Always-on AI pentesting for your web apps and APIsAlways-on AI pentestingStart an AI pentest

Always-On Agentic Pentesting for Engineering Teams

Barrion's AI agents test your web apps and APIs autonomously and safely, the way an attacker would. Run continuously or on demand, as often as you ship.

Not ready for a pentest? Start with a free passive scan.

Rate-limited, non-destructive No setup or code required Clear fix for every finding
Used by 5,000+ developers and engineering teams
Oracle logoShopify logoGoDaddy logoChubb logoToshiba logoMAPFRE logoBelfius logoHolcim logo

Stored and hosted in Sweden. AI processing in the EU.

How it works

From the first test to always-on.

AI agents test your web app or API, and you decide how often they come back.

Step 01

Set the scope

Add your web app or API, verify you own it and approve what the agents may test. Add test accounts if you want authenticated testing.

Step 02

Agents test

Specialist agents work in parallel, rate-limited and non-destructive. Findings are checked against the live app before they're reported.

Step 03

Keep it running

Save the pentest and it reruns on a schedule. Each run shows what's new, still open, resolved or regressed.

Want a quick baseline first? Run a free passive scan of your TLS, headers and cookies in about 60 seconds.

Start an AI pentestRun a free passive scan
Why Barrion

Pentesting that doesn't stop at the report.

Continuous AI pentesting

Deep pentests that keep running

AI agents test your app the way an attacker would, chaining requests across endpoints to confirm which vulnerabilities are exploitable. Run it on a schedule, from your pipeline or on demand. Each run checks its findings against your live app and shows what's new, what's fixed and what came back.

See how continuous pentesting works
Passive scanning

A light check between pentests

A read-only scan of your live app that flags misconfigurations and security drift on a schedule. It runs from the outside, so there's nothing to install and no credentials to share.

About passive scanning
Remediation

Step-by-step fixes

Every finding comes with a plain-language explanation and exact remediation steps your team can ship immediately.

Reports

Reports you can hand over

PDF, XLSX and JSON reports mapped to OWASP WSTG. From Deep up a security engineer signs the report off. Teams use them as evidence for SOC 2, ISO 27001 and NIS2 work.

See a sample pentest report
Built for

For software companies that outgrew yearly pentests.

Barrion is made for growing SaaS teams with more apps than security people, and also fits a two-person dev team, an agency or an in-house security team. It pentests your apps as often as you ship and keeps watch in between.

StartupsSMEsAgenciesScale-upsEnterprise

Growing SaaS companies

You run several apps and APIs, enterprise customers want a recent pentest report, and NIS2, ISO 27001 or SOC 2 is on the calendar. Pentests rerun on a schedule, deeper tests come with a report signed off by a security engineer, and retests of fixed findings are free.

Small dev teams and startups

No security hire needed. Run a pentest before a launch or your first security review, get each finding in plain language with a fix for your stack, and retest it for free once the fix ships.

Agencies and security teams

Pentest every client app or every product line from one account. Teams & organizations share access and reports, and API access lets you start pentests from your own pipeline.

Pricing

Pricing that starts free.

Paid plans come with AI pentest credits every month, plus passive scans, alerts and reports. Business adds continuous pentesting.

Free
€0/mo

No credit card required.

Get started

Top-up pentest credits

No plan needed. Buy credits and spend them on a pentest whenever you want. Buy credits

  • Core passive, read-only scans
  • Step-by-step remediation
  • Security score history
Essential
€199/mo

Cancel anytime.

Subscribe

About 1 Light pentest a month.

  • Everything in Free, plus:
  • 410 pentest credits a month
  • Complete passive, read-only scans
  • Weekly passive scans, 1 domain
  • Email alerts
  • Standard support
From the founder

“We used to get one pentest a year, and the report was out of date a few releases later. We built Barrion so every release gets tested the way an attacker would, not just the one in the audit window.”

Mikael Karlgren, Founder of Barrion
Mikael Karlgren, Founder of Barrion
LinkedIn
FAQ

Frequently asked.

