Autonomous cyber operations. Proven, not guessed.

One harness for the whole engagement. Nothing is called proven until an independent check reproduces it.

One objective. A disposable sandbox. Evidence.

One objective in.
A report you can act on.

01

Set the goal

Describe the objective in a sentence and choose the scope. Only your approval can extend either.

02

Agents go to work

Short-lived agents run real commands in a disposable container or microVM, pivoting on what they find.

03

Proof, then a report

Candidates go to an independent validator, as many as the run’s validation budget allows. The report separates what it proved from what it could not, and what it never got to.

See the proof,
not the claim.

Nothing is confirmed until a separate validator reproduces it from its own evidence.

flow-1  ·  report.md
Assessment — staging web application
objective "Find exploitable access to the customer portal"
scope internal · app.example.test
Confirmed
SQL injection → authenticated session takeover
severity high
status confirmed — reproduced independently, 2 of 2
evidence ev_9f2ac71 · request, response, extracted session
Prompt injection → support assistant leaks ticket history
status confirmed — reproduced independently, 2 of 2
evidence ev_c41b8e0 · transcript, leaked records
Corroborated
Verbose error page discloses stack frames
status grounded, not yet independently confirmed
Held
privilege escalation not attempted — no human approval granted

Example output. Identifiers are illustrative.

Autonomy needs
a boundary.

Every action passes the same check. It can ask for less. It can never grant itself more.

The agent can’t widen it

Scope and budgets are set when you create the run, and only you can widen either. Credentials it finds are reused inside that boundary, never past it.

Nothing touches your host

Work happens in a disposable container or microVM with no host access, reaching only what the scope you chose allows. It is destroyed afterwards.

You approve the dangerous parts

Privilege escalation, lateral movement and anything destructive stay off until approved — one at a time, or up front if you choose automatic mode.

You choose what leaves

Every outside call is opt-in — a hosted model, a remote sandbox, OSINT and search lookups. Run it all yourself and the only traffic leaving is the assessment, to the target you authorized.

Request access.

OrcaCyber is in private testing. Tell us a little and we’ll be in touch.

Teams with a company email are reviewed first.

One email when your invite is ready. Nothing else.

You’re on the list.

We’ve saved .