Competitive analysis · Aug 2026

The whole field, on the record.

Most vendor comparison pages name one rival and rig the table. This one covers every serious player in autonomous and adversarial offensive security — what each genuinely does, how it proves impact, what it has actually shipped, and where K0G differs. Company claims are labelled as claims; figures we could not source are left out, not dressed up. Expand any card for the full read.

What changed in 2026

Two shifts reset the category.

You cannot read this field without them — and any comparison that ignores them is already stale.

Gartner · 24 Mar 2026

BAS and automated pentesting merged into one class

Gartner's Market Guide for Adversarial Exposure Validation defines AEV as tech that delivers "consistent, continuous and automated evidence of the feasibility of an attack" — and explicitly consolidates the old Breach & Attack Simulation and automated-pentest segments into it. "BAS" as a standalone label is now legacy; Cymulate and Picus have both repositioned onto exposure validation.

Industry · Apr–Jul 2026

The "AI can exploit" moment went mainstream

A frontier-model demonstration of autonomous vulnerability discovery and exploitation reframed vendor messaging across the board — Picus literally launched a platform for "the post-Mythos era," and a model-provider verification program became a de-facto credential. The bar moved from "can AI find bugs" to "can it prove them without making a mess."

The scorecard

Ten capabilities. K0G is the only one with all ten.

These are the ten things a modern offensive-security platform should do — really exploit, chain, prove, run continuously, cover everything, stay autonomous and production-safe, fix and re-verify, and hand you audit evidence. Every competitor does some of them well. K0G is the only platform on this page that does all ten — so on the complete capability set, it comes out ahead of each one, on at least one front, every time.

K0G 10/10 · complete capability set nearest competitor 8/10 field average 4.9/10
full ~partial / qualified not offered · score counts full capabilities only

Scoring reflects each vendor's publicly stated capabilities as of August 2026 and is K0G's own assessment on this fixed capability set — chosen because they are the things K0G commits to. A vendor scoring lower here may lead K0G on axes this scorecard doesn't rank, such as novel human research; see the fair, two-sided view in the category comparison.

The field

Thirteen competitors, analysed.

Filter by how they actually work. Autonomous pentest tools really exploit and chain; BAS & exposure tools simulate against controls; PTaaS & crowd blend humans with agents.

At a glance

The field on one screen.

Autonomy is how much runs without a person. "Human in loop" flags whether a person validates before you see a finding — a real architectural choice, not a flaw.

"Human in loop" marked amber where a person validates every finding, green where humans sit on configurable exceptions only, grey where it is an optional mode. None of these is wrong — it is the trade between throughput and hand-checking.

The part that isn't marketing

What independent data says.

Nearly every number a vendor prints is self-reported. These three are not — and they are the honest backdrop for every claim above, K0G's included.

2nd

AI placed second against ten OSCP humans

In a controlled head-to-head on a live ~8,000-host enterprise network, an autonomous agent beat 9 of 10 certified human testers on volume — at roughly $18/hr vs $60/hr — but every AI agent carried a higher false-positive rate than every human, and the top human won on creative chaining.

ARTEMIS study · arXiv 2512.09882 · Dec 2025
560

Valid "hackbot" reports across a full year

Autonomous agents submitted 560 valid reports platform-wide — "primarily surface-level flaws like XSS" — against $81M of human-found bounties. 58% of researchers say AI still misses business logic and chained exploits.

HackerOne Hacker-Powered Security Report, 9th ed. · Oct 2025
29→9%

Reliance on full automation fell, hard

Organisations relying entirely on AI automation for testing dropped from 29% to 9% in a year; 47% now prefer a hybrid model, and 78% reported critical false negatives from automated scanning. (A pentest vendor's survey — an interested party, but directionally corroborated.)

Cobalt State of Pentesting 2026 · n=450

The honest synthesis, which K0G is built around: autonomous agents beat the median human tester on breadth, cadence and cost, and trail the best human on business logic and novel research. The winning product is not "AI replaces pentesters" — it is AI that proves the routine majority continuously and safely, and hands the hard, creative work to people.

Methodology & sources. Compiled August 2026 from public company statements, trade press (SecurityWeek, TechCrunch, Help Net Security, SiliconANGLE, Business Wire, Fortune), primary research documents (the ARTEMIS study arXiv 2512.09882; the HackerOne HPSR 9th edition; the Gartner AEV Market Guide; MITRE ATT&CK; OWASP; PTES), and vendors' own pricing and product pages. Figures attributed to a company ("company-reported") are the vendor's own and are not independently verified here. Funding rounds are corroborated across independent trade press. Where sources conflicted (customer counts, total funding), the conflict is stated rather than resolved. Criticisms are attributed to their source and presented neutrally. This is competitive analysis, not legal or investment advice, and reflects public information as of the compile date.