About

Pentesting that keeps up with how often you ship.

A yearly pentest is out of date a few releases later. Barrion's AI agents test your web apps and APIs on a schedule or on demand, and check each finding against your live app before it reaches your report.

Barrion runs continuous, agentic AI penetration tests of web applications and APIs. AI agents test your app the way an attacker would, safely, on a schedule, from your CI/CD pipeline through the Barrion API, or on demand. Findings are checked against the live app before they're reported, and tracked across runs as new, still open, resolved or regressed. From Standard level up, a security engineer reviews each report. Barrion AB is based in Gothenburg, Sweden.

Barrion AB · Org. no. 559569-0917 · Gothenburg, Sweden · Barrion facts

Used by 5,000+ developers and engineering teams
Oracle logoShopify logoGoDaddy logoChubb logoToshiba logoMAPFRE logoBelfius logoHolcim logo
Why we built it

The gap we kept running into.

A yearly pentest report is out of date a few releases later. Scanners give you a list of maybes and leave the triage to you. We built Barrion to pentest as often as you ship, check findings against the live app, and hand you a fix for your stack.

Developer-first

Built by developers, for developers

Barrion was created by engineers who got tired of waiting for security teams that didn't exist. Every check, every report, every fix-it suggestion is shaped by what we wished we had at our last startup.
Safe by default

Safe to point at production

Pentests are rate-limited and non-destructive, and nothing is sent until you've approved the scope. Staging works too. The free passive scan only reads what your app already exposes, so it never submits a form.
Continuous

Tests that rerun as you ship

Save a pentest and it reruns daily, weekly, monthly or on your own rhythm. Or have it run only when your app has changed. Every run labels findings new, still open, resolved or regressed, so a fix that breaks again shows up in the next run instead of at next year's test.
Audit-ready

Reports your auditor can use

PDF, XLSX and JSON, with an OWASP WSTG coverage matrix. From Standard up a security engineer reviews the findings, and deeper tests come with a report signed off by that engineer.
Pragmatic

Self-serve, no forced sales call

Per-run pentest prices are on the website and you pay in credits. Retests of found issues are free. When you want a continuous program scoped to several apps, talk to us and we'll price it for your setup.
Actionable

Fixes engineers can ship today

Every finding ships with a plain-language explanation and step-by-step remediation tailored to your stack (Next.js, Django, Laravel, Rails, and more), not a CVE link and a CVSS score.
Built by

Engineers who live in the same problem you do.

Mikael Karlgren
Mikael Karlgren
Founder

Barrion started as the tool we looked for in our previous roles: automated, time-efficient, and easy enough for any engineer to operate. Security was the thing we knew mattered, but we only got a pentest once a year, and by the next release it was already out of date. Our goal with Barrion is to help engineering teams ship secure software, and to give security teams the repeatable part of their work back.

Coverage
97
OWASP WSTG v4.2 test cases
Plus the OWASP Top 10 and API Security Top 10.
Cadence
Daily
Scheduled pentests, daily to yearly
Or only when your app has changed.
Users
5,000+
Developers and engineering teams
Signed up to use Barrion.
Free passive scan
60s
First passive report
Reads TLS, headers, cookies and DNS. A quick look at your attack surface.
Who Barrion is for

Built for engineering teams that ship every week.

  • ✓Engineering teams that want their pentests on the same rhythm as their releases
  • ✓SaaS teams facing an enterprise security review, or a SOC 2, ISO 27001 or PCI DSS audit
  • ✓Agencies that need a real test of a client app before handover
  • ✓Teams without a security engineer who still want findings someone has checked
How we work

Pentests on your release rhythm, a free scan to start.

Pentest

AI agents test your app and API

A coordinating agent runs one specialist per testing area, in parallel, inside an isolated sandbox. They test your web app and API the way an attacker would, rate-limited and non-destructive, within the scope you approved.
Rerun

On a schedule

Save the test once. It reruns on the schedule you pick, or only when your app has changed. Retests of found issues are free.
Review

Checked, then reviewed

Findings are checked against the live app before they're reported. Anything we can't confirm stays in the report as a lower-confidence lead, clearly marked. From Standard up, a security engineer reviews the findings.
Free passive scan

First report in about 60 seconds

Not ready for a pentest? Enter your URL for a free passive scan. It reads what your app already shows (TLS, headers, cookies, DNS) and gives you a first report with fixes. It doesn't test whether anything is exploitable.
Origin

Why we started Barrion.

