The whole field, on the record.
Most vendor comparison pages name one rival and rig the table. This one covers every serious player in autonomous and adversarial offensive security — what each genuinely does, how it proves impact, what it has actually shipped, and where K0G differs. Company claims are labelled as claims; figures we could not source are left out, not dressed up. Expand any card for the full read.
Two shifts reset the category.
You cannot read this field without them — and any comparison that ignores them is already stale.
BAS and automated pentesting merged into one class
Gartner's Market Guide for Adversarial Exposure Validation defines AEV as tech that delivers "consistent, continuous and automated evidence of the feasibility of an attack" — and explicitly consolidates the old Breach & Attack Simulation and automated-pentest segments into it. "BAS" as a standalone label is now legacy; Cymulate and Picus have both repositioned onto exposure validation.
The "AI can exploit" moment went mainstream
A frontier-model demonstration of autonomous vulnerability discovery and exploitation reframed vendor messaging across the board — Picus literally launched a platform for "the post-Mythos era," and a model-provider verification program became a de-facto credential. The bar moved from "can AI find bugs" to "can it prove them without making a mess."
Ten capabilities. K0G is the only one with all ten.
These are the ten things a modern offensive-security platform should do — really exploit, chain, prove, run continuously, cover everything, stay autonomous and production-safe, fix and re-verify, and hand you audit evidence. Every competitor does some of them well. K0G is the only platform on this page that does all ten — so on the complete capability set, it comes out ahead of each one, on at least one front, every time.
Scoring reflects each vendor's publicly stated capabilities as of August 2026 and is K0G's own assessment on this fixed capability set — chosen because they are the things K0G commits to. A vendor scoring lower here may lead K0G on axes this scorecard doesn't rank, such as novel human research; see the fair, two-sided view in the category comparison.
Thirteen competitors, analysed.
Filter by how they actually work. Autonomous pentest tools really exploit and chain; BAS & exposure tools simulate against controls; PTaaS & crowd blend humans with agents.
The field on one screen.
Autonomy is how much runs without a person. "Human in loop" flags whether a person validates before you see a finding — a real architectural choice, not a flaw.
"Human in loop" marked amber where a person validates every finding, green where humans sit on configurable exceptions only, grey where it is an optional mode. None of these is wrong — it is the trade between throughput and hand-checking.
What independent data says.
Nearly every number a vendor prints is self-reported. These three are not — and they are the honest backdrop for every claim above, K0G's included.
AI placed second against ten OSCP humans
In a controlled head-to-head on a live ~8,000-host enterprise network, an autonomous agent beat 9 of 10 certified human testers on volume — at roughly $18/hr vs $60/hr — but every AI agent carried a higher false-positive rate than every human, and the top human won on creative chaining.
Valid "hackbot" reports across a full year
Autonomous agents submitted 560 valid reports platform-wide — "primarily surface-level flaws like XSS" — against $81M of human-found bounties. 58% of researchers say AI still misses business logic and chained exploits.
Reliance on full automation fell, hard
Organisations relying entirely on AI automation for testing dropped from 29% to 9% in a year; 47% now prefer a hybrid model, and 78% reported critical false negatives from automated scanning. (A pentest vendor's survey — an interested party, but directionally corroborated.)
The honest synthesis, which K0G is built around: autonomous agents beat the median human tester on breadth, cadence and cost, and trail the best human on business logic and novel research. The winning product is not "AI replaces pentesters" — it is AI that proves the routine majority continuously and safely, and hands the hard, creative work to people.
Methodology & sources. Compiled August 2026 from public company statements, trade press (SecurityWeek, TechCrunch, Help Net Security, SiliconANGLE, Business Wire, Fortune), primary research documents (the ARTEMIS study arXiv 2512.09882; the HackerOne HPSR 9th edition; the Gartner AEV Market Guide; MITRE ATT&CK; OWASP; PTES), and vendors' own pricing and product pages. Figures attributed to a company ("company-reported") are the vendor's own and are not independently verified here. Funding rounds are corroborated across independent trade press. Where sources conflicted (customer counts, total funding), the conflict is stated rather than resolved. Criticisms are attributed to their source and presented neutrally. This is competitive analysis, not legal or investment advice, and reflects public information as of the compile date.