Ido Geffen on Why Novee Owns the Full AI Pentesting Stack
Ido Geffen outlines Novee’s innovative approach to AI-driven penetration testing, emphasizing the company’s development of a fully integrated proprietary stack that sets it apart from traditional “AI security” solutions.
Novee’s Approach to AI-Driven Penetration Testing
Traditional “AI security” solutions often rely on generic large language models (LLMs) with minimal customization, applying standardized scanning processes. Novee’s strategy diverges by building a comprehensive system that includes a dedicated offensive reasoning model, a coordination framework for specialized agents, and a training environment where these agents are continuously evaluated, refined with real-world attacker methodologies, and transitioned into active use.
The Proprietary Stack: A Comprehensive System
Geffen outlines the significance of controlling each layer of this architecture. The proprietary model enables superior performance in live browser exploitation compared to widely available LLMs. The platform’s iterative improvements ensure measurable progress for users with each cycle, while the absence of token-based pricing models maintains cost efficiency. Additionally, the system rapidly incorporates emerging attack techniques into agent capabilities as soon as they are identified by Novee’s research team.
The Asset Intelligence Model: Tailoring Threat Simulation
A critical component of Novee’s framework is the Asset Intelligence Model, which creates a dynamic understanding of a customer’s infrastructure, workflows, permissions, application programming interfaces (APIs), and business logic. This integration transforms a generic AI adversary into a tailored threat simulator, capable of reasoning about specific organizational contexts.
Strategic Value of Vertical Integration
Geffen highlights the resulting advantages for clients: increasingly precise findings, remediation strategies aligned with their unique environments, and a platform that evolves alongside advancing attacker capabilities. The discussion underscores the strategic value of vertical integration in AI security. By maintaining control over both the foundational models and environment-specific adaptations, Novee positions itself to deliver sustained competitive advantages in detecting and mitigating vulnerabilities.
Broader Implications for Cybersecurity
This approach addresses limitations of fragmented solutions, where reliance on external technologies restricts customization and responsiveness to evolving threats. The conversation also touches on broader implications for the cybersecurity industry, suggesting that proprietary stacks may become essential for organizations seeking to counteract the growing sophistication of automated attack vectors.
Technical Details and Platform Architecture
Technical details include the use of specialized agents trained through simulated attack scenarios, the integration of observed attacker behaviors into agent training data, and the emphasis on reducing false positives through environment-specific analysis. The platform’s architecture is designed to minimize latency while maximizing the accuracy of vulnerability assessments, particularly in complex, dynamic digital ecosystems.
Conclusion: The Future of Adaptive Security
Geffen concludes by emphasizing that the combination of a self-owned AI model and environment-specific intelligence creates a feedback loop where both the platform and its users benefit from ongoing advancements in offensive tactics. This dual-layered strategy not only enhances detection rates but also ensures that security measures remain aligned with the rapidly changing threat landscape.
According to Ido Geffen, Novee’s focus on vertical integration and environment-specific adaptations positions the company to address the evolving challenges of AI-driven cybersecurity.
