RUN THE FULL KILL CHAIN ON YOUR OWN ORGANIZATION. BEFORE AN ATTACKER DOES.

Authorized, under your command, inside your network.

// Where an attacker goes

  1. 01 Compromise a person
  2. 02 Cross identity
  3. 03 Exploit systems
  4. 04 Persist + move
  5. 05 Hijack the agent
  6. 06 Critical impact
app.cracken.ai — realm operation
// The model

Cyber opened. Everything else still refuses.

Performs the authorized offensive work every guarded frontier endpoint declines.

MODELEnabled on request — Red is never bundled into a plan.
  • Anthropic logo
  • Google logo
  • Meta logo
  • CRACKENRED
model picker
The Cracken model picker: Red, security-specialised, selected above the general Max and Smart tiers.
UNIQUE HARNESS
  1. Distributed Tentacles 
  2. Shared filesystem 
  3. Cybergraph 
  4. Cyber orchestrationA playbook plans the engagement and dispatches specialist sub-operations — recon, testing, verification — each with its own tools and model.
PLAYBOOKSPhases, model and tools, pinned before anything runs.
See the five playbooks
// Safe by design

Offensive and safe.

Nothing runs above the intrusiveness level you allow, or against a target outside your scope.

A browser action proposed as “navigate to https://vulnbank.org”, held below it at “Waiting for approval”
Above the level you allow, the run proposes the action and stops.

Human in & on the loop

Manual holds every action for approval. Semi puts you on the loop, not in it.

Unique semi-autonomy

Set per operation. Where sub-operations exist it cascades to them by default, and you can scope it back to one.

Group killswitches

Pause, resume and autonomy changes cascade to the whole sub-operation tree, not just the one you clicked.

Sandboxing

Each Tentacle runs isolated, and its egress can be pinned to a fixed, revocable IP.

Secret scanning & redaction

The model gets a reference, never the value — and output is stripped as it streams.

Operation ledger

Every action and the reasoning behind it, recorded in sequence as the operation runs — and every node type carries a link back to the work that produced it.

// Auto-approve up to

  1. PassiveWeb research, Cybergraph queries
  2. Read onlycurl GET, dig, whois, ping
  3. Enumerationnmap, masscan, ffuf, gobuster
  4. Validationcurl POST, exploiting a vulnerability
  5. Destructiverm -rf, mkfs, passwd changes

Reaching the destructive rung takes a custom policy — no preset goes there.

// Deployment

Deploy anywhere.

Nothing has to leave your network.

+ arrives inside your boundary. Everything else was already where it is.

  1. 01SaaS
    • backendruns at Cracken · US / UK
    • databaseruns at Cracken · US / UK
    • modelcommercial endpoint
    • tentacleon hosts you control
    Nothing is delivered — the Tentacle is already yours, on your hosts.
  2. 02Private cloud
    • backendinto your tenancy
    • databaseinto your tenancy
    • modelendpoint, or self-hosted
    • tentacleon hosts you control
    Credentials and synced findings stay inside.
  3. 03On-premises
    • backendyour infrastructure
    • databaseyour infrastructure
    • modelself-hosted
    • tentacleon hosts you control
    Only selected, redacted results leave.
  4. 04Air-gapped
    • backendyour infrastructure
    • databaseyour infrastructure
    • modelself-hosted, or a reachable endpoint
    • tentacleon hosts you control
    Removed: the live internet link. Output quality is somewhat reduced without it.
Execution never moves. The Tentacle never arrives, because it never left — it runs on hosts you control in every mode, including SaaS.
// Execution

Distributed Tentacles.

Execute next to your target, or wherever you have the compute.

Shared filesystem — one store every Tentacle reads and writes.

Scanners only look at CVEs. What I want is to give the agent part of the network and ask it what it would do if it were an attacker.
Red team operations lead, global bank
YOUR NETWORKMCPsTOOLST1CPU 0.4%BROWSERT2CPU 11.8%BASHT3CPU 2.1%BASHT4CPU 0.9%BROWSERBACKEND
Four connected Cracken Tentacles, each running Linux next to its own target.
app.cracken.ai · tentacles — connected Tentacles on one realm
// Shared memory

Cybergraph.

Every host, service and finding a run touches is stored and typed. The next run starts from what you already know instead of scanning for it again.

// Traversalfirst_seen_at · last_seen_at · lifecycle · evidence → operation record
  1. Netblockipv4range
  2. CONTAINS
    IPAddressipv4address · internal
  3. CONTAINS
    Portport_number
  4. COMMUNICATIONprotocol · port · direction
    Servicebanner · port_number
Three edge types, and only three. The third is TECHNIC — MITRE ATT&CK references, Exploit → Vulnerability.mitre_id · tactic · technique_name
app.cracken.ai — realm cybergraph, table view
The realm Cybergraph in table view: every row a node typed url, evidence, finding, ipaddress or vulnerability, with its severity beside it.
// Integrations

It drives your tools. Your coding agent drives it.

One direction: the connectors for your stack, plus the offensive tooling it lacks. The other: Cracken is an MCP server, so Claude Code or Cursor can run operations from where you already work.

// After the thirty days

$189/moStarter

Included
175 credits/mo
Which buys
44–87 findings triaged, or up to 3 web app tests
See every plan →

Start your first run.

Thirty days, no card. Credits are extra. If it has to clear security review first, we walk your team through it.