Clear your external findings backlog

Novee Exploitability Validation

Clear your external findings backlog

Novee Exploitability Validation

Novee vs. Microsoft Project Perception

Project Perception delivers whitebox security testing. Novee starts from just a domain and proves what a real attacker can actually reach, and closes the loop with a verified fix.

Project Perception brings coordinated AI agents and Microsoft-scale visibility to defending the estate you already operate. But defending what you know and proving what an attacker can exploit are two different jobs. Novee starts where the attacker starts — a domain name, zero access — finds the exploitable risk in your application logic, proves it with a working exploit, and closes the loop with a stack-specific fix that’s automatically retested.

See what's actually exploitable in your environment — before an attacker does. Book a Demo.

Thank you!

We’ll be in touch as soon as we can.

Chosen by teams that take attackers seriously

Novee vs. Microsoft Project Perception at a glance

Challenges with Microsoft Project Perception

Project Perception compresses threat intelligence with contextualized signals from identity, cloud and code. But it’s built for finding common class of vulns horizontally, and with a focus on high-risk codebases

Challenges with Microsoft Project Perception

  • It defends the estate you already know.

    Perception runs inside Microsoft Defender and starts from full internal context — the estate's own identity, policy, and asset data. That's the opposite of a real attacker's external, black-box view, so it hardens what you already see rather than surfacing what you don't.
  • Its focus is vulnerability analysis, not application business logic.

    Perception is built around software-vulnerability analysis and posture hardening. The business-logic flaws, broken authorization, and chained attack paths that actually cause breaches aren't what it has demonstrated finding in its public preview.
  • The loop runs at the pace of human approval.

    Consequential actions require human sign-off, and autonomous remediation was held back from the public preview. That keeps a human in the loop by design — but it means the find-triage-fix cycle moves at review speed, not machine speed.
  • Findings arrive as evidence, not proof.

    Perception's agents investigate, rank risk, and assemble supporting evidence. That stops short of a working exploit and proof-of-concept that proves a finding is exploitable before it reaches your team.
  • Value and cost are tied to the ecosystem.

    Perception's value depends on running inside Microsoft Defender, and it's metered in consumption-based Security Compute Units. Heavier agent tasks draw more units, so the breadth of your testing becomes a usage line rather than fixed coverage.

Why Novee Over Microsoft Project Perception?

Novee approaches the same problem from the opposite end — the attacker’s.

  • Black-box from a domain name.

    No credentials, no source code, no internal access, and no ecosystem to plug into. Novee starts exactly where a real attacker starts and delivers value in days.
  • Novel vulnerabilities and application business-logic depth.

    Novee finds BOLA, authorization gaps, and chained attack paths — the exploitable logic flaws that vulnerability analysis structurally misses.
  • Zero false positives by design.

    Three independent validation agents, deterministic where possible. If any stage fails, the finding is never reported, so what reaches your team is real.
  • Every finding proven exploitable.

    Each critical finding ships with a working exploit, a proof-of-concept, and replication steps — exploitability demonstrated, not just ranked.
  • Fully autonomous, closed-loop remediation.

    Stack-specific fixes tailored to your WAF, backend, and codebase, routed to your tools and automatically retested per finding to confirm the fix held.
  • Flat, predictable per-asset pricing.

    Coverage tied to the complexity of your environment, not the number of runs — so continuous, deep testing stays economically viable across the whole portfolio.

Novee vs. Microsoft Project Perception Across Key Areas

Capability Novee AI Pentesting Microsoft Project Perception
Where testing starts

Starts from full internal estate context inside Microsoft Defender, using the estate’s own identity, policy, and asset data.

Application business-logic exploitation

Focused on software-vulnerability analysis and posture hardening; application business-logic exploitation isn’t demonstrated in the public preview.

Validation & false positives

Blue agents investigate, rank risk, and assemble evidence, with human sign-off required on fixes.

Proof of exploitability

Delivers investigation, ranking, and supporting evidence; a working-exploit and PoC package isn’t part of the published preview.

Autonomy & remediation loop

Green agents propose fixes as GitHub pull requests; autonomous remediation was held back from the preview, and per-finding auto-retest isn’t confirmed.

Pricing

Consumption-based, metered in Security Compute Units; heavier agent tasks draw more units, so breadth becomes a usage line.

Proprietary AI model

MAI-Cyber-1-Flash, Microsoft’s first purpose-built cyber model, trained on its own exploit and remediation data.

Estate breadth & ecosystem

Whole-estate defensive breadth — endpoints, identities, cloud, apps, data, and AI — with deep native integration across Defender, Agent 365, Security Copilot, and GitHub.

