Now Accepting Subscriptions — No Sales Call Required

Penetration Testing,
Fully Automated.

Cairn is Trailhead Security's agentic security testing engine. Multiple best-of-breed OSS tools, AI-normalized findings, and human+AI review on Premium — assessed, triaged, and reported at a pace the industry has never seen.

Cairn Engine · Built by Brendon McCaulley, CISSP · Subscriptions from $299/mo

cairn api — launch an engagement
# Initiate an agentic web application assessment POST https://api.trailheadsecurity.com/v1/engagements Authorization: Bearer <your-api-key> { "target": "https://app.target.com", "scan_type": "web_full", "auth_roles": ["admin", "member", "anonymous"], "modules": ["xss", "sqli", "idor", "auth_bypass", "api_fuzzing"], "ai_triage": true, "report_format": "pdf" } # Cairn handles discovery, exploitation, triage, and reporting. # Results available at /v1/engagements/{id}/findings

Full-Spectrum Attack Surface Coverage

Cairn's agentic engine autonomously discovers, exploits, and documents vulnerabilities across every layer of your environment — with AI-driven triage, not just raw scanner output.

Web Application & API

Authenticated crawling across all defined user roles. Automatic Swagger/OpenAPI discovery, HTTP method enumeration, cross-role IDOR substitution, BOLA/BFLA detection, XSS, SQLi, CSRF, and path traversal. tRPC and GraphQL introspection included.

OWASP Top 10 IDOR Auth Bypass GraphQL tRPC

Active Directory

ACL/DACL enumeration, ADCS abuse path discovery, cross-forest trust analysis, GPO misconfiguration review, LAPS assessment, and BloodHound-comparable attack path mapping — fully automated against your AD environment.

ADCS Kerberoasting GPO Abuse Trust Attacks

Cloud Infrastructure

IAM privilege escalation path discovery, public exposure analysis, and misconfiguration detection across AWS, Azure, and GCP. SaaS coverage includes M365, Google Workspace, GitHub, and Okta. Benchmarked against CloudGoat and AzureGoat.

AWS Azure GCP M365 IAM

AI Triage & Reporting

LLM-powered finding analysis eliminates false positives, contextualizes severity, and generates remediation guidance — automatically. Every engagement produces a compliance-ready PDF with executive summary, CVSS scoring, and evidence chains via the Basecamp client portal.

PCI-DSS SOC 2 HIPAA CVSS

From API Call to Report

Cairn handles the full engagement lifecycle. You define the scope — the engine handles the rest.

01

Define Scope

Submit your target, auth credentials, role definitions, and enabled modules via the API. Cairn validates scope and queues the engagement.

02

Autonomous Assessment

Cairn runs discovery, enumeration, exploitation attempts, and cross-role testing. AI triage runs continuously — findings are classified and prioritized in real time.

03

Report & Portal

A compliance-ready PDF report and a live findings portal are generated automatically. Clients access findings via a secure, tokenized portal link.

Built for Security Teams Who Move Fast

Cairn plugs into your existing security workflow — no lengthy scoping calls, no waiting weeks for a report.

Security Engineering

Integrate Cairn into your CI/CD pipeline via API keys. Trigger assessments on every major release. Get findings in your existing workflow.

Red Teams & Pentesters

Use Cairn's autonomous engine to handle breadth scanning while your team focuses on depth. Multi-target orchestration built in.

Compliance & GRC

PCI-DSS Req 11.4, SOC 2 CC7, HIPAA risk assessments. Reports formatted for your auditor, generated at the pace compliance requires.

Typical engagement scope: single web app to full enterprise environment · Reports in 24–72 hours

What Sets Cairn Apart

AI

Not Just Wrappers

Cairn orchestrates ZAP, Nuclei, Nikto, testssl.sh, ffuf, and its own engine in parallel. The agentic layer reasons across all findings — not just one scanner's output.

