YesWeHack launches Agentic Pentest, using AI agents for rapid security testing of attack surfaces.

YesWeHack officially launched Agentic Pentest on June 25, 2026, a new on-demand solution that uses autonomous AI agents to test company attack surfaces and deliver findings the same day Business Wire. The tool covers web apps, mobile apps, and APIs, and integrates into YesWeHack's broader offensive security platform.
CEO Guillaume Vassault-Houlière said Agentic Pentest is "faster and simpler to set up and run than traditional human-led pentesting, while offering broader coverage, greater scalability and lower costs" Financial Post. The launch follows a €26 million Series C funding round and the September 2025 acquisition of French cybersecurity firm Sekost, which provided the core technology Financial Post.
Traditional penetration testing happens once or twice a year at most. That leaves a huge problem: according to Financial Post, only 32% of an enterprise's attack surface actually gets tested in a given year. That means 68% of potential entry points go unchecked — a gap adversaries are happy to exploit.
Gartner analysts have named this shift "Continuous Offensive Security Testing" (COST). They predict that by 2028, 60% of enterprise pentesting will move to this always-on model, replacing the old periodic approach Montreal Gazette. YesWeHack is betting its new product lands at exactly the right moment.
YesWeHack bought Sekost in September 2025 — its first-ever acquisition. Sekost is a French cybersecurity audit firm. Its CTO, Christophe Hauquiert, is a former elite ethical hacker who built the automation technology now powering Agentic Pentest Montreal Gazette. Sekost had doubled its revenue for two straight years before the deal, showing strong market demand.
The Agentic Pentest capabilities are also being rolled out to Sekost's existing customers. In March 2026, YesWeHack launched an earlier product called Autonomous Pentest, which focused on screening actively exploited vulnerabilities. Agentic Pentest builds on that, adding broader scope and same-day reporting Financial Post.
The product is not fully autonomous. YesWeHack calls it "Human-in-the-Loop" — AI agents find potential vulnerabilities, and human experts validate the results. This matters to CISOs (chief information security officers) who worry that unchecked AI agents could accidentally crash production systems Sault Star.
The company's community of 150,000+ ethical hackers provides that human validation layer Business Wire. Ethical hacker Xclow3n noted that AI is a "force multiplier" for coverage but still struggles with "impact assessment and knowing what's actually exploitable" — making human review essential. Agents also operate within guardrails to protect the confidentiality and availability of customer systems throughout testing.
Unlike US rivals HackerOne and Bugcrowd, which lean on proprietary AI models hosted in America, YesWeHack uses open-weight models that can be hosted locally inside the EU Montreal Gazette. This directly addresses GDPR compliance — a major concern for European enterprises and government agencies. HackerOne launched its own competing product, "Agentic PTaaS," in January 2026, signaling how fast this market is moving.
Early adopters include French multinationals Dassault Systèmes and Sanofi, along with several other CAC 40 companies Financial Post. YesWeHack also became a CVE Numbering Authority in October 2025, giving it an official role in the global vulnerability reporting system. A survey in the company's 2026 report found 91% of bug bounty hunters now use AI tools, with 94% reporting real benefits.
Publishers
12
Articles
12
Reach
12