Planck for Startups

Building an API fast? Your first two scans are on us.

If you are actively shipping an API, we will run two full agentic penetration tests against it, free. The agent tests every operation for the flaws that actually breach APIs, BOLA, BFLA, broken auth and injection across roles, and proves each finding with a working exploit. No credit card, no sales call to get value. We do it to earn design partners while your product is young.

What you get

Two real scans, not a trial teaser

2 free scans

Every operation tested

From your OpenAPI spec, the agent enumerates and tests every endpoint across your user roles, not a sampled subset.

Proof

Exploits, not alerts

Each finding ships reproduced, with the exact request and response and a CVSS v3.1 vector. Near-zero false positives.

Safe

Scope-locked on staging

Non-destructive by default, scope enforced in software, run it against staging. Stop any run instantly.

Live

Watch the agent test an API

This is the Operator console streaming a run: it maps every operation, replays one role's requests as another to confirm BOLA and BFLA, then proves each finding. Illustrative demo against api.example.com, the requests, sessions, and confirmations are what a real scan streams.

The deal

Free scans, in exchange for a partnership

What you give

Candid product feedback as a design partner, and, only if you agree later, an optional short case study or testimonial. That is it. No obligation to buy, no credit card.

Why we do it

Our product is young and we would rather earn early believers than run ads. Testing real, fast-moving APIs makes the agent sharper and gives us partners we grow with.

Best fit: API-first SaaS, fintech, and AI startups from pre-seed through Series A that are shipping an API right now.

How it works

From application to proof in days

01

Apply

Tell us about your API in the form below. We review for fit within a couple of business days.

02

Scope

You share your spec and one token per user role, and pick a staging target. We confirm scope and authorization.

03

Two scans

The agent runs two full engagements and streams its work. You receive proof-backed findings.

04

Decide

Fix what it found, share feedback, and continue on a startup-friendly plan only if it earned it.

Apply

Claim your 2 free scans

Actively building an API? Tell us about it. We reply within a couple of business days.

Your application reaches a practitioner at [email protected]. Keep details as high level as you like. We will propose an NDA before any sensitive specifics or credentials are shared.

FAQ

Questions about the program

Who is eligible?

Startups actively developing an API, with (or able to produce) an OpenAPI or Swagger spec, and authorized to permit security testing. Aimed at API-first SaaS, fintech, and AI companies from pre-seed through Series A.

What do the two free scans include?

Each is a full agentic API penetration test: the agent parses your spec, tests every operation for BOLA, BFLA, broken authentication, injection, and mass assignment across roles, and proves each finding with the exact request and response and a CVSS v3.1 vector.

Is it really free? What is the catch?

The two scans are free. In return we ask for candid product feedback and, optionally and only with your agreement later, a short case study or testimonial. No obligation to buy, no credit card.

Is it safe to run against our systems?

Yes. Testing is scope-locked and non-destructive by default, and we recommend staging. Nothing with real side effects runs without your written approval, and you can stop a run instantly.

What happens after the two scans?

You keep the findings and fix them. If it earned a place in your stack, you can continue on a startup-friendly plan. There is no automatic charge and no obligation.

Get Started

Two scans. Real proof. On us.

If you are shipping an API, there is no reason to wait for the flaws that breach it. Apply and put the agent on your endpoints.