№ 01 Continuous Pen Testing · Australia For the AI you put in front of the world

Continuous pen testing for web-facing AI.

Real human hackers. Always-on automated testing. Simple fixed pricing. StrikePath finds the prompt injection, data exfiltration, and agent-abuse paths in your AI products, and keeps finding them as you ship. Not next quarter. Today.

strikepath — live engagement
# target: support-agent.acme.ai strikepath> probe prompt-injection injecting indirect payload via retrieved doc... [HIT] system prompt disclosed [HIT] tool `send_email` invoked out of policy strikepath> probe data-exfil walking RAG index for adjacent tenants... [HIT] cross-tenant record returned strikepath> report --severity critical 3 findings · repro steps · fix guidance attached strikepath>
Real humans
Senior pentesters, not interns
Always-on
Continuous testing never sleeps
Fixed price
No scoping theatre
Free retests
We help you finish the job
I /

AI security, made boring on purpose.

Most security companies hide behind buzzwords. We don't. Here's the whole thing in three sentences.

01

Real humans test your AI.

Senior pentesters attack your models, agents, and APIs the way real adversaries do, and write it up so anyone can understand it.

02

Our platform watches in between.

SentryLine runs continuously between manual tests, so the time between "all clear" and "now we're exposed" doesn't catch you out.

03

You get one fixed price.

Pick a package. Know the cost. We tell you what's broken, you fix it, we retest. No surprise invoices.

II /

Your AI app is a new attack surface. Your scanner can't see it.

An LLM follows instructions wherever it finds them, a document, a calendar invite, a web page your agent visits. Untrusted text becomes a control channel. StrikePath tests against the OWASP Top 10 for LLM Applications and the classic web and API flaws underneath. Here is the core of what we throw at a web-facing AI system.

01 /
Prompt Injection
Direct & Indirect
Untrusted input from docs, pages, and tickets overriding your instructions and policy.
02 /
Jailbreaks
Guardrail Bypass
Talking the model out of its safety rules, refusals, and content boundaries.
03 /
Data Exfiltration
Sensitive Disclosure
Coaxing out secrets, PII, training data, and other tenants' records.
04 /
Excessive Agency
Tool & Function Abuse
Agents invoking tools, APIs, and actions outside their intended authority.
05 /
Output Handling
XSS · SSRF · Injection
Model output flowing unescaped into browsers, shells, queries, and downstream systems.
06 /
RAG Poisoning
Knowledge & Vectors
Planting hostile content in the sources your model retrieves and trusts.
07 /
System Prompt Leak
Configuration Exposure
Extracting hidden instructions, keys, and logic baked into the prompt.
08 /
Model DoS & Cost
Abuse & Spend
Unbounded prompts and loops that exhaust quota, latency, and your token budget.
09 /
Auth & The Web Layer
OWASP Top 10 · APIs
Broken authn/authz, IDOR, and the classic web and API flaws holding the AI up.
Aligned to the OWASP Top 10 for LLM Applications. Scoped to your stack on every engagement.
The uncomfortable truth

The model will do exactly what it's told. The question is who's telling it.

III /

From first call to ongoing coverage, in days, not months.

01

Pick a package.

Three options, clear inclusions. Pick yours in five minutes. No quote pingpong, no 12-page proposals.

02

Onboard.

We confirm scope, set up SentryLine against your AI assets and the web and API layers around them, and book your first manual test.

03

Test & report.

Senior pentesters dig in. You get a clear, prioritised report, written for leaders and the technical teams who'll act on it.

04

Continuous coverage.

SentryLine keeps watching. Free retests when you ship fixes. Quarterly reviews with your security lead.

IV /

Three packages. One simple choice.

Pick the one that fits. Upgrade or move when your needs change. Every package includes humans, the platform, and free retests.

