Inside the Lorikeet Security Platform: Lory AI and PTaaS: A Complete Product Guide | Lorikeet Security Skip to main content
Back to Blog

Inside the Lorikeet Security Platform: Lory AI and PTaaS: A Complete Product Guide

Lorikeet Security Team April 13, 2026 18 min read

TL;DR: Lorikeet Security provides two products that work together to give organizations complete security coverage. Lory AI is our autonomous AI pentester -she runs a five-stage engine (Discover, Probe, Chain, Report, Human Review) that plans and executes engagements the way a human tester would, chains weaknesses into real attack paths, and writes CVSS-scored findings straight into your portal, 24/7. Penetration Testing as a Service (PTaaS) delivers expert-led, 100% manual penetration testing through a modern portal with digital contract signing, real-time finding delivery, and compliance-ready reports. This guide walks through every feature of both products, shows the actual platform interfaces, and explains why modern organizations need continuous autonomous testing and deep human expertise working in tandem.

Most organizations discover they have a security problem in one of two ways: they get breached, or they hire someone to try. The first option is catastrophic. The second option -penetration testing -has been the gold standard for decades, but the way it has traditionally been delivered is fundamentally broken for the pace at which modern organizations operate. Testing once a year leaves eleven months of blind spots.

We built the Lorikeet Security platform to solve both problems simultaneously. Lory AI, our autonomous AI pentester, runs continuous engagements against your authorized assets -planning, probing, and chaining vulnerabilities around the clock. Our Penetration Testing as a Service portal delivers expert-led human assessments through a modern, transparent workflow. Together, they give organizations both the continuous coverage of an always-on AI tester and the depth of human expert analysis -and every Lory finding passes through a human pentester before it reaches your report.


Part 1: Lory AI -Your Autonomous Pentester

Traditional testing happens on a calendar. You get assessed once a year, maybe quarterly if you are diligent, and for the rest of the year your attack surface drifts -new services ship, dependencies age, misconfigurations creep in -with nobody adversarially testing it. Attackers do not work on your schedule.

Lory is Lorikeet Security's autonomous AI pentester, and she closes that gap. She is not a scanner with a dashboard and she is more than a chatbot. Lory plans an engagement the way a human tester would -recon first, then targeted probing based on what is actually exposed, then chaining individual weaknesses into a real attack path -and writes CVSS-scored, evidence-backed findings straight into your portal. She runs once on demand or continuously, 24/7, and she is scope-gated and non-destructive by default so she only ever touches assets you have explicitly authorized.

Lory, the Lorikeet Security AI pentester mascot, standing ready to run an autonomous penetration testing engagement

Meet Lory -the AI pentester living inside the Lorikeet Security dashboard, running the same TTPs as a human tester, around the clock.

The Lory Engine: Five Stages

Lory operates in five distinct stages, each building on the results of the previous one. This is not a single-shot scan -it is a methodical process that mirrors how an actual attacker approaches a target, from first reconnaissance through a fully written, human-reviewed finding.

1. Discover

Reconnaissance across your in-scope assets, technology fingerprinting, and exposed-service identification to map what is actually reachable within your authorized scope.

2. Probe

Active testing for OWASP Top 10 classes, authentication and access-control flaws, and misconfigurations -chosen from what is exposed, not a static checklist.

3. Chain

Individual weaknesses linked into a real attack path -recon → access → pivot → objective -the way an adversary actually operates.

4. Report

CVSS-scored findings with evidence and AI-written remediation, mapped to CWE and, where relevant, MITRE ATT&CK.

5. Human Review

Every finding is held as pending review and countersigned by a Lorikeet Security pentester -nothing reaches a report without human sign-off.

Why this matters: Most "AI security" tools fire a scanner and call it a day. Lory replicates attacker methodology -the same progression from reconnaissance to exploitation and pivoting that a real adversary follows -and then hands every result to a human expert. You get the speed and coverage of automation with the judgment and accountability of a human pentester.

What Makes Lory Different

Plenty of tools bolt "AI" onto a vulnerability scanner. Lory is built around six capabilities that set autonomous pentesting apart from automated scanning:

Multi-Stage Attack Chains

Recon → access → pivot → objective. Findings are chained for real impact, not reported as isolated CVEs.

MITRE ATT&CK-Driven

Technique selection based on what is actually exposed in your environment -not a fixed playbook or checklist.

Adversary Emulation

Mirrors real APT, ransomware, and insider tactics, techniques, and procedures against your systems.

Continuous, 24/7

Run once or always-on. Lory catches drift the moment your in-scope assets change, not at your next annual test.

Compliance-Mapped

Every chain mapped to SOC 2, PCI-DSS, HIPAA, ISO 27001, and CMMC controls as findings are generated.

Safe By Default

Non-destructive exploitation, scope-gated tools, and human review on every finding before it lands.

