:novee-gym: Elite AI hackers aren’t born. They’re trained.

Step into the gym at Black Hat 2026.

:novee-gym: Elite AI hackers aren’t born. They’re trained.

Step into the gym at Black Hat 2026.

Growing the Novee Coverage Map: Continuous AI Pentesting for Mobile

The first AI pentesting platform for mobile apps. Novee tests your entire attack surface—web, API, and mobile—continuously, mapping every finding to OWASP.

Netta Rager Dan, VP Product

4 mins

Explore Article +

Introducing an industry-first: an AI penetration testing platform that covers the mobile attack surface, alongside web applications, API, desktop applications, and AI and LLM-enabled applications.

Your application is not just a website; it’s a mobile app your most engaged users log in from, APIs that expose far more than any UI shows, all of it being built faster than anyone can read every line.

Attackers treat all of that as one connected system. They chain a weakness in the mobile client into an API, and the API into your data, occasionally even bypassing the web front end.

The addition of mobile application testing makes Novee the industry’s first complete AI pentesting platform that delivers continuous, autonomous pentesting for mobile apps. That means Novee offensive AI agents test your entire application attack surface: web apps, mobile apps, and the dedicated API that underlies both. 

Attackers don’t stop at your web apps. Neither does Novee.

First in the Industry: Continuous AI Pentesting for Mobile

Mobile apps hold the logins, payments, and personal data attackers most want to reach. They’re also the least-tested part of most security programs. The market standard is a manual pentest, once a year, while the app ships every sprint. By the next release, the report is already out of date.

Novee closes that gap. Upload your app, and results land in hours, in the same dashboard as your web applications. The Novee agents go beyond a simple code scan to test your real app, running live, with two lenses at once:

  • It reverse-engineers the application package. Novee unpacks the app and traces how data moves through it, mapping every way in: deep links, shared components, in-app browsers, not just the obvious network calls.
  • It runs the app live. In a fully instrumented runtime environment, Novee self-operates, the agent watches real behavior, network traffic, and what the app stores on the device.

Because apps encrypt and pin their traffic, most tools stop at the screens. Novee sees through the encryption from inside the running app, so the backend APIs behind your mobile app become a fully testable attack surface. 

Every finding maps to OWASP MASVS, giving you a coverage matrix ready for compliance, board reporting, and customer due diligence. 

In three steps, users see detailed testing results in the same dashboard as their web applications: 

One Standard, Every Surface

Coverage only matters if it’s rigorous everywhere. Novee’s testing maps to OWASP standards across every layer it touches: WSTG for web, MASVS for mobile, and AITG for AI-enabled systems. Point Novee at any surface and get the same attacker-driven testing: reasoning about how your system actually works, not firing known payloads and matching signatures.

Coverage of these three asset types demonstrates comprehensive testing of the entire application attack surface:

  • Web Applications (maps to WSTG). Novee continuously builds understanding of every application’s workflows, permissions, APIs, business logic, and attack paths. That persistent context enables deeper reasoning and the discovery of business logic flaws, authorization gaps, and chained attack paths.
  • Mobile Applications (maps to MASTG). Upload an APK and Novee handles the rest. Offensive AI combines static analysis, runtime testing, and deep application context via the Asset Intelligence Model (AIM) to continuously uncover the vulnerabilities that lead to breaches.
  • API Backend Servers. Novee tests APIs, delivering full coverage for REST and GraphQL. Schema-aware analysis combined with runtime awareness maps every endpoint, including the ones omitted from documentation. Then Novee generates test cases tailored to each endpoint’s authentication requirements, exposure level, and role in the application.

Because Novee owns and continuously optimizes the entire offensive AI system, every surface benefits as the same system gets better.

Finding Real-World Critical Vulnerabilities in Mobile Apps

See what Novee can uncover in mobile applications. Our latest research into twenty Android Apps turned seven manual findings into 13 repetitions of the same exploitable bug. Read it here.

Mobile application testing is available now. Book a demo and watch Novee test every attack surface that matters, the way an attacker would.

Stay updated

Get the latest insights on AI, cybersecurity, and continuous pentesting delivered to your inbox