What is XBOW?
XBOW is a Seattle-based autonomous offensive security company founded by Oege de Moor, who created GitHub Copilot. Its AI agents test web apps and their APIs, and independent validators confirm each exploit before a finding is reported. In June 2025 it became the first autonomous system to rank #1 on HackerOne's US leaderboard.
Comparison at a glance
| Aspect | Barrion | XBOW |
|---|---|---|
| What it tests | Web apps and APIs, including authenticated testing as several users in named roles. 8 testing areas and all 97 OWASP WSTG v4.2 cases | Web applications and their APIs, including authenticated testing with credentials and API specs you supply. Other asset types are on its roadmap |
| How it validates findings | Every finding is checked against the live app. Confirmed ones come with the request and response that prove them. Anything unconfirmed is clearly marked and capped in severity | Independent validators confirm exploitability. Validated findings carry a full exploit, reproduction steps and evidence. Issues it can't exploit are listed as informational |
| Continuous and scheduling | On a schedule you set (daily to yearly, or a custom rhythm), every time or only when the app has changed, or on demand. Each run labels findings new, still open, resolved or regressed | Runs "every time your applications change", with no scheduling window. Separate retest assessments check fixes |
| Human involvement | AI agents do the testing. From Standard level up a security engineer reviews the findings, and deeper tests come with a report signed off by that engineer. Retests of found issues are free | Mentions review before findings surface, without saying who reviews. No human tester or report sign-off stated |
| Pricing model | Plans and per-run prices are public on the pricing page. Continuous programs are priced through sales | Usage-based, scaled to coverage. No public price. Also sold on the AWS, Google Cloud, Oracle and Microsoft marketplaces |
| Self-serve or sales | Self-serve for single pentests. Continuous programs through sales | Through a quote or a demo |
| Data residency | Stored and hosted in Sweden. AI processing in the EU | US by default. EU (Frankfurt) and Singapore regions are in private preview for Enterprise |
| What it doesn't do | No internal network, Active Directory, mobile, physical or social engineering testing | Web apps and APIs only for now. Its docs say it may not test every endpoint in a single assessment |
XBOW facts checked 2026-09-26 on the vendor's own site: XBOW, XBOW platform, XBOW pricing, XBOW asset types, XBOW interpreting results, XBOW data residency, SecurityWeek on XBOW's Series C (2026-03-18).
Who Barrion is best for
Choose Barrion if you're a SaaS or product team that wants to start a pentest this week without a sales cycle, wants a security engineer to review findings from Standard level up with signed-off reports on deeper tests, or needs data stored in Sweden with AI processing in the EU today. Scheduled runs label each finding new, still open, resolved or regressed.
Who XBOW is best for
Choose XBOW if you have a large portfolio of web apps to test at once, want usage-based pricing through a cloud marketplace, or want the vendor with the most public track record in autonomous exploitation, including its #1 ranking on HackerOne. It's the stronger choice at enterprise scale.
Frequently asked questions
Is Barrion an XBOW alternative?
Yes, for web app and API pentesting. Both use AI agents and confirm findings against the live app before reporting them. XBOW is built for large portfolios on usage-based pricing. Barrion is self-serve for single pentests, adds security engineer review from Standard level up, and stores data in Sweden.
Does XBOW have human review?
XBOW's platform page mentions review before findings surface but doesn't say who does it (checked 2026-09-26). Its findings are confirmed by automated validators. Barrion's agents do the testing, and from Standard level up a security engineer reviews the findings. Deeper tests come with a report signed off by that engineer.
How much does XBOW cost compared with Barrion?
XBOW doesn't publish a price. It uses usage-based pricing through a quote or a cloud marketplace. Barrion's Essential plan starts at €199/month and per-run prices are on the pricing page. Scheduled pentests are on the Business plan, priced through sales.
Can XBOW keep data in the EU?
XBOW's docs list the US as the default region, with EU (Frankfurt) and Singapore regions in private preview for Enterprise customers (checked 2026-09-26). Barrion stores and hosts data in Sweden and processes AI in the EU on every plan.
Does either test internal networks?
No. Both test web apps and APIs. For internal networks and Active Directory, look at Pentera or Horizon3.ai NodeZero.
Summary
XBOW and Barrion agree on the part that matters most: a finding without proof isn't a finding. XBOW is the bigger platform, built for enterprises with hundreds or thousands of apps and bought through a quote. Barrion is the easier start for a single product team, adds human review of findings from Standard level up and keeps data in the EU by default. If you're comparing more options, see our list of XBOW alternatives.
Explore Barrion further
See how Barrion's AI pentest works on the AI pentesting page, compare more vendors in best AI pentesting tools, or check what each plan includes on the pricing page.