Essentials
Essentials
For smaller organisations and startups shipping their first AI feature.
$499 /mo
or $5,400 / year
  • One annual manual pen test, choose: your primary AI / web app (unauthenticated), or external network up to 10 active IPs
  • SentryLine continuous assessments on the original scope
  • One free retest included
  • Executive security report
  • Email support
Start with Essentials
Most popular
Professional
For mature, or rapidly growing, security-conscious organisations.
$1,490 /mo
or $16,000 / year
  • Everything in Essentials
  • One authenticated AI / web app + one API, tested annually
  • Internal & external network testing, up to 256 active IPs
  • Unlimited SentryLine assessments & retests on scope
  • Priority support
Choose Professional
Enterprise
Enterprise
For large enterprises and regulated industries.
$3,990 /mo+
from, scoped to you
  • Everything in Professional
  • Up to three AI / web apps and three APIs, or an annual red-team exercise
  • Web, API & cloud testing (AWS · Azure · GCP) on request
  • Dedicated security lead
  • Custom executive risk reporting
Talk to us
Prices in AUD. Annual billing saves up to 11%. Every package includes humans, the platform, and free retests.
V /

Our continuous testing platform, working between manual pentests.

Manual pentests are essential. They're also a single point in time. SentryLine runs in the background, every day, every change, so the gaps that open between tests don't go unnoticed.

Always on

Continuously checks your AI endpoints and the surfaces around them for new exposures, every day.

Tuned by humans

Findings are reviewed by our team. You don't drown in scanner noise.

Included

Bundled with every package. No add-ons, no extra licences, no per-seat fees.

Invisible to your team

No agents to install. No dashboards to babysit. We just send what matters.

AI / LLMWebAPICloudNetworkIdentityCI/CD Real hackers + always-on platform
VI /

Built for security-conscious teams, not 200-page scoping documents.

We started StrikePath because traditional pentesting wasn't built for the pace and complexity teams ship AI at today.

01 / Fast to start

Kick off this week.

Pick a package today. No 12-page proposals, no procurement marathon.

02 / Real humans

Not just scanners.

Senior pentesters do the work. Always. The platform supports them, it doesn't replace them.

03 / Continuous

Not once a year.

SentryLine watches in between manual tests. Risk drops, and stays low.

04 / Plain language

Reports people read.

An executive summary leadership reads in two minutes. Detail the technical team can act on.

05 / Free retests

Verify your own fixes.

We don't charge you to confirm a fix worked. That's just bizarre.

06 / Australian team

Local and accountable.

Responsive, onshore, no offshored boilerplate. You know who's testing you.

VII /

Every surface that matters, bundled into one package.

You don't need to know which test you need. Pick a package; the right testing is included.

01 /
AI & LLM Application Testing
Prompt injection, jailbreaks, tool abuse, RAG poisoning, and data exfiltration, against the OWASP Top 10 for LLM Applications.
02 /
Web Application Testing
Real humans break your web app the way real attackers do, not a scanner left running overnight.
03 /
API Security Testing
Your APIs probably hold your business together. We test them like that matters.
04 /
Network Testing — Internal & External
We find the way in. Then we find the way deeper.
05 /
Cloud Security Testing
AWS, Azure, and GCP, tested by people who actually run in them.
06 /
Red Teaming
A real, persistent attacker simulation for when you're past basic assurance.
VIII /

Built by people who've been doing this for a while.

RM
Founder · CISO On Demand

Rob McAdam

StrikePath is founded by Rob McAdam, one of Australia's most trusted offensive security operators. Rob founded Pure Hacking and has spent 20+ years in offensive security.

StrikePath is what he wishes existed when he was building those companies: the same senior craft, made simple, productised, and always on. It is operated by CISO On Demand, with offensive testing and accountability sitting squarely with the cyber team.

Morti · Build Partner

Morti designs and runs production AI agents for Australian businesses, and commissions StrikePath to pen test every AI system it ships. The split is deliberate: Morti builds the AI; StrikePath, operated independently by CISO On Demand, breaks it. Different teams, different accountability, the way it should be.

Pick a package. Get protected.

Break your AI before someone else does.

A five-minute decision. Real human hackers, an always-on platform, and free retests. The modern way to do continuous penetration testing, built for the AI you put in front of the world.