Blog
AI penetration testing models
A cyber-specialized model for AI penetration testing that runs inside your environment. Build your security product on a model trained for the work, not a general-purpose API.
If you are looking for a product that runs penetration tests, you want an application built on a model like this one. If you are building that application, or deciding what to build it on, this page is for you.
Submersion makes the model, not the testing product around it. Basin is a cyber-specialized model that finds and validates vulnerabilities. Your team supplies the harness, the tooling, and the controls, and integrates Basin as the model layer. That separation is deliberate, because the durable advantage in AI penetration testing is the model, and the model is what most teams do not want to build themselves.
Why a specialized model instead of a general API
Most AI penetration testing today runs on a general-purpose frontier API. That works until it does not. The provider restricts categories of security work under its usage policy, so the model refuses the offensive analysis the task requires. The economics get expensive at the volume real testing needs. And the API sits outside the environment you are testing, so systems, credentials, and findings leave the boundary.
A model trained specifically for security work behaves differently. It finds and validates vulnerabilities a general model misses, it does the offensive analysis without refusing, and it costs less per task. The capability comes from how the model is trained and evaluated, not from a security prompt wrapped around a general model.
Runs where the testing happens
Basin runs inside your environment, on-premises, in a private cloud, or air-gapped, on your own hardware. For a product sold into regulated or sovereignty-constrained customers, that matters as much as the capability, because those customers cannot send their systems to a hosted API. The work and the findings stay inside the boundary.
How the model is built and proven
Basin is trained and evaluated against real offensive environments. Its capability is proven in the open. The model discovers real vulnerabilities in widely used software, and after each is patched, it rediscovers the same vulnerability with no prior knowledge of it. That blind rediscovery is our evidence that the capability is learned rather than memorized. The disclosed findings, including the model's discovery trajectory for each, are in our advisories, and how we evaluate the model is on our methodology page.
Build on it
Bring the model you use today and a workload your product has to perform, and we will benchmark Basin against it inside an environment that matches your customers' deployment constraints. Request an evaluation.