Pentesting that keeps up with how often you ship.
A yearly pentest is out of date a few releases later. Barrion's AI agents test your web apps and APIs on a schedule or on demand, and check each finding against your live app before it reaches your report.
Barrion runs continuous, agentic AI penetration tests of web applications and APIs. AI agents test your app the way an attacker would, safely, on a schedule, from your CI/CD pipeline through the Barrion API, or on demand. Findings are checked against the live app before they're reported, and tracked across runs as new, still open, resolved or regressed. From Standard level up, a security engineer reviews each report. Barrion AB is based in Gothenburg, Sweden.
Barrion AB · Org. no. 559569-0917 · Gothenburg, Sweden · Barrion facts

The gap we kept running into.
A yearly pentest report is out of date a few releases later. Scanners give you a list of maybes and leave the triage to you. We built Barrion to pentest as often as you ship, check findings against the live app, and hand you a fix for your stack.
Built by developers, for developers
Safe to point at production
Tests that rerun as you ship
Reports your auditor can use
Self-serve, no forced sales call
Fixes engineers can ship today
Engineers who live in the same problem you do.

Barrion started as the tool we looked for in our previous roles: automated, time-efficient, and easy enough for any engineer to operate. Security was the thing we knew mattered, but we only got a pentest once a year, and by the next release it was already out of date. Our goal with Barrion is to help engineering teams ship secure software, and to give security teams the repeatable part of their work back.
Built for engineering teams that ship every week.
- ✓Engineering teams that want their pentests on the same rhythm as their releases
- ✓SaaS teams facing an enterprise security review, or a SOC 2, ISO 27001 or PCI DSS audit
- ✓Agencies that need a real test of a client app before handover
- ✓Teams without a security engineer who still want findings someone has checked
Pentests on your release rhythm, a free scan to start.
AI agents test your app and API
On a schedule
Checked, then reviewed
First report in about 60 seconds
Why we started Barrion.
Across our previous roles, the same pattern kept showing up. Security would land at the worst possible moments: a customer security review the week before a deal closed, an audit that surfaced misconfigurations dating back months, a prospect who wanted a recent pentest report nobody had to show them. We ordered a pentest once a year, and between those, security was whatever someone found time for. We sat in the gap between the once-a-year pentest and a security program that runs on its own.
The existing tools were either built for large enterprise security organisations we didn't have, or so noisy that triaging their output became a part-time job. We wanted something that tested our live applications as often as we shipped, told us which findings actually held up, suggested fixes specific to our stack, and produced a report we could hand a customer as is. Barrion is what came out of that brief.
What we test, and how we test it.
Barrion has two parts: AI pentesting, and a free passive scan that also runs as ongoing monitoring on paid plans. They answer different questions. A pentest asks whether someone can actually get in. The passive scan asks whether anything visible from outside is set up wrong.
In a pentest, a coordinating agent runs one specialist agent per testing area, in parallel, in an isolated sandbox with tools like sqlmap, nuclei, ZAP and ffuf. The agents send crafted requests to your app and API and chain them across steps. They look for SQL injection, cross-site scripting, broken access control and IDOR, server-side request forgery, broken authentication and business-logic abuse. Coverage maps to all 97 OWASP WSTG v4.2 test cases, the OWASP Top 10 and the OWASP API Security Top 10. Runs are rate-limited and non-destructive, and you approve the scope before any traffic is sent.
Before a finding reaches you, its request is replayed against the live app. If it doesn't reproduce, we drop it. If it can't be replayed, it stays in the report as a lower-confidence lead. Confirmed findings come with the request and response that prove them. From Standard up, a security engineer reviews the findings, and deeper tests come with a report signed off by that engineer.
The passive scan only reads what your application already exposes: TLS and certificates, HTTP security headers, cookie flags, CORS, DNS and email authentication (SPF, DKIM, DMARC, DNSSEC, CAA), open ports, subdomain takeover candidates and JavaScript libraries with known CVEs. It never submits a form or touches a state-changing route, so it's safe on production. It's the free way in, and it keeps watching for drift between pentests. What it can't tell you is whether an issue is exploitable. That's the pentest's job.
How often it actually needs to run.
Match the test to your release rhythm. If you ship every day, a Light pentest every day catches a regression the day it lands. You can mix depths on one target, say a daily Light run and a monthly Deep one.
You can also have a schedule run only when your app has changed. Barrion compares a snapshot of your start page's links and scripts and, if something changed, reruns the full pentest at the depth you chose. A backend-only change won't show up in that snapshot, so keep a fixed schedule next to it.
Every run is compared with the one before, and each finding is labelled new, still open, resolved or regressed. Scheduled pentests are part of the Business plan. Passive monitoring runs alongside them, weekly on Essential and daily on Business. You can also start a pentest from your CI/CD pipeline via the Barrion API, or on demand whenever you need one.
Continuous programs are scoped to your apps, cadence and depth. Talk to us and we'll price it for your setup.
Common questions about Barrion.
Who is Barrion for?
How is Barrion different from a traditional pentest?
Is Barrion safe to run against my production app?
What compliance frameworks does Barrion cover?
Do I need to install anything?
Questions about Barrion? Talk to us.
Pentest scoping, pricing or support: tell us what you need and someone on the team gets back to you.