Penetration testing solutions
Choose the systems you need tested.
Casco tests web applications, APIs, cloud infrastructure, mobile apps, AI systems, and networks. One approved scope can include more than one system.
Start with the testing model
AI pentesting
See how Casco agents choose tests, confirm a vulnerability, and write the finding.
What we cover
Choose what you need tested.
A test can cover one system or several. The scope must name each application, API, account, environment, or network and provide the access needed to test it.
Web applications
Login, roles, tenant boundaries, and business logic
View solution02APIs
Endpoints, identities, and data boundaries
View solution03Cloud infrastructure
Public assets, private services, IAM, and network paths
View solution04Mobile applications
App workflows, backend APIs, roles, and data access
View solution05AI apps and agents
Prompts, tools, permissions, data, RAG, and MCP
View solution06Network pentesting
Public targets, private networks, services, and credentials
View solutionTesting options
Choose the level of human review.
Both options use Casco agents and the same approved scope. Supervised pentesting adds review by a security engineer.
AI PENTESTING
Agent-led testing
Casco tests the approved scope on a schedule or continuously, reports confirmed vulnerabilities, and retests fixes.
View AI pentesting02SUPERVISED PENTESTING
Agent-led testing with engineer review
A Casco security engineer reviews the scope and findings and can provide an attestation.
View supervised pentestingFrequently asked questions
Questions about scope and coverage.
What types of penetration testing does Casco cover?+
Casco tests web applications, APIs, cloud infrastructure, mobile applications, AI applications and agents, and external and internal networks. One approved test can include more than one of these systems.
Which pentesting solution should I choose?+
Choose the page for the system you need tested. Use AI pentesting for agent-led tests. Use supervised pentesting when you need a security engineer to review the scope and findings or provide an attestation.
Can one pentest cover web, API, mobile, and cloud systems?+
Yes. One test can include applications, APIs, mobile clients, cloud services, identities, and infrastructure when each system is named in the approved scope and the required access is available.
One system or several