Engagement Depth: Surface, Standard, Deep

Not every engagement needs the same intensity. You choose how far Lory goes, and the depth changes what she actually attempts:

DepthWhat Lory DoesTypical Duration
SurfacePassive recon plus safe, non-intrusive checks only. A fast read on obvious exposure.1–2 hours
StandardActive enumeration and non-destructive exploitation. Most OWASP Top 10 classes tested.4–6 hours
DeepFull AI-led engagement with a human pentester reviewing throughout -chaining, pivoting, and multi-stage attack paths in scope.1–3 days

Findings, Severity, and Remediation

Every vulnerability Lory identifies is classified by severity (Critical, High, Medium, Low, Informational) and tracked through a status workflow: Pending ReviewOpenIn ProgressResolved, with additional states for False Positive and Accepted Risk. Each finding includes a clear title and description, affected asset URL, evidence (screenshots, HTTP requests and responses, proof-of-concept), a CVSS score, CWE mapping for standardized classification, and specific remediation guidance grounded in Lorikeet's vulnerability knowledge base -1,969+ entries spanning OWASP ASVS/WSTG/Top 10 and MITRE CWE/CAPEC -rather than an unmoored model guess.

Lorikeet Security finding detail modal showing a Vulnerable version of TLS in use finding with MEDIUM severity, CWE-326, CVSS 5.9, detailed description, attack scenario, remediation guidance, and Simplify with AI buttons

A finding written by Lory in the portal -description, attack scenario, CVSS score, and remediation, with "Simplify with AI" for board-ready risk summaries.

Fix Findings Without Leaving Your Editor

Lory's findings -like every finding in the platform -are pullable directly into your development environment through the Lorikeet MCP server. Wire it into Claude Code, Cursor, or Claude Desktop and your AI coding assistant can read a finding, understand the attack scenario, apply the remediation, and file a retest request without you ever copying a vulnerability out of a dashboard. The loop from "Lory found it" to "developer fixed it" collapses from weeks to minutes.

Continuous, Always-On Testing

Lory is not a one-time engagement. You can schedule recurring runs (daily, weekly, or monthly) or leave her running continuously, and she re-tests the moment your in-scope assets change -a shipped service, a new endpoint, a changed dependency. This is critical because your exposure is never static: developers deploy services, configurations change, dependencies age, and every change can introduce new risk that an annual pentest would never catch in time.


Part 2: Penetration Testing as a Service

Penetration testing has been the most effective way to identify real security vulnerabilities for decades. The methodology is sound: hire experienced security researchers to think and act like attackers, find the weaknesses that automated tools miss, and deliver actionable findings. The problem has never been the testing -it has been the delivery model.

The Problem with Traditional Pentesting

You email a vendor. They send a questionnaire. You wait. They send a proposal. You negotiate. You sign a contract via DocuSign. You wait again. Testing happens behind a curtain with zero visibility. Weeks later, a 200-page PDF lands in your inbox. By then, your codebase has changed, your infrastructure has shifted, and some findings are already outdated.

This model worked in 2005 when organizations deployed software quarterly. It does not work in 2026 when teams deploy multiple times per day.

How Lorikeet Security PTaaS Works

Lorikeet Security PTaaS portal onboarding wizard showing the Welcome to Lorikeet Security screen with a 5-step progress bar, Expert Testing, Real-Time Findings, and Compliance-Ready feature cards, and the How It Works workflow guide with Get Started button

The PTaaS portal onboarding wizard -a guided 5-step workflow from scoping through contract signing, with feature highlights and the "How It Works" guide.

The Lorikeet Security PTaaS portal replaces the entire traditional workflow with a modern, self-service experience:

1

Scope Your Engagement

Select your project type, specify target assets, choose testing dates, and upload supporting documentation -all directly in the portal. No email chains, no questionnaires.

2

Sign Contracts Digitally

Review the auto-generated Statement of Work and Rules of Engagement in a scrollable viewer, then sign with the embedded signature pad. No DocuSign, no wet signatures, no PDF roundtrips.

3

Track Real-Time Findings

Findings are delivered as they are discovered -not weeks later in a PDF. When a tester finds a critical vulnerability on day one, you see it on day one. Your team can start remediating immediately.

4

Download Your Report

Executive and technical report formats with compliance mappings for SOC 2, PCI-DSS, ISO 27001, and HIPAA. Reports are pushed to your portal and downloadable instantly.

Testing Types We Offer

We support 15 types of expert-led penetration testing through the portal -each scoped and delivered through the same streamlined workflow:

Web Application
API Testing
Mobile App
Cloud Infrastructure
Active Directory
Thick Client
IoT & Hardware
Physical Security
PCI-DSS
ISO 27001
ATM / Banking
Kiosk Testing
Red Team Ops
SOC 2 Compliance
Custom Scope

The Project Dashboard

Lorikeet Security PTaaS project overview for flowtriq.com.test showing the five-stage engagement pipeline (Contracting, Actively Pentesting, Remediation, Retesting, Completed), project details including start date, end date, testing type, and target asset, with an Actively Pentesting status badge

A live pentest engagement in the PTaaS portal. The five-stage pipeline tracks progress from contracting through completion, with project details and real-time status.

