The One-Line Difference
BreachLock is a Unified Platform that claims one of the broadest self-described coverage footprints in PTaaS - web, API, network, cloud, mobile, IoT, and AI/LLM assets - pairing AI-assisted automation with human testers.
Lory is an AI pentester where a named Lorikeet Security pentester reads the evidence and signs every finding, with an enforced scope gate and a coverage record showing what was and wasn't tested.
Both share a similar philosophy - AI for speed and scale, humans in the loop somewhere - which makes this the closest comparison on this list in overall positioning. The differences are in specifics: how strong the human-review guarantee is, and how the coverage claim is backed up.
At a Glance
| Dimension | BreachLock | Lory by Lorikeet |
|---|---|---|
| Model | Unified PTaaS platform, AI-assisted automation plus human testers | On-demand or repeating AI pentester engagements |
| Human review guarantee | "AI-assisted automation with human testers"; a universal per-finding sign-off isn't specifically published | A named pentester countersigns every finding, no exceptions |
| Compliance framework mapping | PCI DSS, SOC 2, ISO 27001, HIPAA, NIST, CREST, OSSTMM, OWASP | CWE plus control mapping across 7 frameworks |
| Retesting | Unlimited on-demand retesting included in the base engagement | On demand against your existing credit balance, closed by a human |
| Coverage record | Not published | Vectors planned, run, and never reached, with the reason attached |
| Scope enforcement | Not published as an architectural control | Every tool call checked against a signed allowlist before it fires |
| Machine-readable output | Not published | SARIF 2.1.0, GitHub code scanning, MCP |
| Pricing | Quote-based; one source cites a starting figure around $2,500 for smaller engagements | Prepaid credits, itemised quote within 24 hours |
Coverage, Side by Side
| Asset Type | BreachLock | Lory |
|---|---|---|
| Web app | Yes | Yes |
| API | Yes | Yes, crawl, auth testing, injection, access control |
| Network | Yes | Yes, external directly and internal via the mesh connector |
| Cloud | Yes | Yes, AWS, Azure, GCP, Kubernetes, containers, serverless |
| Mobile | Yes | Yes, iOS and Android plus their backends |
| IoT | Yes | Not offered as a dedicated engagement type |
| AI / LLM assets | Yes | Not offered as a dedicated engagement type |
| Source code review | Point-in-time code review is mentioned; depth not fully published | Yes, secret hunting, sink tracing, supply chain |
On paper, BreachLock claims the broadest asset list of anyone in this series, including IoT and AI/LLM targets that Lory doesn't offer as dedicated engagement types today. Whether that breadth is uniformly deep across every asset type isn't something BreachLock has published in detail - worth asking about directly if IoT or LLM testing is your priority.
Where BreachLock Differentiates
- The broadest published asset list in this comparison series. IoT and AI/LLM assets sit alongside the usual web, API, network, cloud, and mobile targets under one shared data model.
- Deep, named compliance framework coverage. PCI DSS, SOC 2, ISO 27001, HIPAA, NIST, CREST, and OSSTMM are all explicitly called out, which is a longer named list than most vendors in this space publish.
- Unlimited retesting included in the base engagement, not sold as a paid add-on - a genuinely fair, customer-friendly term.
- A similar AI-plus-human philosophy to Lory's, which means a buyer already sold on that model has a real, credible alternative to evaluate against.
Where Lory Differentiates
- A named human signs every finding, by contract, not just "human testers" somewhere in the process. BreachLock's language describes pairing automation with human testers; it does not publish a specific universal per-finding countersignature guarantee the way Lory does.
- Scope as an enforced technical gate, not just a documented rule of engagement - every tool call is checked against a signed allowlist before it fires.
- A coverage record showing which vectors were planned, run, and never reached, and why - something we haven't seen BreachLock publish an equivalent of.
- Findings leave the report. SARIF 2.1.0 and MCP mean findings land in GitHub code scanning and in your agents, not just a PDF.
- Scheduled, recurring engagements queued and started automatically on your cadence, off a prepaid credit balance.
Picking Between Them
- You need IoT or AI/LLM asset testing specifically
- You want the widest possible named list of compliance frameworks mapped to your report
- Unlimited retesting bundled into the base price matters to your budgeting
- You want a specific, contractual guarantee that a named human signs every finding
- You want scope enforced as a technical gate, not just a documented rule
- You want a written record of what wasn't tested, not just what was
- You want findings that land in SARIF/GitHub/MCP, not just a report
Both companies are building toward the same idea - AI for speed, humans for judgment. The honest way to choose is to ask each vendor directly how strong their human-review guarantee actually is, and get it in writing.
See a Signed Engagement in Action
Book a scoping call and we'll show you exactly what "a named pentester signs every finding" means in practice - and how our coverage record shows what wasn't tested, not just what was.
Book a Consultation