← Back to archiveXBOW cover

XBOW: Why AI Security Products Sell Evidence, Not Scans

XBOW shows how autonomous security AI can commercialize by turning expert pentesting into a purchasable, audit-ready evidence package with exploit proof, repeat testing, and enterprise controls.

AI security products do not really sell scans. They sell evidence.

XBOW is worth studying because it turns autonomous penetration testing into something an enterprise security team can buy, review, audit, and rerun. The pitch is not just that an AI agent can find vulnerabilities. The more commercial claim is that it can return exploit-validated findings with enough context for engineers to believe, prioritize, fix, and verify them.

That distinction matters. A scanner tells a team that something may be risky. XBOW wants to tell the team that a path can actually be exploited, how the exploit works, what evidence supports the finding, and why the issue should change the team’s remediation priority.

For AI builders, the case is useful because it shows how a high-risk expert workflow can become a product. The model is only one part of the system. The real product is the input boundary, the execution process, the validation loop, the report, the permissions model, the audit trail, and the retest workflow.

Three Signals First

The first signal is pricing. XBOW’s public pricing page lists Lightspeed Plus at $4,000 per test and Lightspeed Premium at $8,000 per test, with Enterprise handled through custom quotes. That is important because it packages a complicated expert service into a concrete buying unit.

The second signal is product shape. XBOW is not positioned as a chatbot for security teams. Its platform describes a loop that learns target context, maps the attack surface, coordinates attack agents, executes attacks, and independently validates results.

The third signal is proof language. The company says it is trusted by more than 150 security teams and has found more than 14,000 zero days. Those figures are company-disclosed and should not be treated as independent audit data, but they show the type of credibility story the product is trying to build.

Many AI products talk about replacing experts. The place where customers actually pay is often more specific: turning an expert result into an output that can be purchased, accepted, repeated, and audited.

XBOW is interesting because it does not stop at the demo layer of “AI can find bugs.” It packages autonomous offensive capability as an enterprise security product. Give it a target and context, let the agents attack, then receive a vulnerability report with exploit proof.

Compressing an Expensive Expert Workflow

Traditional penetration testing has a natural bottleneck. Companies ship software faster than senior security experts can manually test it.

A manual pentest usually requires scoping, scheduling, testing, report writing, remediation, and retesting. By the time a report is delivered, the application may already have changed. Security teams do not ignore the problem; they simply cannot cover every release and every surface at the speed engineering now moves.

XBOW’s product angle is to decompose that workflow into a loop machines can run. Its platform page describes a process that roughly follows five steps: learn the target context, map the attack surface, coordinate attack agents, execute attacks, and validate findings independently.

The last step is the most important one.

AI security tools can easily become alert factories. If a system produces large volumes of vulnerability guesses, it gives the customer more noise, not more leverage. XBOW puts working exploits and attack paths at the center of the product. The message to the buyer is: you are not buying a list of possibilities; you are buying reproducible evidence.

That is a stronger commercial object. Evidence can move through existing security workflows. It can be assigned to engineers, discussed with application owners, attached to remediation tickets, referenced in audits, and retested after a fix. A clever AI answer is impressive. A proof package can change work.

Why It Can Charge

XBOW’s public pricing is direct: Lightspeed Plus is $4,000 per test, Lightspeed Premium is $8,000 per test, and Enterprise is priced by quote.

That structure is strategically interesting. Per-test pricing turns a complicated enterprise service into a low-friction entry point. A buyer does not have to start with a large annual platform contract. They can buy one autonomous pentest, compare the findings with what they already know, and decide whether the delivery is trustworthy.

If the output works, the expansion path is obvious. Enterprise is about continuity: more applications, more teams, more access controls, more integrations, more repeat testing, and more visibility as the application changes.

This is also an existing budget. Security teams already buy penetration testing, vulnerability management, red-team services, compliance support, and audit-ready reports. XBOW is not asking the buyer to invent a new category of spend. It is using AI to repackage a job the buyer already understands and already pays for.

That is a recurring pattern in strong vertical AI products. The customer has a known budget, a known pain, and a known acceptance standard. The AI product wins by making the result faster, more repeatable, and more defensible.

