Zum Inhalt springen
IJONIS
AUTONOMOUS PENTEST AGENT

You shipped fast.
Let's see what else you shipped.

Your scanner says "all clear." Penny says "hold my beer." Real exploits, real proof, delivered in days.

Let Penny looseScope review within 24h
penny

Damage report

92%
of apps had critical vulns hiding in prod
4.2
exploitable findings per test (avg)
0
false positives. Zero. Every finding is real.
< 3d
scope to report. Not weeks. Days.

How Penny hunts

01

Point. Click. Sign.

Drop your domain, sign authorization. Done in 5 minutes. Penny handles the rest.

02

Penny goes hunting

Recon, scanning, exploitation, chaining. Fully autonomous. No human bottleneck.

03

Read and weep

Every finding verified with proof-of-concept. Fix what matters, ignore nothing.

Pick your poison

One test, one price. No retainers, no surprise invoices.

The Quick Slash

799/ pentest

Find the worst stuff fast. External surface, top vulns, done.

3 business days
  • External recon & enumeration
  • OWASP Top 10 testing
  • Auth & authorization bypass
  • API endpoint discovery
  • Every finding verified with PoC
  • Step-by-step fix guidance
Get slashed
MOST DAMAGE

The Full Autopsy

1,499/ pentest

The whole pipeline. Exploit chains. The stuff that keeps CTOs up at night.

5 business days
  • Everything in Quick Slash
  • Full autonomous attack pipeline
  • Multi-step exploit chains
  • Cloud & infrastructure assessment
  • AI/LLM endpoint testing
  • Business logic & race conditions
  • Post-exploitation impact proof
  • Executive + deep technical report
Full autopsy

What Penny found last month

Vibe-coded MVP

Found 3 critical vulns we had no idea about. The JWT key in our bundle was... embarrassing.

Founder, AI SaaS startup

Series A

Way more thorough than the automated scan we were paying €200/month for.

CTO, Fintech startup

Side project → startup

Penny found an IDOR chain that gave access to every user record. Fixed it before launch.

Solo developer

Not a script kiddie

Built by IJONIS in Hamburg. Real pentests, not automated scan dumps. Every finding is exploited and verified before it hits your report. We don't touch anything without signed authorization.

Signed authorization requiredHuman-reviewed reportsHamburg, Germany

Sleep better. Ship safer.

Let Penny loose

Scope review within 24h · No commitment until authorization is signed

Penny is built by IJONIS · Hamburg, Germany · All engagements require signed authorization