
Vedha
vedha - piercing, going through to what is inside
Authorized penetration testing on a release cadence, not a quarterly one.
Vedha is an autonomous multi-agent penetration testing platform for authorized security work. A goal is decomposed into an ordered plan, specialist agents carry out reconnaissance, discovery, and exploitation attempts inside an ephemeral sandbox, and a knowledge graph retains what has been found so later work builds on it rather than repeating it. Findings arrive as a structured report mapped to control areas. Because agents reason about whether a finding is genuinely exploitable, false positive rates fall well below signature-based scanning.
Workflow
Problem
Manual penetration tests cost tens of thousands and land weeks after the code has already changed, leaving a blind spot between engagements that grows with every deploy.
Outcome
Pentest-quality findings produced continuously against authorized scope, with reasoning and evidence attached to every finding.
01
Scope and authorize
A target and goal are defined against scope the customer explicitly authorizes.
02
Plan and decompose
The goal becomes an ordered set of subtasks, refined as the environment reveals itself.
03
Execute in a sandbox
Tooling runs inside an ephemeral container so the target environment is never put at risk.
04
Report with evidence
Findings are categorized by control area with severity, exploitability reasoning, and remediation.
Modules
Goal Decomposition
A stated testing goal broken into an ordered plan of scoped subtasks.
Sandboxed Execution
Every tool and script runs inside an ephemeral container, isolated from the target environment.
Knowledge Graph Memory
Discovered assets and relationships retained across subtasks and sessions instead of rediscovered.
Structured Reporting
Findings categorized by control area with severity and remediation, ready for a compliance file.
Representative use cases
Continuous Security for a Fast-Moving SaaS Startup
A Series-B SaaS startup ships product updates multiple times per week. Their engineering team of 40 developers deploys microservices across AWS ECS, but they have only one part-time security engineer. Manual penetration tests are performed once a quarter by an external vendor, costing $15,000-$25,000 per engagement, and the reports arrive weeks after the code has already changed.
Pre-Compliance Penetration Testing for a Healthcare Platform
A digital health company building an electronic health records (EHR) platform must satisfy HIPAA security requirements before launching. Their compliance officer needs evidence of penetration testing to include in the security risk assessment. The company's infrastructure includes a React frontend, a Node.js/Express API, a PostgreSQL database, and an S3 bucket storing patient documents.
Red Team Simulation for a Financial Institution
A mid-size bank with 2,000 employees conducts annual red team exercises as part of its cybersecurity maturity program. The internal red team consists of three senior security engineers who manually simulate adversary tactics across the bank's external-facing infrastructure: internet banking portals, mobile API gateways, and partner integration endpoints. Each exercise takes 4-6 weeks.
Securing a University's Research Infrastructure
A large public university runs a sprawling IT environment: student portals, research lab servers, faculty intranets, IoT devices in smart buildings, and shared HPC (High-Performance Computing) clusters. The central IT security team of two people is responsible for securing all of it. They have no budget for commercial penetration testing tools and limited time for manual assessments.
DevSecOps Pipeline Integration for a Cloud- Native Company
A cloud-native company with 200 engineers operates a CI/CD pipeline deploying containerized services to Kubernetes clusters across three cloud regions. They practice \"shift-left\" security but have found that SAST/DAST scanners (Semgrep, ZAP) produce too many false positives and miss logic-level vulnerabilities. They want to add intelligent, context-aware penetration testing as a gate in their deployment pipeline.
Bug Bounty Reconnaissance Acceleration
An independent security researcher participates in bug bounty programs on platforms like HackerOne and Bugcrowd. They target large-scope programs where the attack surface includes hundreds of subdomains, APIs, and legacy applications. Reconnaissance alone subdomain enumeration, port scanning, technology fingerprinting, content discovery consumes 60-70% of their total hunting time.
Evidence
What Wayam can show for this entry
Curated solution design with an owner and a review date. No performance or production claim.
Allowed claims at this tier: Possible workflow, typical stack, prerequisites.
- Evidence tier
- T4 · Reference pattern
- Integration status
- Typical enterprise system
- Metric status
- Scenario only
- Evidence owner
- Not yet attached
- Validated
- Not yet attached
- Valid until
- —
- Content version
- 2026.09
Pending evidence attachment
This entry represents an enterprise architectural reference pattern. Customer benchmarks, run replays, and metric verifications are established during technical discovery.
Limitations
- Headline metrics are representative until a customer result is attached.
Representative metrics · Reference · scenario only
Continuous
testing cadence instead of quarterly
Reasoned
findings assessed for exploitability, not pattern-matched
These describe the intended outcome of the design. They are not measured customer results until a validated case is attached above.
Architecture & controls
Composed across the operating loop
Ingest
Connect the systems of record and read the signals the work already produces.
Covered by the platform
Reason
Ground context, score options against policy and the stated goal, draft the next step.
3 agent roles
Act
Execute an approved step in the system of record and keep the evidence.
Covered by the platform
Govern
Set policy, gate consequential actions on a named approver, and audit what ran.
7 agent roles
Pack Architecture & Agent Composition Graph
10 Composed Agents- AGT-0301
Vulnerability Prioritization Agent
Cyber
- AGT-0259
Security Scanning Agent
Software Engineering
- AGT-0312
Compliance Audit Evidence Agent
Cyber
- AGT-0309
Penetration Test Reporting Agent
Cyber
- AGT-0299
Threat Hunting Agent
Cyber
- AGT-0310
Incident Response Coordination Agent
Cyber
- AGT-0227
Vulnerability Triage Agent
IT Operations
- AGT-0237
CI/CD Build Failure Diagnosis Agent
Software Engineering
Control gates
- A named approver on every consequential write-back
- Evidence and audit trail kept with every run
- In-boundary deployment available
Capability atoms
- workflow-orchestration
- generative-design
- root-cause-reasoning
- risk-scoring
- evidence-audit-trail
- human-approval
- in-boundary-deployment
Typical enterprise systems
Typical stack for solution design; compatibility is validated during discovery.
- Microsoft Sentinel
- CrowdStrike Falcon
- Splunk
- Wiz
- GitHub
- Cursor
- Anthropic Claude Code
- Kubernetes
Designed for
technology, financial-services, healthcare, public-sector
Business case
Model a Vedha scenario with your own baseline
Three scenarios from the numbers you enter. Capacity released is time; it becomes a saving only when roles or costs are actually removed or avoided.
| Scenario | Improvement | Capacity released | Cashable savings | Net annual | Payback |
|---|---|---|---|---|---|
| Conservative | 9% | — | — | — | — |
| Expected | 18% | — | — | — | — |
| Upside | 24% | — | — | — | — |
Enter an annual volume and a baseline cost to see figures.
Illustrative planning scenario, not a guarantee. Results depend on process baseline, adoption, data quality, integration scope, controls, and deployment costs.
Pilot this
From solution design to a bounded pilot
Step 1 · 3–4 weeks
Discovery Sprint
Validate the workflow, data, controls, baseline and business case before anything is built.
Gate: Blueprint and pilot plan signed by the business owner, technical owner and Wayam.
Step 2 · 6–10 weeks
Bounded Pilot
Prove quality and value on agreed data against agreed acceptance tests.
Gate: Acceptance thresholds met on the evaluation set; go/no-go decision recorded.
Pairs well with