Shellvoide

Product · KLUE

Meet KLUE, your AI security engineer.

One agent that runs continuous pentests across your apps, cloud, code, APIs and CI/CD, and delivers a working proof for every finding. In hours, not days.

KLUE
Overview
Autonomous VAPT
Autonomous Pentest
Vulnerability Assessment
Application Security
Static Analysis
Cloud & Compliance
Cloud Audit
M365 Assessment
Signals & Intelligence
Threat Intelligence
Settings
D
Demo UserUser
Overview
Total
Assessments
6
⚡ 0 active right now
Open
Findings
43
Critical · High · Medium combined
Critical
Open
10
Address immediately
Avg. Scan
Duration
20m
Across completed scans
klue · session
$ klue status
[✓] Welcome back, Demo User
[+] Platform status: ONLINE
[+] Active modules: 6/6
[+] Last assessment: 1mo ago · Autonomous Pentest (www.valecta.nl)
$
Finding Severity Breakdown50 TOTAL
Critical
10
High
23
Medium
10
Low
7
Info
0
Security Posture
F
Critical Risk
10 critical findings open. Targeted remediation required.
Total Scans
6
Critical
10
Targets
6
Open
43

The problem

Most tools look for what they already know.

A rule, a signature, a playbook someone wrote years ago. Every scanner shares that engine: it catches what its rules describe, and everything else slips past. There is no signature for a bug your team wrote yesterday, or for two safe steps run in the wrong order. Those are judgments about intent. KLUE reasons about the target instead.

One platform

Six assessments. One graph of findings.

Same reasoning engine, same isolated runtime, same report format. Pick what to test and the agent does the rest.

Autonomous Pentest

Vulnerability discovery, exploitation and chained attack paths, attacker-style.

Vulnerability Assessment

Runtime discovery against live web and API targets.

Static Analysis

Source review for code flaws, hardcoded secrets and dependency risk.

Cloud Audit

AWS, Azure and GCP posture against CIS, SOC 2, ISO 27001 and PCI.

M365 Assessment

Microsoft 365 posture, identity configuration and compliance state.

Threat Intelligence

Unified search across CVE, ATT&CK, malware and credential-leak sources.

Measured, not claimed

We ran the benchmark. KLUE sat above the curve.

Rule-based tools trade coverage against noise. A reasoning engine is not bound by that curve, and it runs fast enough to fit your release cadence.

RECALLPRECISION02550751000255075100
0%

Precision

Zero false alarms on the public code-review benchmark.

0.5%

Recall

Above the ceiling rule-based tools reach in practice.

0+

CVE-level flaws

Responsibly disclosed in popular open-source software.

~30 min

Per run

Fast enough to run after every release, not once a quarter.

The cadence

Thirty minutes. Not four hours. Not weeks.

How much you catch is half the story. How long it takes is the other half. Most AI testing tools take four to six hours a run, so you can only afford to test once a quarter. A thirty-minute run fits into every release.

ToolRecallDurationSoft positive rate
KLUEReasoning agent, thirty-minute budget82%~30 min~4%
Leading commercial agentCombines several AI models75.0%4 hr6.3%
Raw frontier modelA top model on its own70.0%10 min6.7%
Open-source agent ASame underlying AI model45.0%4 hr10.0%
Open-source agent BSame underlying AI model30.0%6 hr25.0%
Open-source agent CSame underlying AI model5.0%2 hr0.0%

Public benchmark against a well-known target with twenty-two documented vulnerabilities. KLUE figures come from real runs under a thirty-minute budget. Other figures come from publicly reported results.

One

It is how the agent is built, not the AI behind it.

Three tools on the public board use the same underlying AI model and catch 45%, 30%, and 5% of bugs. That gap comes down to how each one is built. KLUE is the difference.

Two

Model choice becomes a cost decision.

On a separate benchmark, KLUE on a cheaper open model matched a top-tier paid model on the most critical bugs, at one-fifth the cost.

Three

Speed is what unlocks it.

Four-hour tests force you to a quarterly schedule. Thirty-minute tests run after every release. That is the bar serious autonomous tools will be measured against.

The landscape

Three categories. The category decides the ceiling.

Every product in this space falls into one of three groups, set by what its engine actually does: matches known patterns, replays known attacks, or reasons about the target. The group sets the cap.

CapabilityKLUEVulnerability scannersBreach simulatorsOther AI agentsHuman pentesters
Engine
Underlying modelReasoningRulesSimulated playbooksMixed agentsHuman reasoning
Discovers unknown vulnerabilitiesPartial
Writes custom exploit codePer targetPresetPreset
Chains findings into attack pathsMulti-stepLimitedSomeManual
Delivery
Time per engagement~30 min to 6 hrAlways-on scanHoursHours2 to 6 weeks
OutputPDF, data export, working proofCSV, dashboardDashboardDashboard, PDFPDF (weeks later)
Free retest after fixNot applicableRe-runRe-runExtra cost
Operations
Runs on every releaseKnown-flaw scan onlyScheduledScheduledImpossible
Parallel scansUnlimitedUnlimited, shallowScheduledScheduledOne per team
Vendor modelProprietary, exclusiveLicensed softwareLicensed softwareLicensed softwareConsulting hours

Most tools answer “what known weakness might you have?” KLUE answers “what would an attacker actually do here?” The category decides which question can be asked.

Track record

Real engagements. Not pitch decks.

Real targets, real attack paths, every step confirmed with a working proof. Nothing reported on suspicion alone.

No access

Full database read

Public sector portal

A blind SQL injection flaw chained up to full admin rights.

11 findings·61 min
Full breakdown
Coordinated with NCERT

Account takeover, no password

Government agency

Any official reached by username. No code, no password required.

7 findings·37 min·CVSS 9.8

Pricing

Plans from $150 per month. Services quoted to fit.

Self-serve KLUE subscriptions for continuous testing, or a scoped quote for pentest, red team and managed security.

Review pricing

Get started

See what an hour findsagainst your own systems.

One hour. Real exploits. Real fixes. No procurement cycle, no consulting engagement. You keep the findings either way.