Clear your external findings backlog
Novee Exploitability ValidationClear your external findings backlog
Novee Exploitability ValidationProject Perception brings coordinated AI agents and Microsoft-scale visibility to defending the estate you already operate. But defending what you know and proving what an attacker can exploit are two different jobs. Novee starts where the attacker starts — a domain name, zero access — finds the exploitable risk in your application logic, proves it with a working exploit, and closes the loop with a stack-specific fix that’s automatically retested.
Project Perception compresses threat intelligence with contextualized signals from identity, cloud and code. But it’s built for finding common class of vulns horizontally, and with a focus on high-risk codebases
It defends the estate you already know.
Its focus is vulnerability analysis, not application business logic.
The loop runs at the pace of human approval.
Findings arrive as evidence, not proof.
Value and cost are tied to the ecosystem.
Novee approaches the same problem from the opposite end — the attacker’s.
Black-box from a domain name.
Novel vulnerabilities and application business-logic depth.
Zero false positives by design.
Every finding proven exploitable.
Fully autonomous, closed-loop remediation.
Flat, predictable per-asset pricing.
| Capability | Novee AI Pentesting | Microsoft Project Perception |
|---|---|---|
| Where testing starts | Black-box from a domain name. No credentials, no source, no internal access — the same starting point as a real attacker. |
Starts from full internal estate context inside Microsoft Defender, using the estate’s own identity, policy, and asset data. |
| Application business-logic exploitation | Core strength. Finds BOLA, broken authorization, and chained attack paths — the logic flaws that lead to real breaches. |
Focused on software-vulnerability analysis and posture hardening; application business-logic exploitation isn’t demonstrated in the public preview. |
| Validation & false positives | Zero false positives by design. Three independent agents — exploit, blind re-exploit, independent validate — with deterministic checks; if any stage fails, the finding is never reported. |
Blue agents investigate, rank risk, and assemble evidence, with human sign-off required on fixes. |
| Proof of exploitability | Working exploit + PoC. Every critical finding ships with a proof-of-concept and replication steps that prove it’s exploitable before it reaches your team. |
Delivers investigation, ranking, and supporting evidence; a working-exploit and PoC package isn’t part of the published preview. |
| Autonomy & remediation loop | Fully autonomous, closed-loop. Stack-specific fixes routed to your tools and automatically retested per finding to confirm the fix held. |
Green agents propose fixes as GitHub pull requests; autonomous remediation was held back from the preview, and per-finding auto-retest isn’t confirmed. |
| Pricing | Flat, predictable per-asset. Coverage tied to the complexity of your environment, not the number of runs or findings. |
Consumption-based, metered in Security Compute Units; heavier agent tasks draw more units, so breadth becomes a usage line. |
| Proprietary AI model | Purpose-trained offensive system. A proprietary offensive reasoning model combined with best-fit frontier models, each agent running the best model for its task. |
MAI-Cyber-1-Flash, Microsoft’s first purpose-built cyber model, trained on its own exploit and remediation data. |
| Estate breadth & ecosystem | Focused offensive coverage across web, API, mobile, and AI applications, with CI/CD, Jira, and GitHub integration. |
Whole-estate defensive breadth — endpoints, identities, cloud, apps, data, and AI — with deep native integration across Defender, Agent 365, Security Copilot, and GitHub. |