Cait vs Lory: Comparing Prescient Security's and Lorikeet Security's AI Pentesters | Lorikeet Security Skip to main content
Back to Blog
Vendor Comparison

Cait vs Lory: Comparing Prescient Security's and Lorikeet Security's AI Pentesters

Lorikeet Security · September 7, 2026 · 11 min read
Disclosure: This is written by Lorikeet Security. The Cait column sticks to what Prescient Security has published publicly - their May 2026 launch release, their Cait product page, and the July 2026 Help Net Security piece on the ASM expansion - rather than what we'd like it to say. Anything Prescient hasn't published is marked not published rather than guessed at. Re-check what's actually shipped before using this in a bake-off; Prescient's roadmap items were dated summer 2026.

The One-Line Difference

Cait is a continuous, always-on layer that keeps re-testing the same assets so coverage never goes stale between annual pentests.

Lory is a full engagement that runs on demand or on a repeating schedule, where a named human pentester signs every finding before it reaches you.

Both now give you recurring, unattended coverage. The difference that's left is what happens to a finding: Cait's model is that AI provides coverage while human testers work the hardest problems, and Lory's is that no finding reaches you at all until a person has read the evidence and signed it.


At a Glance

DimensionCait by PrescientLory by Lorikeet
ModelContinuous, recurring AI-assisted serviceOn-demand or repeating engagements, scoped per run
PlatformCacilian PTaaS platformPortal, terminal, or MCP
Time to startRecurring schedule, always onImmediately on request, or automatically when a scheduled run comes due
Recurring coverageAlways-on layer, re-tests the same assets after changesRepeating engagements on your cadence, queued and started automatically, each one signed
Out-of-scope handlingNot publishedHeld for human scope review, never run silently
Bring your own agentNot publishedMCP server, works with Claude Code, Cursor, or any MCP-aware agent
QuoteFixed-price subscription or one-time engagementItemised scoped quote within 24 hours
Pricing modelSubscription or per-engagement fixed bidPrepaid credits, no seats, no subscription
Human sign-offHuman testers focus on the hardest problemsA named pentester countersigns every finding, no exceptions
Evidence standardExploit-validated, audit-ready proofReproduced with request/response, screenshots, and the chain it unlocked
Coverage recordNot publishedVectors planned, run, and never reached, with the reason attached
Attack surface discoveryASM, announced summer 2026Not offered, you declare the scope
Asset typesWeb apps at GA, expansion beyond web announced for summer 2026Web app, API, mobile, network (internal and external), cloud, source code review
PhysicalNot offeredHuman-led, never run by Lory
RetestingContinuous re-testing after changes is the core of the modelOn demand against your existing credit balance, closed by a human
Machine-readable outputNot publishedSARIF 2.1.0, GitHub code scanning, MCP
Framework mappingSOC 2 and ISO called outCWE plus control mapping across 7 frameworks
Methodology structureExplores and understands the app before attacking104 written playbooks across 12 attack categories, one pass per vector

Coverage, Side by Side

This is the widest gap between the two products, and the easiest one to demonstrate.

Asset TypeCaitLory
Web appYes, the launch focusYes
APINot called out separatelyYes, crawl, auth testing, injection, access control
MobileNot publishedYes, iOS and Android plus their backends: storage, IPC, deep links, pinning
Network, externalNot publishedYes, services, versions, exposure
Network, internalNot publishedYes, internal ranges via the mesh connector
CloudNot publishedYes, AWS, Azure, GCP, Kubernetes, containers, serverless: IAM, metadata paths, privilege escalation
Source code reviewNot publishedYes, secret hunting and SAST-style sink tracing, plus supply chain
PhysicalNot offeredHuman-led, never run by Lory

Cait went GA web-app-focused, and Prescient announced in July 2026 that it would extend to more asset types over the summer. Check what has actually shipped before you put "web app only" in front of a prospect, because that claim has a short shelf life and getting it wrong in a bake-off is expensive. The safer framing is what you cover, not what they don't.


Worth Saying Plainly

Because a comparison that pretends otherwise isn't useful to anybody.


Where Lory Differentiates

Honest Weak Spots for Lory Cait says "continuous," Lory says "recurring" - functionally close now, but a buyer working from a compliance checklist may pattern-match on the word. There's no ASM: scope-as-a-gate is a security property, but unknown assets stay untested, and a buyer who doesn't know their own surface gets more from Cait's discovery loop. Human countersign is a throughput ceiling by design - it's the feature and the constraint, and at high volume it's the bottleneck a prospect will ask about. Prescient is also a known audit and security firm, and that carries weight in procurement independent of product quality.

Picking Between Them

Cait may fit if...
  • Your scope really is just web applications
  • You don't have a clear picture of your external attack surface and want discovery bundled in
  • Predictable subscription billing suits your finance team
  • An established audit-firm name carries weight in your procurement
Lory may fit if...
  • You have more than web apps to test - API, mobile, network, cloud, or source code
  • You need findings a named person stands behind
  • You want proof your engineers can reproduce in minutes, plus the chain it unlocked
  • You want a written record of what wasn't tested
  • You'd rather run a standing cadence off a credit balance than carry a subscription

They aren't mutually exclusive. A continuous layer and a signed engagement solve different problems, and some orgs will end up running both.

See a Signed Engagement in Action

Book a scoping call and we'll walk you through exactly what a Lory engagement looks like end to end - the playbooks, the evidence standard, and how a human pentester signs off before anything reaches your report.

Book a Consultation
-- views
Link copied!
Lorikeet Security

Lorikeet Security Team

Penetration Testing & Cybersecurity Consulting

Lorikeet Security helps modern engineering teams ship safer software. Our work spans web applications, APIs, cloud infrastructure, and AI-generated codebases — and everything we publish here comes from patterns we see in real client engagements.