Autonomous Penetration Testing,
Fully Priced.

Cairn covers your full attack surface — web, API, Active Directory, and cloud. AI triage eliminates scanner noise. Compliance-ready reports included at every tier.

No sales call required · Subscriptions from $299/mo · Built by Brendon McCaulley, CISSP

Full-Spectrum Coverage

Cairn's agentic engine autonomously discovers, exploits, and documents vulnerabilities across every layer of your environment — with AI-driven triage, not raw scanner output.

Web Application & API

Authenticated crawling across all defined user roles. Automatic Swagger/OpenAPI discovery, HTTP method enumeration, cross-role IDOR substitution, BOLA/BFLA detection, XSS, SQLi, CSRF, and path traversal. tRPC and GraphQL introspection included.

OWASP Top 10 IDOR Auth Bypass GraphQL tRPC

Active Directory

ACL/DACL enumeration, ADCS abuse path discovery, cross-forest trust analysis, GPO misconfiguration review, LAPS assessment, and BloodHound-comparable attack path mapping — fully automated against your AD environment.

ADCS Kerberoasting GPO Abuse Trust Attacks

Cloud & SaaS

IAM privilege escalation path discovery, public exposure analysis, and misconfiguration detection across AWS, Azure, and GCP. SaaS coverage: M365, Google Workspace, GitHub, and Okta. Benchmarked against CloudGoat and AzureGoat.

AWS Azure GCP M365 IAM

AI Triage & Reporting

LLM-powered finding analysis eliminates false positives, contextualizes severity, and generates remediation guidance automatically. Every engagement produces a compliance-ready PDF with executive summary, CVSS scoring, and evidence chains via the Basecamp client portal.

PCI-DSS SOC 2 HIPAA CVSS

From API Call to Report

Cairn handles the full engagement lifecycle. You define the scope — the engine handles the rest.

01

Define Scope

Submit your target, auth credentials, role definitions, and enabled modules via API. Cairn validates scope and queues the engagement.

02

Autonomous Assessment

Cairn runs discovery, enumeration, exploitation attempts, and cross-role testing. AI triage runs continuously — findings are classified and prioritized in real time.

03

Report & Portal

A compliance-ready PDF report and live findings portal are generated automatically. Premium clients get a dedicated Basecamp workspace with signed attestation.

Pricing That Doesn't Require a Sales Call

Traditional pen tests run $10,000–$30,000 per engagement, take weeks to schedule, and give you one shot at a report. Cairn subscriptions start at $299/month — unlimited rescans, no per-scan fees. Annual billing via invoice saves ~3 months.

Starter
$299
per month · 1 root domain
or $2,500/yr — save ~3 months (billed annually via invoice, Net 30)

  • 1 root domain
  • Full autonomous assessment
  • AI triage — zero scanner noise
  • Unlimited rescans
  • PDF report via API
  • Full API access
  • Quarterly findings report
  • Client portal
  • Signed attestation
Get Started
Premium
$3,499
per month · unlimited root domains
or $30,000/yr — save ~3 months (billed annually via invoice, Net 30)

  • Unlimited root domains
  • Everything in Pro
  • Monthly review by Brendon McCaulley, CISSP + AI agent team
  • Interactive attack surface crawl each session
  • 1hr monthly findings call
  • Basecamp client portal (auto-provisioned)
  • DocuSeal signed attestation on every report
  • Compliance-ready: SOC 2, PCI-DSS, HIPAA
  • Custom SLA available
  • Your engagement trains Cairn's detection intelligence
Talk to Brendon

All plans are monthly subscriptions. Annual billing via invoice, Net 30 — saves ~3 months.  Questions? Talk to us.

Compliance-Ready by Default

Every engagement maps findings to your compliance framework. Reports are formatted for auditor review — no post-processing required.

PCI

PCI-DSS v4.0

Req 11.4 penetration testing covered. Segmentation validation available. QSA-ready evidence packages on Premium.

SOC

SOC 2 CC7

Findings mapped to Common Criteria 7 (Logical Access Controls). Suitable for Type I and Type II audit evidence.

HIPAA

HIPAA Risk Analysis

Findings classified against HIPAA Security Rule requirements. Supports § 164.308(a)(1) risk analysis obligation.

NIST

NIST 800-53

Control mapping included for organizations running NIST-based frameworks or preparing FedRAMP submissions.

Ready to Run Your First Engagement?

Start with Starter at $299/mo, or talk to us about Pro and Premium subscriptions for your team.

Get in Touch
Brendon McCaulley
Founder & CISSP · Trailhead Security