PLEXICUS / AI PENTEST SPAIN · SCOPED SERVICE ENGAGEMENT

AI Pentest for teams building critical software

Find vulnerabilities before attackers do.

Nexus is an AI Pentest harness: a swarm of specialist agents that explores the applications your company builds, connects real attack paths and verifies the evidence within an authorised scope.

Reproducible attack paths. Independent verification. No automatic production changes.

José Ramón Palanco Speak with our founder, José Ramón Palanco. Around 20 years of cybersecurity experience.
If you don't fit the ICP, we'll tell you too — without wasting your time.

Share the scope and we will tell you if it fits.

Pioneering teams are already inside

Plexicus technology and ecosystem

Nexus turns attack hypotheses into evidence your team can verify.

NexusControlled AI Pentest harness
HiveSpecialist agents · one shared memory
ReplaySeparate verification before a finding is published
NEXUS · AI PENTEST

Nexus does not match patterns. It thinks like an attacker.

Nexus is an AI Pentest harness: it coordinates a swarm of specialist agents to explore attack paths, share evidence and verify each finding within the authorised scope.

  • Scope guard on every action
  • Shared mission memory
  • Human final decision
AI PentestBusiness application Q2 · authorised environment
ILLUSTRATIVE VIEW 09:22:11 AI PENTEST AGENT
Checkout + account
https://application.example.test/accountILLUSTRATIVE VIEW
AI Pentest running
Account access Approved test journey
test.user@example.test
••••••••
REPLAY00:14 / replay
HTTP captureRequestResponse
POST /api/session/validate HTTP/1.1
Content-Type: application/json

request: approved test case

# Sensitive content is omitted from this illustrative view.
Agent reasoning

The agent compares the baseline with the observed response. A finding is not marked as verified until another run reproduces the evidence within the authorised scope.

Shared mission memory
  1. 01Discarded path recorded
  2. 02Evidence available
  3. 03Verifier activated
A finding is published only after an independent replay.Independent replay · verifiedScope guard · human review
A real customer experience

As one of Plexicus's first customers, we've witnessed firsthand how their platform has evolved into an indispensable security solution. Their AI-powered remediation has dramatically reduced our vulnerability management overhead and allowed our security team to focus on strategic initiatives instead of repetitive fixes.

Jose Fernando Dominguez Jose Fernando Dominguez CISO, Ironchip Ironchip · customer voice

Every unpatched finding is debt you already carry. The challenge is knowing what is real — and what to do next.

Your external pentester hands you a report. Your in-house team still has to decide what to do with it. Meanwhile, every unclosed finding is cognitive debt on your core: the team stops understanding its own surface, questions pile up, and the next audit may find the same things again.

A scanner compares signatures and a chatbot gives advice. Nexus forms hypotheses, explores attack paths and connects the evidence. The hive automates repetitive work without replacing your team's context or decision.

Nexus architecture

Not one brain. A hive.

Nexus distributes the mission across specialist agents. Each one leaves discoveries, evidence and discarded paths in shared memory so the next can move forward without starting over.

The agents do not share opinions. They share evidence.
01 Mapper Maps surfaces and journeys. 02 Hypothesis Forms paths worth testing. 03 Attack Runs tests inside the scope. 04 Evidence Retains context and replay. Shared mission memory 05 Verifier Attempts a separate reproduction. Your failure is my map.

Shared mission memory. The shared state connects hypotheses, attempts, proof and decisions. Coordination through traces is called stigmergy: the same principle that lets a colony find a route without depending on a single mind.

THE HANDOFF DIFFERENCE

One agent guesses. A mission team builds proof.

Both start with the same authorised target. The difference is what happens when the first path is not the right path.

The conventional agent follows one path, hits a dead end, and restarts. Nexus gives three equal agents direct peer-to-peer communication: a finding is broadcast into a shared evidence graph, related paths continue in parallel, and the final report is independently verified.

ONE THREAD · STARTS OVER

A conventional agent

01

One agent follows one route, then loses the trail.

  • One path at a time
  • No shared findings
  • A dead end means a restart
Same target · more reruns
3 EQUAL AGENTS · DIRECT BROADCAST

Nexus

02

Equal agents share findings directly through a living evidence graph.

