FireCompass AI pentest agent hits HackerOne top 3 on $5,000 monthly budget
FireCompass, an EC-Council investee company, reached No. 3 on HackerOne’s U.S. country board during an April-to-June 2026 experiment testing agentic AI against live, authorized production systems. The result underscores how autonomous security tools could reshape offensive testing costs, speed and continuous validation for defenders and attackers alike.
Why it matters: - FireCompass’ result gives enterprises a live-market signal that agentic AI can find real vulnerabilities at scale, not just perform in benchmarks. - The experiment points to a lower-cost model for offensive security testing, which could make continuous validation more practical for defenders. - The same economics may also reduce the barrier for attackers to automate reconnaissance and exploitation.
What happened: - FireCompass took its AI-powered pentest agent into HackerOne’s top three U.S. business researchers during an April-to-June 2026 experiment. - The company operated on an initial budget of about $5,000 per month. - The testing ran against authorized production systems alongside experienced human researchers. - FireCompass recorded peak positions of No. 3 on HackerOne’s U.S. country board, No. 2 for Highest Critical Reputation, ahead of XBOW, and No. 1 in the Up and Comers category. - The rankings were recorded as of July 17 after the primary testing period ended.
The details: - The experiment ran for three months and measured whether agentic AI could produce real offensive security outcomes in live environments. - FireCompass had to stay within each program’s authorized scope, identify legitimate vulnerabilities, provide proof of exploit, and pass independent triage before findings counted. - The system submitted 150 reports during the April-to-June period and 204 reports across the full experiment. - Nineteen reports were accepted as triaged or resolved. - Fifty-eight reports were duplicates of vulnerabilities already reported by other researchers. - Critical- and high-severity findings made up 64.4% of results with assigned severity ratings. - The company used multiple frontier AI models, its own small language models, and an automated workflow to discover, validate, and report vulnerabilities. - The budget covered AI tokens, cloud infrastructure, and human oversight. - Safeguards included hard scope enforcement, non-destructive validation, request-rate and concurrency limits, blast-radius controls, and proof of exploit for every submission. - FireCompass applies agentic AI to autonomous penetration testing and red teaming across web applications, APIs, and infrastructure. - The platform discovers shadow assets and applications, validates exploitability, and links findings into multi-stage attack paths.
Between the lines: - HackerOne’s rankings change daily, so the result is a point-in-time performance measure in a highly competitive environment. - The finding strengthens the case for moving from periodic security reviews to continuous security validation as systems and attack surfaces change. - EC-Council framed the milestone as evidence that AI should augment, not replace, cybersecurity professionals. - FireCompass founder and CEO Bikash Barai said the economics matter as much for attackers as defenders, and that controls, safety, and accountability are the next challenge.
What’s next: - FireCompass and EC-Council are positioning agentic AI as a tool for more frequent testing, earlier exposure validation, and faster prioritization of the highest-risk issues. - The company says the approach can help security teams focus human expertise on the most important risks while maintaining continuous coverage. - The methodology note says the rankings reflect peak positions during and immediately after the experiment, and HackerOne did not sponsor, verify, approve, or endorse the announcement.
The bottom line: - FireCompass’ HackerOne performance suggests autonomous security testing can work in the wild under tight controls, with meaningful results at a relatively low monthly cost.
Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.
Sign up for:
Sci-Tech News Today
The daily local news briefing you can trust. Every day. Subscribe now.
Check Your Email!
We sent a one-time activation link to: .
Confirm it's you by clicking the email link.
If the email is not in your inbox, check spam or try again.
Welcome back!
is already signed up. Check your inbox for updates.