N

Multi-Role Testing

Define multiple auth roles. Cairn tests every endpoint as every role — catching IDOR, privilege escalation, and tenant isolation failures automatically.

0

False Positive Noise

All tool findings pass through an LLM normalization layer before they reach you — semantic dedup, triage scoring, false positive suppression. Every tier.

H

Human+AI Review Team

Premium adds Brendon McCaulley, CISSP + a purpose-built team of Claude-powered AI agents — interactive crawling, pattern correlation, human judgment where it counts.

M

Mythos-Ready

Cairn's AI layer is model-agnostic by design. When Anthropic Mythos — the most capable vulnerability-discovery AI ever built — reaches general availability, Cairn will be first in line.

Architected for Mythos
The Cairn Delivery Model

Best-of-All Tools.
AI-Normalized. Continuously Learning.

Cairn doesn't run a single scanner. Every engagement deploys multiple industry-standard OSS tools in parallel, aggregates findings through an AI normalization layer, and — at the Premium tier — routes through a human+AI review team whose discoveries feed Cairn's growing detection corpus.

01

Best-of-All-Tools Scan

ZAP, Nuclei, Nikto, testssl.sh, ffuf, SQLmap, and Cairn's own engine run in parallel. No single-scanner blind spot. Every tool contributes its findings to a shared pool.

All Tiers
02

AI Normalization

All raw findings pass through an LLM layer: semantic dedup, false positive suppression, CVSS triage scoring. You get clean, ranked, actionable output — not a wall of noise.

All Tiers
03

Human+AI Review Team

Brendon McCaulley, CISSP, and a purpose-built team of Claude-powered AI agents review findings together — crawling the attack surface interactively, correlating patterns, validating findings a scanner can't reason about.

Premium Only
04

Cairn Learns

Attack methods surfaced by the human+AI review team feed back into Cairn's detection corpus. The engine that runs next month is sharper — because this month's engagement made it so.

Premium-Driven
🔒

Your data stays yours. Only attack methods are extracted from Premium review sessions — never target data, finding details, or client identity. The loop advances Cairn's intelligence, not a data warehouse.

Become a Premium Client Full Technical Details
AI Models
Claude (Anthropic) Mythos-Ready
OSS Scanners
OWASP ZAP Nuclei Nikto testssl.sh ffuf SQLmap Nmap
Output
AI-normalized CVSS-scored Compliance-mapped

Pricing That Doesn't Require a Sales Call

Traditional pentests run $10,000–$30,000 per engagement, take weeks to schedule, and give you one shot at a report. Cairn subscriptions start at $299/month — unlimited rescans, no per-scan fees.
All plans are subscriptions. Annual billing available via invoice (Net 30) — saves ~3 months.

Starter
$299
per month · 1 root domain
or $2,500/yr — save ~3 months (billed annually via invoice, Net 30)

  • 1 root domain
  • Full autonomous assessment
  • AI triage — zero scanner noise
  • Unlimited rescans
  • PDF report via API
  • Full API access
  • Quarterly findings report
  • Client portal
  • Signed attestation
Get Started
Premium
$3,499
per month · unlimited root domains
or $30,000/yr — save ~3 months (billed annually via invoice, Net 30)

  • Unlimited root domains
  • Everything in Pro
  • Monthly review by Brendon McCaulley, CISSP + AI agent team
  • Interactive attack surface crawl each session
  • 1hr monthly findings call
  • Basecamp client portal (auto-provisioned)
  • DocuSeal signed attestation on every report
  • Compliance-ready: SOC 2, PCI-DSS, HIPAA
  • Custom SLA available
  • Your engagement trains Cairn's detection intelligence
Get Started

All plans are monthly subscriptions. Annual billing via invoice, Net 30 — saves ~3 months.  Questions? Talk to us.

Ready to Run Your First Engagement?

Start with Starter at $299/mo, or talk to us about Pro and Premium subscriptions for your team.

Get in Touch
Brendon McCaulley
Founder & CISSP · Trailhead Security