AI VAPT Autopilot for India

Your product's red team,
on Autopilot.

Tell Autopilot what to prove, like IDOR on /api/users, SQLi on login, or full OWASP coverage. Specialists attack within your rules. Oracles confirm. You stop when it is proved.

Mission goals for IDOR, BOLA, SQLi, XSS, SSRF, and continuous Autopilot

Mission goalsStop on proveOWASP Top 10BOLA / BFLASSRF / OASTKill chainsRules confirm findings
0x
Parallel swarm workers
0
LLM only confirmations
0+
APK secret patterns
Continuous retest diffs
Platform

Everything a senior red teamer does.
Automated. Continuously.

Autopilot live run

Real attack, real output.

Watch Autopilot recon the surface, mint identities, and confirm BOLA, often in under 5 minutes.

guardial autopilot run_a3f7
recon
probe
exploit
report
$ guardial run --target app.mymotor.in --apk MyMotor.apk
Multi-signal oracle

Confirmed by rules, not guesses.

Control request, soft-404 check, and body diff. Every finding is confirmed by rules, not by an LLM guessing.

Mobile APK analysis

50+ secret patterns in DEX and native code.

Bearer tokens, AWS keys, Firebase API keys, Stripe secrets. Live validated against vendor APIs.

Identity depth

Real User A and B sessions.

Works with Auth0, Keycloak, Cognito, Firebase, and Okta so authorization tests use real sessions.

Goal based testing

State a mission. Get a verdict.

Type “Prove IDOR on /api/users.” Guardial builds the mission, seeds the Strategist, and can stop when proved. Leave the goal empty for full Autopilot.

Attack chains

Attack chains, not one off alerts.

From IDOR to privilege escalation to data access. Steps are stitched only after each one is confirmed.

Scoped missions

Prove SQLi on /login. Skip the blind spray.

Only the specialists that match your goal run first. If IDOR needs a session and you have none, you get blocked, not a fake clean result.

Proof first export

Curl, SARIF, and HTML. Evidence you can replay.

Every confirmed finding ships a bound PoC, not a scanner dump. Export JSON, SARIF, or HTML your team can re-run.

How Autopilot works

Observe → Plan → Validate → Execute → Commit.

From mission goal to oracle verdict. The LLM plans. Rules confirm. Your team reviews results, not every request.

Kill chain: MyMotor APK
01
APK Secret Scan
recon
Decompiling APK. Bearer token found in libapp.so
02
Cloudflare Token Validate
recon
Live CF API confirms token active. DNS zones exposed
03
Firebase Identity Signup
probe
API key confirmed. Disposable User A/B minted
04
Garage BOLA
exploit
Sequential vehicle IDs with foreign session. Object-level auth bypassed
05
EV Wallet Credit Forgery
exploit
Unsigned top-up callback. Wallet credited without payment
OK
Oracle confirmed kill chain
confirmed
Control + soft-404 + diff. Zero false positives
Swarm workers · live
surface_recon running
identity_signup running
session_api_diff confirmed
injection_probe running
senior_rt_probe confirmed
owasp_top10 queued
Multi-signal oracle on /api/vehicles/:id
control_req 200 → garbage ID = 404 ✓
foreign_sess 200 different user data ✓
soft_404 body diff confirms real data ✓
llm_confirm NOT USED (rule-based only)
verdict CONFIRMED CRITICAL
Coverage

Every attack class. RoE-bound.

Web, API, identity, mobile, SSRF/OAST, business logic. Evidence-backed, not pattern-matched.

Web & API
  • IDOR / BOLA: sequential & UUID IDs
  • BFLA: function-level auth bypass
  • SQLi / NoSQLi: error-based, multi-signal
  • XSS, CSRF, open redirect
  • Mass assignment: role:admin injection
Identity
  • Auth0, Keycloak, Cognito
  • Firebase mint / accounts:signUp
  • Okta / OIDC flows
  • JWT alg:none / key forge
  • Open signup exploit, default creds
SSRF & OAST
  • Blind SSRF: DNS/HTTP/SMTP callbacks
  • Private Interactsh: never public infra
  • AWS metadata exfil (169.254.x)
  • GCP service account probe
  • Open Redis / Elasticsearch
Mobile / APK
  • 50+ secret patterns in DEX + native libs
  • Cloudflare Bearer token live validation
  • Firebase API key confirmation
  • AWS / Stripe keys in libapp.so
  • JWT / PEM in binary resources
Business Logic
  • Payment callback forgery
  • Wallet credit-without-pay path
  • Quota / rate-limit bypass (header oracle)
  • Race conditions: concurrent write exploit
  • Billing top-up at amount=0
OSINT & Creds
  • Subdomain enumeration
  • Breach / HIBP email lookup
  • GitHub secret scan: live token check
  • Sensitive path probe: /.env /.git
  • Credential spray (within RoE)
Live proof

Confirmed findings.
Evidence you can act on.