Across our previous roles, the same pattern kept showing up. Security would land at the worst possible moments: a customer security review the week before a deal closed, an audit that surfaced misconfigurations dating back months, a prospect who wanted a recent pentest report nobody had to show them. We ordered a pentest once a year, and between those, security was whatever someone found time for. We sat in the gap between the once-a-year pentest and a security program that runs on its own.

The existing tools were either built for large enterprise security organisations we didn't have, or so noisy that triaging their output became a part-time job. We wanted something that tested our live applications as often as we shipped, told us which findings actually held up, suggested fixes specific to our stack, and produced a report we could hand a customer as is. Barrion is what came out of that brief.

Methodology

What we test, and how we test it.

Barrion has two parts: AI pentesting, and a free passive scan that also runs as ongoing monitoring on paid plans. They answer different questions. A pentest asks whether someone can actually get in. The passive scan asks whether anything visible from outside is set up wrong.

In a pentest, a coordinating agent runs one specialist agent per testing area, in parallel, in an isolated sandbox with tools like sqlmap, nuclei, ZAP and ffuf. The agents send crafted requests to your app and API and chain them across steps. They look for SQL injection, cross-site scripting, broken access control and IDOR, server-side request forgery, broken authentication and business-logic abuse. Coverage maps to all 97 OWASP WSTG v4.2 test cases, the OWASP Top 10 and the OWASP API Security Top 10. Runs are rate-limited and non-destructive, and you approve the scope before any traffic is sent.

Before a finding reaches you, its request is replayed against the live app. If it doesn't reproduce, we drop it. If it can't be replayed, it stays in the report as a lower-confidence lead. Confirmed findings come with the request and response that prove them. From Standard up, a security engineer reviews the findings, and deeper tests come with a report signed off by that engineer.

The passive scan only reads what your application already exposes: TLS and certificates, HTTP security headers, cookie flags, CORS, DNS and email authentication (SPF, DKIM, DMARC, DNSSEC, CAA), open ports, subdomain takeover candidates and JavaScript libraries with known CVEs. It never submits a form or touches a state-changing route, so it's safe on production. It's the free way in, and it keeps watching for drift between pentests. What it can't tell you is whether an issue is exploitable. That's the pentest's job.

Schedule

How often it actually needs to run.

Match the test to your release rhythm. If you ship every day, a Light pentest every day catches a regression the day it lands. You can mix depths on one target, say a daily Light run and a monthly Deep one.

You can also have a schedule run only when your app has changed. Barrion compares a snapshot of your start page's links and scripts and, if something changed, reruns the full pentest at the depth you chose. A backend-only change won't show up in that snapshot, so keep a fixed schedule next to it.

Every run is compared with the one before, and each finding is labelled new, still open, resolved or regressed. Scheduled pentests are part of the Business plan. Passive monitoring runs alongside them, weekly on Essential and daily on Business. You can also start a pentest from your CI/CD pipeline via the Barrion API, or on demand whenever you need one.

Continuous programs are scoped to your apps, cadence and depth. Talk to us and we'll price it for your setup.

FAQ

Common questions about Barrion.

Who is Barrion for?
SaaS teams and agencies that ship often, with or without a security team of their own. Engineering teams use it to pentest their web apps and APIs on the same rhythm they release. Plenty of individual developers start with the free passive scan and add pentests later.
How is Barrion different from a traditional pentest?
A traditional pentest is a human engagement at one point in time, usually once a year. Barrion's AI agents run the pentest on a schedule or on demand, and compare every run with the last, so you see what's new, what's fixed and what came back. From Standard up, a security engineer reviews the findings. For judgement-heavy work such as threat modelling, a human-led test is still worth doing from time to time.
Is Barrion safe to run against my production app?
Yes. Pentests are rate-limited and non-destructive, and they only start once you've approved the scope. If you'd rather begin on staging or a preview environment, that works too. The free passive scan is read-only: it never submits forms, brute-forces endpoints or touches state-changing routes.
What compliance frameworks does Barrion cover?
Pentest reports come as PDF, XLSX and JSON with an OWASP WSTG coverage matrix, and passive monitoring adds timestamped PDF and CSV exports. Teams use both as evidence for SOC 2, ISO 27001, PCI DSS, GDPR, HIPAA and NIS2. They support your audit rather than certify compliance. Framework notes are on the /compliance pages.
Do I need to install anything?
No. Barrion runs in the cloud. For a pentest you verify that you own the target, set the scope and, for authenticated testing, add test accounts. The free passive scan needs only a URL and returns a first report in about 60 seconds.

Questions about Barrion? Talk to us.

Pentest scoping, pricing or support: tell us what you need and someone on the team gets back to you.