BreachLock vs Lory: Unified PTaaS Platform vs a Human-Signed AI Pentester | Lorikeet Security Skip to main content
Back to Blog
Vendor Comparison

BreachLock vs Lory: Unified PTaaS Platform vs a Human-Signed AI Pentester

Lorikeet Security · September 7, 2026 · 9 min read
Disclosure: This is written by Lorikeet Security. The BreachLock column reflects BreachLock's public platform, penetration testing, and compliance reporting pages as of this writing. Anything not stated publicly is marked not published rather than guessed at.

The One-Line Difference

BreachLock is a Unified Platform that claims one of the broadest self-described coverage footprints in PTaaS - web, API, network, cloud, mobile, IoT, and AI/LLM assets - pairing AI-assisted automation with human testers.

Lory is an AI pentester where a named Lorikeet Security pentester reads the evidence and signs every finding, with an enforced scope gate and a coverage record showing what was and wasn't tested.

Both share a similar philosophy - AI for speed and scale, humans in the loop somewhere - which makes this the closest comparison on this list in overall positioning. The differences are in specifics: how strong the human-review guarantee is, and how the coverage claim is backed up.


At a Glance

DimensionBreachLockLory by Lorikeet
ModelUnified PTaaS platform, AI-assisted automation plus human testersOn-demand or repeating AI pentester engagements
Human review guarantee"AI-assisted automation with human testers"; a universal per-finding sign-off isn't specifically publishedA named pentester countersigns every finding, no exceptions
Compliance framework mappingPCI DSS, SOC 2, ISO 27001, HIPAA, NIST, CREST, OSSTMM, OWASPCWE plus control mapping across 7 frameworks
RetestingUnlimited on-demand retesting included in the base engagementOn demand against your existing credit balance, closed by a human
Coverage recordNot publishedVectors planned, run, and never reached, with the reason attached
Scope enforcementNot published as an architectural controlEvery tool call checked against a signed allowlist before it fires
Machine-readable outputNot publishedSARIF 2.1.0, GitHub code scanning, MCP
PricingQuote-based; one source cites a starting figure around $2,500 for smaller engagementsPrepaid credits, itemised quote within 24 hours

Coverage, Side by Side

Asset TypeBreachLockLory
Web appYesYes
APIYesYes, crawl, auth testing, injection, access control
NetworkYesYes, external directly and internal via the mesh connector
CloudYesYes, AWS, Azure, GCP, Kubernetes, containers, serverless
MobileYesYes, iOS and Android plus their backends
IoTYesNot offered as a dedicated engagement type
AI / LLM assetsYesNot offered as a dedicated engagement type
Source code reviewPoint-in-time code review is mentioned; depth not fully publishedYes, secret hunting, sink tracing, supply chain

On paper, BreachLock claims the broadest asset list of anyone in this series, including IoT and AI/LLM targets that Lory doesn't offer as dedicated engagement types today. Whether that breadth is uniformly deep across every asset type isn't something BreachLock has published in detail - worth asking about directly if IoT or LLM testing is your priority.


Where BreachLock Differentiates


Where Lory Differentiates

Honest Weak Spots for Lory BreachLock's published asset list is broader - IoT and AI/LLM testing aren't things Lory offers as dedicated engagement types today. Its named compliance-framework list (PCI DSS, NIST, CREST, OSSTMM specifically called out) is longer than what we've published. And unlimited retesting bundled into the base engagement, stated plainly, is a clean, easy-to-compare term that puts the burden on us to be equally clear about our own retest policy.

Picking Between Them

BreachLock may fit if...
  • You need IoT or AI/LLM asset testing specifically
  • You want the widest possible named list of compliance frameworks mapped to your report
  • Unlimited retesting bundled into the base price matters to your budgeting
Lory may fit if...
  • You want a specific, contractual guarantee that a named human signs every finding
  • You want scope enforced as a technical gate, not just a documented rule
  • You want a written record of what wasn't tested, not just what was
  • You want findings that land in SARIF/GitHub/MCP, not just a report

Both companies are building toward the same idea - AI for speed, humans for judgment. The honest way to choose is to ask each vendor directly how strong their human-review guarantee actually is, and get it in writing.

See a Signed Engagement in Action

Book a scoping call and we'll show you exactly what "a named pentester signs every finding" means in practice - and how our coverage record shows what wasn't tested, not just what was.

Book a Consultation
-- views
Link copied!
Lorikeet Security

Lorikeet Security Team

Penetration Testing & Cybersecurity Consulting

Lorikeet Security helps modern engineering teams ship safer software. Our work spans web applications, APIs, cloud infrastructure, and AI-generated codebases — and everything we publish here comes from patterns we see in real client engagements.