What security leaders say

“As the leading agentic orchestration platform for the enterprise, data isolation between our customers is non-negotiable. We need to prove that continuously, not once a year. Novee adapted to our multi-tenant SaaS product within days.”

Scott Roberts
CISO
john

“Our pen tests took weeks and consistently missed critical issues. Novee found them immediately and gave us instant remediation guidance. It showed us what we'd been missing.”

John Barrow
CISO

"Traditional DAST produced either zero or irrelevant results. We needed something that could identify complex vulnerabilities like server-side request forgery. Novee consistently surfaces findings we simply weren't seeing before."

Robert Kugler
Head of Security, IT & Compliance

“Novee rethinks penetration testing for how attacks actually happen today. Continuous, attacker-level validation that proves what’s exploitable and shows teams exactly how to fix it is a meaningful shift for modern security programs.”

Troy Wilkinson
Former Fortune 500 CISO
tamir ronen

"The hardest vulnerabilities for us to catch aren’t misconfigurations or known patterns. They’re business logic issues that only show up when someone understands how the application is supposed to work. That’s exactly the gap Novee closes."

Tamir Ronen
CISO, HiBob

"We had EASM tools and manual pentests that produced mostly noise. Novee came in black-box with zero credentials and within days found dozens of real vulnerabilities we could actually fix."

Itzik Menashe
CISO, Global VP IT InfoSec & productivity

“As an AI researcher, what stood out about Novee is that they built a proprietary offensive AI model designed to think like an attacker, rather than wrapping generic LLMs. That matters for enterprise-grade results.”

Tal Shapira
PhD, CTO

“This was by far the deepest and fastest security assessment we’ve had. Novee uncovered issues across our web and mobile applications that had gone undetected before, and the level of depth was unlike anything we’d seen from other vendors.”

Amir Tito
CISO

“We had urgent compliance need and we couldn’t wait weeks for DAST findings, an external exposure audit, and an in-depth pentest report. Instead Novee came in and delivered immediate value with their AI pentesting platform; with their findings, we closed our gaps and quickly met the criteria we needed for certification.”

Ron Reiter
CTO

"Before Novee, we were getting a snapshot once a year. Now we have continuous coverage across our application portfolio, we're already finding things that prior manual pentests missed completely, and I have real confidence that our security posture reflects what's actually in our environment."

Abhijeet Patkar
Cyber Security Manager

The Novee Advantages

Both the AI hacker and the AI defender

Problem with Microsoft Project Perception:

Having coordinated AI agents native inside Defender and correlating signals across the whole estate, is a genuine advantage for teams standardized on Microsoft. But it's a defensive loop. It starts from full internal context and hardens the estate you already know about — it doesn't prove what a real attacker can reach from the outside, and it isn't built to exploit your application's business logic.

How Novee closes it:

Novee is both. The AI hacker starts black-box from a domain, reasons about your environment the way an attacker would, and uncovers the novel, exploitable risk that leads to breaches. The AI defender then closes the loop with a stack-specific fix and automatically retests it. You get external offensive proof and verified remediation in one system, not defense wrapped around what you already run.

Proof from the attacker's starting line, not from full internal context

Problem with Microsoft Project Perception:

Full context and human-in-the-loop control are legitimate design choices, and they make Perception safe to run inside the estate. But a system that sees everything and requires human sign-off for consequential actions is the opposite of an independent attacker testing you from the outside with no context. Its findings reflect what the estate knows about itself, gated by human approval — not what an adversary can actually reach.

How Novee closes it:

Novee reproduces the adversary's real starting position — a domain name, zero access — and runs continuously at machine speed. Every finding is validated to zero false positives by three independent agents before your team ever sees it, so what you act on is proven exploitable, discovered the way an attacker would discover it, at the pace attacks actually happen.

Independent of your stack, not tied to one ecosystem

Problem with Microsoft Project Perception:

Deep native integration across Defender, Agent 365, Security Copilot, and GitHub is a real strength for Microsoft-standardized teams. But it's also a dependency: Perception's value is tied to running inside Defender, and it's metered in Security Compute Units, so heavier testing draws more consumption. The breadth of your coverage becomes a usage decision rather than a fixed line.

How Novee closes it:

Novee delivers from a domain name, regardless of the stack you run, and prices flat per asset based on the complexity of your environment. Continuous, deep offensive testing stays predictable across your entire portfolio — coverage expands every cycle as the Asset Intelligence Model gets sharper, and the cost doesn't climb with it.