The Real Point in the Moderna Story

XBOW’s Moderna customer story contains a detail that matters more than the generic statement “AI found a vulnerability.”

According to the company story, Moderna’s deputy CISO asked XBOW to test an application that had already been tested and remediated. XBOW found a WAF bypass: when the same path was URL-encoded, the firewall allowed it through and the backend exposed sensitive environment information.

This is still an official customer story, not independent third-party audit evidence. But it illustrates the product logic. The customer is not buying the idea that the model “knows security.” The customer is buying a system that may find an attack path the team previously missed.

The story then becomes more important. XBOW says it chained multiple issues into a broader attack path, completed the chain within 18 hours, and helped the related issues get fixed within 24 hours of discovery. Those time claims should also be treated as company-reported figures. Still, they explain why a security team would care.

The vulnerability is only the start. The commercial loop closes when the engineering organization believes the finding, prioritizes it, fixes it, and can confirm the risk has been reduced.

Distribution Comes From the Leaderboard Story

XBOW has strong distribution material. Its site emphasizes HackerOne ranking, Microsoft critical RCEs, more than 150 security teams, and a large zero-day count.

Third-party media amplified the same broader story. The Verge discussed XBOW in the context of AI attack capabilities and noted that it reached the top of a HackerOne leaderboard in June 2025. WIRED also used XBOW as an example of autonomous AI offensive security becoming more real.

That type of distribution has two sides.

The upside is obvious. Security audiences naturally pay attention to real vulnerability discovery. If the leaderboard story and exploit stories are credible, they travel farther than ordinary SaaS advertising.

The pressure is just as real. The stronger an offensive AI system becomes, the more buyers will ask about authorization boundaries, false-positive controls, audit logs, data isolation, access control, and compliance responsibility. XBOW’s product messaging includes audit logs, independent validation, data isolation, and enterprise certifications or control language such as SOC 2, ISO 27001, PCI DSS, and NIS 2. In product terms, it is trying to package trust alongside capability.

That is the broader lesson: the higher-risk the AI capability, the less a product can rely on capability demos alone. Governance, boundaries, reviewability, and accountability have to be product features.

Three Moves Builders Can Copy

1. Sell an Acceptable Result, Not an AI Capability

XBOW does not simply say it has many security agents. It says findings come with reproducible exploit proof. That is more useful to a buyer.

Many vertical AI products get stuck at the demo stage because the output cannot enter the customer’s normal workflow. The customer sees that the model is impressive, but does not know how to buy it, accept it, explain it internally, or measure return on investment.

If an AI product operates in law, healthcare, finance, security, compliance, or another high-responsibility domain, the first product question should be: can the output become evidence?

2. Enter Through One Paid Delivery, Then Expand Into a Continuous System

The $4,000 and $8,000 per-test packages look like productized service entry points. They reduce the psychological cost of the first purchase and let the buyer evaluate value with one concrete delivery.

But the larger enterprise value is continuous coverage. Once the product can repeatedly test changing applications, manage teams, support API access, integrate with SSO, and expose real-time visibility, it becomes more than a one-time service.

This path applies beyond security. First, turn one expert service into a standardized result. Then, if customers repeat the job, turn the data, permissions, workflow, and history behind those repeated deliveries into a platform.

3. Treat Noise Reduction as a Core Feature

Security teams do not lack alerts. They lack certainty.

Sales teams do not lack call recordings. They lack evidence about what changes outcomes. Legal teams do not lack contract summaries. They lack explainable, traceable, accountable risk judgments.

The stronger an AI product gets, the easier it becomes to create more content. The commercial value often comes from reducing judgment cost. XBOW makes independent validation central because it is selling less uncertainty.

Final Judgment

The lesson from XBOW is not that every AI founder should build in cybersecurity.

The lesson is that high-priced enterprise AI needs an expensive, slow, scarce, evidence-sensitive workflow. Then the product has to compress that workflow into a result customers are willing to buy repeatedly.

In that system, the model is the engine. The product is the boundary around the input, the execution process, the validation mechanism, the report format, the permissions model, and the retesting loop.

Many AI founders still ask whether AI can replace a specific expert. A better question is: inside that expert workflow, which result is expensive, slow to obtain, and most dependent on evidence?

Productize that result first. That is where the business begins.