FailSafe SWARM is #1 on CVE-Bench

Trusted by leading technology companies worldwide.

    • NVIDIA
    • Vercel
    • Grab
    • NVIDIA
    • OpenAI
    • Anthropic
    • Coinbase
    • OpenAI
    • NEAR
    • AWS
    • Base
    • NEAR
    • Consensys
    • Ensign
    • OpenEden
    • Consensys

Proof system

Security claims you can check.

Versioned benchmarks, public traces, and coordinated disclosures make our work inspectable.

As of August 2026, FailSafe SWARM holds the highest reported score on CVE-Bench v2.1.0: 62.5% zero-day and 70% one-day at pass@1 (28 of 40 targets), graded by a deterministic oracle with results published under MIT.

Check the evidence

FailSafe's AttackBench, developed with NEAR, ran 624 hostile exchanges between an attacker model and defending AI agents across three runtimes.

Check the evidence

FailSafe has disclosed 240+ vulnerabilities across 101 coordinated reports, including findings at Deutsche Bank, MUFG, Zurich Insurance, and Vercel.

Check the evidence
12 days12 hours

Continuous Testing on Every Deploy

Launch pentests in minutes and receive exploit-validated findings the same day, matching the pace of daily engineering releases.

Exploit Verified

Validated Exploits, Zero False Positives

Every issue is proven with a safe reproduction trace. If a vulnerability cannot be exploited in context, it is not reported as an emergency.

MAS
SOC 2
ISO 27001

Auditor-Approved Compliance Reports

Findings and remediation verifications are formatted directly for SOC 2 Type II, ISO 27001, PCI-DSS, and MAS TRM requirements.

Gartner

“By 2028, over 60% of enterprise pen test programs will operate as continuous validation, replacing annual assessments as the primary proof of resilience.”

Gartner·How to Implement a Continuous Offensive Security Testing Program, 2026

Recognition

Industry Recognition

EDB

Global Founder Programme

Anthropic

Cyber Partner

Meet The Drapers

2025 Winner

Regulation Asia

Best Security 2025

Immunefi

Top 3 Auditor

CoinDesk

Consensus 2024 Winner

Codehawks

Top 3 Auditor

AWS

2026 Partner

CREST Certification

Questions & answers

Frequently asked questions

Quick answers about FailSafe's services, coverage, and engagement process.

FailSafe Security builds autonomous penetration testing and continuous offensive security systems. It combines GlassBreak cyber-model R&D, SWARM agentic execution, Continuous Threat Exposure Management (CTEM) workflows, and human-led security research for applications, APIs, cloud infrastructure, and AI systems.

Traditional pentests are point-in-time snapshots conducted once a year that take weeks to schedule and deliver. FailSafe SWARM runs continuously throughout the year, validating attack paths as code and infrastructure deploy, and retesting remediated findings on demand.

Unlike vulnerability scanners that flag theoretical pattern matches, FailSafe SWARM validates suspected vulnerabilities by constructing working, safe proof-of-concept exploits in your authorized environment. If a vulnerability cannot be exploited in context, it is not reported as an emergency.

Yes. Every FailSafe pentest report includes an executive summary, technical methodology, CVSS/CWE scores, MITRE ATT&CK mappings, proof-of-concept evidence, and verification confirmation. Reports are formatted for SOC 2 Type II, ISO 27001, PCI-DSS, and MAS TRM compliance submissions.

FailSafe tests web applications, APIs, cloud infrastructure, identity controls, Active Directory, LLM applications, AI agents, MCP servers, and specialized critical code.