What is Barrion?
Barrion runs continuous, agentic AI penetration tests of web applications and APIs. AI agents test your app the way an attacker would, safely, on a schedule or on demand. Findings are checked against the live app before they're reported, and tracked across runs as new, still open, resolved or regressed. From Standard level up, a security engineer reviews each report. Barrion AB is based in Gothenburg, Sweden. A free passive scan is the quickest way to start.
How safe is Barrion to use for security testing?
AI pentests send real test requests, so they're rate-limited and non-destructive, and you approve the exact scope before a single request goes out. You can point them at staging too. The free passive scan only reads your live app. It never submits forms, brute-forces endpoints or touches anything that changes state, so it's safe to run against production.
What types of security issues does Barrion identify?
AI pentests look for the issues an attacker could exploit, like SQL injection, cross-site scripting and broken access control. Findings are checked against your live app, and confirmed ones come with the request and response that prove them. Anything we couldn't confirm is clearly marked and capped in severity. The passive scan catches misconfigurations in TLS and HTTPS, security headers, cookie flags, CORS policy, DNS records, email authentication (SPF, DKIM, DMARC) and network exposure.
What specific security checks does Barrion perform?
Barrion covers two surfaces. AI pentesting is the active part: specialist agents chain requests to find exploitable flaws such as SQL injection, cross-site scripting and broken access control. Findings are checked against your live app, and confirmed ones come with the request and response that prove them. The passive scan is read-only and safe to point at production. On paid plans it runs 35+ checks (18 on the free plan): transport security (HTTPS, HSTS, TLS version, cipher suites, certificate expiry, hostname and chain validity, OCSP stapling), HTTP response headers (Referrer-Policy, Permissions-Policy, X-Content-Type-Options, Content-Type, server information disclosure), CSP and framing (Content-Security-Policy, bypass detection, Trusted Types, X-Frame-Options), cross-origin policy (COOP, COEP, CORP and the full CORS header set), cookie flags and anti-CSRF tokens, mixed content, vulnerable JavaScript libraries, DNS records including DNSSEC and CAA, email authentication (SPF, DKIM, DMARC), open ports and subdomain takeover. Findings from both are ranked by severity and come with step-by-step remediation.
Will our auditor or enterprise customer accept the report?
The report maps every finding to OWASP WSTG, a security engineer reviews it from Standard up and signs it off from Deep up, and a free retest shows what you fixed. Teams use it as evidence for SOC 2, ISO 27001 and NIS2 work. Whether it's accepted is up to your auditor.
How often does Barrion test my app?
Continuously or on demand. On the Business plan you save a pentest and it reruns daily, weekly, monthly, quarterly, every six months, yearly or on your own rhythm. On any plan you can start a pentest or a passive scan on demand. A passive scan also runs on a schedule and alerts you when something new shows up.
Is Barrion suitable for security testing of all business sizes?
Yes. Solo developers often start with the free passive scan and a single pentest. Teams with several apps run pentests on a schedule, and it fits alongside the tools you already run.
How does Barrion handle data security and privacy during security testing?
Passive scans are read-only: they only look at what your app already exposes publicly. For AI pentests we store the findings and the evidence behind them, the requests and responses that confirm each issue, so you can review and reproduce them. Test credentials you add are encrypted. Data is stored and hosted in Sweden and AI processing runs in the EU. Our trust page lists every subprocessor. Pentests are rate-limited and only run inside the scope you approve.
What if I'm not satisfied with Barrion's security testing service?
You can cancel anytime in the dashboard, and paid plans carry a 14-day refund window from the first charge. If something isn't right, contact us and we'll make it work for your team.
How does Barrion help with SOC 2, ISO 27001, NIS2, and other compliance frameworks?
Barrion's pentest reports come as PDF, XLSX and JSON, mapped to all 97 OWASP WSTG test cases, with engineer review from Standard up, sign-off from Deep up and a free retest after fixes. Teams use them as evidence that supports SOC 2, ISO 27001, PCI DSS and NIS2 work. Whether a report is accepted is up to your auditor or customer.

Anything else? Email contact@barrion.io.

Secure your apps before
someone else finds the gaps.

Used by 5,000+ developers and engineering teams. Start with one pentest or put your apps on a schedule.