Authorized engagements on real production apps. Autopilot surfaced IDOR, SSRF, wallet forgery, and cloud credential exposure. All oracle-confirmed.

0+
Confirmed findings on demo targets
0
LLM-only false positives
0
Kill chains surfaced automatically
<5m
First confirmed finding, typical
Sample run: MyMotor (authorized)
CRITICAL Cloudflare Bearer Token libapp.so oracle
CRITICAL Garage BOLA / Vehicle IDOR /api/vehicles/:id oracle
CRITICAL Firebase Open Account Creation accounts:signUp oracle
HIGH EV Wallet Credit Forgery /wallet/topup oracle
HIGH Rate Limit Header Bypass Internal_search oracle
MEDIUM e-Sign PDF IDOR /esign/:doc_id oracle
2 kill chains stitched, report exported, 0 noise findings
Customer proof

What leaders say after the run.

Authorized engagements. Real production apps. Outcomes scanners and annual VAPT never delivered.

We brought Guardial in for an authorized Autopilot run across our product surface. What stood out was the speed and the quality of proof. Instead of a long list of theoretical issues, we got confirmed, evidence-backed findings our engineering team could act on the same week. It felt like having a senior red team on demand, without the weeks of wait and the noise we usually get from scanners.

HS
Harsh Surana
Chief Strategy Officer
Zoop.one

Guardial changed how we think about continuous security testing. The Autopilot run on selfhost.dev was sharp, disciplined, and genuinely impressive. Clear evidence, zero fluff, and a level of depth we did not expect from an automated platform. For a product company shipping fast, this is exactly the kind of partner you want watching the attack surface.

MA
MD. Aziz
Founder & CEO
selfhost.dev
Pricing

Simple wallet. Pay per scan.

No monthly lock-in. Top up once and debit per Autopilot run. Checkout via Razorpay on the dashboard.

New accounts get ₹350 free, enough for one Quick scan. Top up any time from ₹350.

New accounts get ₹350 free, enough for one Quick scan. Top up any time from ₹350.

Start free
₹350credit
included on signup
  • ₹350 wallet credit for one Quick scan
  • Full Autopilot with confirmed findings
  • Kill chain report + remediation
  • No card required to start
Sign up free
Quick
₹350
per scan, wallet debit
  • Fast surface + high-signal attacks
  • Oracle-confirmed findings only
  • Ideal for first pass / CI gate
  • Same report format as deeper runs
Top up wallet
Most used
Standard
₹700
per scan, wallet debit
  • Broader attack coverage & depth
  • Identity / session-aware probing
  • Kill chains with live proof
  • Best balance of cost vs coverage
Top up & run
Deep
₹1,100
per scan, wallet debit
  • Maximum depth & swarm budget
  • Harder multi-step / objective goals
  • Retest-ready evidence packs
  • Need SSO / private deploy? Talk to us
Top up wallet
The team

Built by practitioners, for operators.

DV
Divyank Vijayvergiya
Founder & CEO
Red teamer and security engineer. Built Guardial so product teams get continuous, evidence-backed testing instead of waiting months for the next VAPT cycle.
FAQ

Common questions.

Why Guardial

AI VAPT Autopilot for API security testing in India.

Built for teams that need confirmed findings, not another vulnerability scanner checklist.

What is an AI VAPT Autopilot?

Guardial Autopilot is an autonomous penetration testing platform: you submit a URL or APK with Rules of Engagement, swarm specialists attack like a red team, and multi-signal oracles confirm exploitability before anything is reported. LLMs plan; rules confirm.

Goal-based security testing vs full Autopilot

State a mission such as prove IDOR on /api/users, hunt SQLi, or cover OWASP API Top 10. Guardial compiles a MissionObjective, seeds the Strategist, and can stop when proved. An empty goal runs full surface Autopilot. See goal-based testing.

API security testing: IDOR, BOLA, SQLi, XSS, SSRF

Coverage spans broken object and function-level authorization, injection, XSS, SSRF/OAST, identity (Auth0, Cognito, Firebase), mobile APK secrets, and business logic. Every class stays inside your Rules of Engagement. Read BOLA testing, IDOR testing, and API security testing.

Affordable VAPT pricing in INR

No Pilot or Team subscriptions. Wallet top-ups via Razorpay: Quick ₹350, Standard ₹700, Deep ₹1,100. Signup includes ₹350 free. See pricing, AI VAPT in India, or Guardial vs scanners.

Get started

Run Autopilot on your app this week.

Sign up free with ₹350 credit. Pick a mission goal or run full Autopilot at Quick, Standard, or Deep. You get confirmed findings and a kill chain report.