Bugcrowd Launches Savant Pathseeker for Continuous Pentesting

Bugcrowd launched Savant Pathseeker on July 28, 2026, an agentic penetration-testing product for continuously testing external web applications and APIs. According to Bugcrowd's announcement and SiliconANGLE, the tool autonomously validates findings, provides reproducible exploit evidence and audit-ready reports, and offers on-demand escalation to human pentesters. The product is the first release in Bugcrowd's Agentic Offensive Testing line.
Bugcrowd launched Savant Pathseeker on July 28, 2026, an agentic penetration-testing product designed to continuously test external web applications and APIs. The company describes it as the first product in its Agentic Offensive Testing line, combining automated discovery and validation with access to Bugcrowd's human researcher community.
According to Bugcrowd's announcement, Savant Pathseeker produces evidence intended to establish whether a discovered issue is genuinely exploitable, rather than reporting unverified scanner findings. SiliconANGLE reports that each finding includes reproducible proof of exploitability and audit-ready reporting for security teams, auditors and regulators.
Continuous testing with human escalation
Bugcrowd states that purpose-built agents test externally facing web applications and APIs continuously, and that findings are autonomously validated in a single platform. The company frames the product as addressing a gap between periodic, manually performed pentests of high-value systems and broad automated scanning that can generate theoretical or unactionable alerts.
SiliconANGLE reports that the product includes built-in guardrails and a manual kill switch to keep testing within a customer's defined scope. The outlet also reports that Savant Pathseeker integrates with Bugcrowd's penetration testing as a service, bug bounty, vulnerability disclosure, red-team-as-a-service, and attack-surface-monitoring offerings. Systems requiring deeper investigation can be escalated to human researchers through the same platform, according to SiliconANGLE.
"Every day, our research community uncovers the next generation of critical vulnerabilities, zero-days, business logic flaws, broken access controls, that automation and AI simply can't find," Bugcrowd CTO Braden Russell said in the company's release. "We built Savant Pathseeker with our customers, designed around that human edge: bringing agentic discovery, testing, and validation into one place."
What the product claims to address
Bugcrowd's release argues that attackers increasingly use AI for continuous probing while defenders often operate on point-in-time assessments. That claim is central to the vendor's rationale for continuous testing, but the announcement does not provide comparative performance data, detection rates, or independent evaluation results for Pathseeker.
The distinction between vulnerability discovery and exploit validation is consequential for application-security teams. In comparable security workflows, reproducible evidence can help reduce time spent investigating low-confidence alerts, while scope controls remain important when autonomous agents interact with production-facing applications and APIs. Human review also remains relevant for business-logic flaws, multi-step exploit chains, and other context-dependent findings that are difficult to assess through automated testing alone.
Bugcrowd characterizes Savant Pathseeker as a complement to, rather than replacement for, its human pentesters. Practitioners evaluating agentic offensive-security tooling will likely look for independent evidence on validation accuracy, coverage of authenticated and complex application flows, integration behavior, and operational controls before comparing it with established scanning and pentesting processes.
Key Points
- 1Bugcrowd launched Savant Pathseeker for continuous agentic testing of external web applications and APIs, with exploit validation as a core product claim.
- 2SiliconANGLE reports reproducible proof, audit-ready reporting, guardrails, and a manual kill switch, features relevant to operationalizing autonomous testing safely.
- 3Comparable security programs use human review for business-logic and multi-step flaws, where automated discovery and validation can remain incomplete.
Scoring Rationale
This is a notable security-tool launch for teams evaluating agentic workflows in application and API testing. Its practitioner relevance rests on the claimed combination of continuous testing, exploit validation, and human escalation, although the available reporting contains no independent performance results.
Sources
Primary source and supporting public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems

