Introducing Novee Pipeline: The Full AI Pentest, Embedded in the Dev Workflow

Recent sandbox escapes and unauthorized lateral movement during security testing, from the likes of OpenAI and Anthropic, prove that offensive AI needs robust guardrails.

Netta Rager Dan, VP Product

4 mins

AI that delivers personalized fixes
Explore Article +

Empower your developers to continuously pressure-test the code they ship – any delta change on runtime – right inside CI/CD.

Entire features are now vibe-coded into existence in an afternoon and pushed toward production before anyone has read every line. Bolting a scanner into CI helps, but pattern-matching against known signatures only defends against known vulnerabilities, and the business-logic flaws that cause real breaches don’t have signatures.

That’s why we’re introducing Novee Pipeline, and delivering the full depth of a Novee pentest into the pipeline itself. Every meaningful delta change gets tested continuously – on runtime, the way an attacker would test it. This means threats are mitigated before they ever reach production.


The Gap Between Commit and Production

Most teams end up choosing between two bad options: gate releases on manual pentests, which provide depth, but on a quarterly cadence that development blows past in a week; or bolt a scanner into CI, which runs continuously but floods the pipeline with low-signal findings while missing the logic flaws that matter.

Neither keeps pace. Which means most changes reach production without ever being tested the way an attacker would.


Pentesting That Fires on Code Changes

Novee Pipeline is delivered as the Novee CLI: a single binary, or a one-line Docker image for pipelines. Novee CLI talks directly to the Novee API. Drop it into GitHub Actions, GitLab CI, or any Docker-capable runner with a scoped, least-privilege service-account key. There’s nothing to install and nothing new to stand up.

  • Scoped to what changed. A delta assessment takes two commit SHAs or git tags and exercises only the affected endpoints, workflows, and trust boundaries, instead of re-scanning the entire portfolio on every push.
  • A gate, not just a report. Distinct exit codes let a CI job fail the build on a real finding, fail fast on a bad key, and continue on clean.
  • Every finding is proven. Results come validated and reproduced with exploitability confirmed (not a signature match and a CVSS score) with enough context to fix the issue fast.
  • Drops into the pipelines you already run. GitHub Actions, GitLab CI, or any Docker-capable executor. The service account is a scoped, least-privilege credential built for automation, meaning no personal keys, nothing baked into an image layer.
  • Catches vibe-coded apps before production. AI-generated code ships fast and almost never arrives with a threat model. Novee continuously tests the application that code produces – business logic and all – while it’s still in the pipeline instead of after an incident.

The effect is the best hacker and the best defender working at the speed your code ships, so meaningful changes get tested the way an attacker would test them: before they reach production.

See how it works:

Reducing the TTE Window is Table Stakes

Giving developers access to a full Novee pentest significantly reduces the critical window between identifying an exposure and neutralizing the risk – because the risk never enters production in the first place. We believe it’s this level of mitigation that earned Novee a spot in Gartner’s Emerging Tech category for the next frontier of exposure management.


“HiBob runs an MCP server for the product, and that surface continues to grow as more tools are introduced. Novee continuously scans it through its CI/CD and CLI capabilities, so new tools and agentic endpoints are tested as they are deployed.”

— Tamir Ronen, Global CISO, HiBob


Closing the Loop By Shifting Pentest to the Pipeline

Testing that runs once a quarter leaves a gap. Testing that runs continuously without the ability to reason just fills that gap with noise. That’s the opening AI-driven adversaries are built for.

Novee Pipeline closes it by moving the full depth of a Novee pentest into the pipeline itself. Every finding comes validated and reproduced with exploitability confirmed, not just flagged, and with enough context to fix it fast, not a signature match and a CVSS score. 

Novee Pipeline is available now. Book a demo and watch Novee take a single change from commit to validated fix.

Stay updated

Get the latest insights on AI, cybersecurity, and continuous pentesting delivered to your inbox