Prescient Security Expands Cait With Attack Surface Management
Prescient Security announced on July 28 that it is adding attack surface management, broader asset testing, and expanded environment support to Cait, its AI-assisted continuous penetration-testing service. According to the company's PRNewswire release and Help Net Security, the updates are scheduled to roll out through summer 2026 and extend Cait beyond its initial web application focus.
Prescient Security announced July 28 that it is expanding Cait, also called Cacilian AI, with attack surface management (ASM), new asset-testing types, and broader environment support. According to the company's PRNewswire release, the updates will roll out through summer 2026 and extend the continuous AI-assisted penetration-testing service beyond its initial web application focus.
Cait reached general availability earlier in 2026, according to PRNewswire and Help Net Security. Those reports describe the product as an autonomous, context-aware pentester that explores applications before attacking them, then produces exploit-validated findings with audit support.
Asset discovery joins testing
Prescient Security's announced ASM capability is intended to automate discovery and mapping of external-facing assets before Cait tests them. The company described the resulting workflow as a loop covering asset discovery, testing, finding validation, and remediation tracking within the Cacilian platform.
Fabrice Mouret, Prescient Security co-founder and CEO, said in the PRNewswire release: "Most organizations still discover their own attack surface the hard way when an auditor flags it or an attacker finds it first." He added that the ASM addition is meant to connect inventory questions with validated testing and remediation evidence.
The announcement also covers testing for additional, unspecified asset types beyond web applications. Neither the PRNewswire release nor Help Net Security identifies the asset categories, technical interfaces, detection coverage, or pricing changes associated with that expansion.
Environment coverage and practitioner questions
According to Prescient Security's release, Cait now supports testing across a range of enterprise environments. The company also reported building a process aligned with autonomous testing protocols for large enterprises requiring isolated test environments.
For security and ML platform teams, the operational distinction is material: attack-surface management is primarily an asset-inventory and exposure-discovery function, while penetration testing attempts to validate whether weaknesses are exploitable. Industry experience with continuous security testing shows that integrating those stages can reduce gaps between asset inventory and validation, but practical value depends on discovery accuracy, authorization controls, false-positive handling, and remediation workflow integration.
The public announcement does not provide benchmarks for Cait's discovery coverage, exploitation success rate, model architecture, human-review process, or support for specific cloud, API, identity, and network asset classes. Those details would be needed to compare the service with established ASM and continuous security-validation products.
Key Points
- 1Prescient Security is adding ASM to Cait, linking external asset discovery with AI-assisted penetration testing and remediation tracking in one platform.
- 2The announced expansion broadens Cait beyond web applications, although public materials do not identify the additional supported asset categories.
- 3Comparable continuous-testing systems depend on accurate asset inventories, explicit authorization, reliable validation, and remediation integrations to produce operational value.
Scoring Rationale
The update is relevant to security practitioners evaluating AI-assisted offensive-security and continuous validation tools. Its impact is limited by the absence of disclosed technical performance data, supported asset types, or independent validation.
Sources
Primary source and supporting public references used for this report.
Practice with real Telecom & ISP data
90 SQL & Python problems · 15 industry datasets
250 free problems · No credit card
See all Telecom & ISP problems