  • 3 paths at once
  • Findings reach every peer
  • Independent replay builds trust
Same target · parallel proof

The useful output is not more activity. It is evidence the next specialist can trust.

What we deliver

What you get — and what you don't.

If what you need is in the right column, this product isn't for you. We'll tell you in the qualification so nobody wastes theirs.

Yes it is
  • AI Pentest of an authorised application, API or test environment with Nexus.
  • Report prioritised by real risk (CVSS + context), not by order of arrival.
  • Replay and independent verification for every finding presented as verified.
  • An attack graph and handover session with your technical team.
  • Scope and scope guard confirmed before work starts.
No it isn't
  • A signature scanner, a security chatbot, or an agent without a signed scope.
  • A classic multi-day on-site human pentest.
  • An endless list of 'potential issues' with no prioritisation.
  • Automatic modifications to production.
The process

Three steps. One actionable result.

From an agreed scope to a demonstrated attack path, reproducible evidence and a clear next step for your team.

  1. Start
    Scope + rules

    We define the authorised application, API or environment, the rules of engagement and any test access required. Nexus does not act outside that scope.

    01
  2. Analysis
    Attack + verification

    The hive maps the surface, forms hypotheses and tests paths. A different agent attempts to reproduce each finding before it is marked verified.

    02
  3. Delivery
    Evidence + handover

    You receive verified findings, an attack graph, evidence, replay and priority, with a documented handover for the next decision.

    03
The deliverable

At the end you have this.

  • Two-layer report: an executive CTO readout plus PDF + JSON with verified findings, severity, evidence, reproducible replay and cross-verification.
  • Complete attack chain: target, steps, obtained capabilities and demonstrated impact.
  • Attack graph: confirmed paths and discarded routes that explain how the result was reached.
  • Verification status and priority: what reproduced, what did not and why it deserves attention.
  • Documented handover with the context your technical team needs to decide the next step.

What if you find nothing? We do not pad the report with theoretical alerts. If a finding cannot be reproduced, it is not delivered as verified; if findings appear, you receive priority and context to decide.

Already know what you want to analyse? Check the fit before you reserve budget.

Request AI-Pentest
AI Pentest harness

Offensive capability, inside verifiable limits.

The harness is not another AI model. It is the system of rules, memory, limits and verification that keeps agents inside the agreed mission.

01

Scope guard

The target and rules of engagement are agreed before work starts.

02

Traceable memory

Hypotheses, attempts and evidence remain linked to the path that produced them.

03

Mission limits

Time, resources and access are bounded for a controlled run.

04

Human decision

Your team retains final approval and control of every change.

Questions you'd ask

Doubts that kill the decision.

Why do you call it an AI Pentest harness?

Because Nexus is not only a model. The harness brings specialist agents, scope rules, shared memory, mission limits, evidence and verification into one controlled system.

What if you find nothing?

We do not pad the report with theoretical alerts. If a finding cannot be reproduced, it is not delivered as verified; if findings appear, you receive priority and context to decide.

How is this different from a scanner or chatbot?

A scanner compares signatures and a chatbot suggests answers. Nexus explores paths, tests hypotheses and connects evidence to prioritise what deserves attention.

How do you control the scope?

Before work starts we define the target, authorised environment, test access and rules of engagement. The scope guard keeps the run inside that agreement.

How do you verify a finding?

Every finding includes a reproducible replay and must be repeated by an independent agent. If the result does not match, it is marked unverified or discarded.

What happens to failed paths?

They do not disappear. They remain useful mission memory so other agents do not repeat the same attempt and can test a better hypothesis.

Do you modify my production?

Never. Only sandbox-reviewed proposals, delivered as PRs or separate patch files. Your team decides whether to merge.

Does Nexus replace a human pentester?

It does not remove human judgement. It automates repetitive exploration, correlation and reproduction while your team retains context, supervision and the final decision.

Qualification

Check whether AI Pentest fits your environment.

Share the minimum context. We will review the scope and tell you the next commercial step.

How does it work?
No commitment. If you don't fit, we'll tell you.
Qualification

Check whether AI Pentest fits your environment.

Share the minimum context. We will review the scope and tell you the next commercial step.

Before submitting — verify you fit

0 / 280

No commitment. If you don't fit, we'll tell you.