local or external, your call.

SIEM-Native integration

Findings → Graylog / Wazuh / Suricata / Cisco FDM automatically. Block exploit IP immediately on firewall. Pentest becomes part of SOC operations, not an isolated quarterly event.

NIS2 / GDPR Ready

5-year audit log · digitally-signed PDF · legal scriptic scope · T&C agreement before scan · BeLegal compliance questionnaire integrated. Ready documentation for DPO or ANSPDCP audit.

Tech stack

  • 5 specialized AI agents (Recon · Classifier · Exploit · Chaining · Report)
  • Qwen 3.5 (35B) local + Gemma 4 + DeepSeek-v3 + Claude (multi-LLM failover)
  • ReAct reasoning loop · qwen3_xml tool parser (deterministic function calling)
  • ASM Watcher 24/7 (subfinder · httpx · naabu · katana · dnsx · gau)
  • Attack Path Engine (cytoscape graph visualization)
  • SIEM integration (Graylog · Wazuh · Suricata · Cisco FDM)

Evidence

  • From 2€ per audit (Site Audit) — 1 credit = 1 EUR, no subscription
  • Complete audit across 6 types (Site · Network · Web App · Code · Compliance · Full) in one platform
  • 5 AI agents with clear roles + Chaining Engine for business-impact attack paths
  • NIS2/GDPR ready out-of-box — 5-year audit log, X.509 digitally-signed PDF

FAQ

Why ARTEMIS and not Burp Suite Enterprise or Nessus? +
Burp/Nessus are classic scanners with good UI and enterprise pricing. ARTEMIS is agent-driven with reasoning (ReAct), Chaining Engine for attack paths, multi-LLM and 1/10 the cost of Burp Enterprise. More flexible on non-standard scopes (IoT, internal APIs, code review).
Does it replace a human pentester? +
Not for deep pentests (red team, social engineering, creative custom exploit chains). It replaces checklist-driven automated pentest. Our recommendation: between major human pentests, run ARTEMIS weekly or monthly.
What data leaves my network during the audit? +
In standard config: ZERO. LLM runs locally (Qwen 3.5 on our EU infrastructure). For companies preferring external LLM (Claude, GPT), configurable — but then scope data transits through that API. Your call.
How does the credit model work? +
1 credit = 1 EUR. You buy packs (Starter 100cr/100€ · Pro 500cr/450€ -10% · Business 2000cr/1700€ -15% · Enterprise custom) and consume when needed. Free trial 50 credits, 90-day validity. No recurring subscription.
How long does an audit take? +
Site Audit: 2-5 minutes. Network Scan: 30-60 minutes. Web App OWASP: 2-6 hours. Code Audit: 1-3 hours (depends on codebase size). Full Audit: 4-12 hours total, with live SSE progress.

We start with a 30-minute conversation.

Free AI-readiness audit for companies with 50+ employees. We reply within 24 hours.