Each finding includes a severity rating, detailed description with reproduction steps, affected assets, evidence (screenshots, HTTP requests/responses, proof-of-concept code), CWE classification, and step-by-step remediation guidance. Findings can be filtered by severity, status, and category.

Lorikeet Security PTaaS client dashboard showing the Compliance Center, security status overview with priority levels, Ask Lory AI assistant, and Quick Actions for viewing projects, booking meetings, and accessing security reports

The PTaaS client dashboard with security status overview, Lory AI assistant, and quick actions for managing your engagement.

Reporting and Compliance

Final reports include an executive summary for leadership, detailed methodology, every finding with evidence and remediation steps, attack path narratives showing how findings chain together, a prioritized remediation roadmap, and compliance mappings to SOC 2, PCI-DSS, ISO 27001, and HIPAA.

Want to see what a report looks like? We publish a full demo penetration testing report so you can review our format, depth, and quality before engaging.

Compliance note: Every Lorikeet Security pentest report satisfies SOC 2 Trust Services Criteria (CC4.1, CC7.1), PCI-DSS Requirement 11.3, ISO 27001 Annex A.8, and HIPAA Security Rule administrative safeguards. Your report is audit-ready out of the box.


PTaaS vs. Traditional Penetration Testing

The difference is not the testing -it is everything around it. Same caliber of researchers, same methodologies. The difference is the delivery model, the transparency, and the speed:

AspectTraditional PentestingLorikeet Security PTaaS
ScopingEmail exchanges, questionnaires, phone calls over days/weeksSelf-service portal -scope and start in minutes
ContractingPDF contracts via DocuSign, legal review cyclesDigital SOW + ROE signed in-browser with signature pad
VisibilityZero visibility -"black box" vendor relationshipReal-time dashboard with live findings as they are discovered
FindingsDelivered weeks later in a monolithic PDFAppear in portal immediately with severity, evidence, remediation
RemediationFix from static PDF, request retesting separatelyTrack status in portal, retesting included
ReportsTemplate-heavy PDF with automated scanner outputExecutive + technical formats, compliance-mapped, downloadable
QualityVaries -may be partially automated100% manual by experienced researchers. No scanner dumps.
RetestingSeparate engagement, additional costIncluded in engagement workflow
Timeline4–8 weeks from inquiry to reportEngagements begin within days of signing

Compliance Integration: GRC Dashboard

Lorikeet Security Compliance Center showing SOC 2 Type II, ISO 27001:2022, and PCI DSS v4.0 framework tabs, a 13% readiness gauge, 4 complete controls, 1 in progress, 25 not started, and SOC 2 Type II controls list with Availability and Control Environment categories

The Compliance Center with SOC 2 Type II, ISO 27001, and PCI-DSS framework tracking, readiness scoring, and per-control status management.

The platform includes a Governance, Risk, and Compliance dashboard mapping your security posture to SOC 2 Type II, ISO 27001:2022, and PCI-DSS. It provides cross-framework control mappings, evidence upload via secure S3 storage, and AI-powered compliance guidance through Lory. Your human pentest findings, Lory AI findings, and compliance evidence all live in one platform.


Why Organizations Need Both Lory AI and Human Pentesting

Lory provides continuous coverage. She tests your authorized assets around the clock, re-runs the moment your attack surface changes, chains weaknesses into attack paths at machine speed, and maps every finding to compliance controls. She answers: what is exploitable right now, and did that fix hold?

Human pentesting provides depth. Expert testers pursue the ambiguous, judgment-heavy business logic flaws and novel attack chains that require creativity automation does not yet match, and they countersign Lory's work. They answer: what can a determined human attacker actually accomplish?

Consider: Lory runs nightly and flags that a dev endpoint's authentication can be bypassed, chains it into an internal API returning customer records, and files the finding with a CVSS score and proof -on the same night the endpoint shipped. A human tester, reviewing that chain, extends it further: the exposed API key rotates into a second environment, and the whole path becomes a full account-takeover narrative for the board. Machine speed plus human judgment, on the same finding.

Lory AI: Continuous Coverage

Tests 24/7 the moment surface changes. Chains vulnerabilities at machine speed. Verifies remediation persists over time. Satisfies continuous monitoring requirements.

Human Pentesting: Expert Depth

Finds what automation still misses. Extends attack paths with human creativity. Reviews and countersigns every Lory finding. Satisfies assessment requirements.


See It in Action

Lory, the Lorikeet Security AI pentester, running an autonomous engagement and writing findings

Meet Lory on her product page at lorikeetsecurity.com/lory -continuous testing, human-reviewed findings, and MCP integration to fix them in your editor.

Visit the Lory AI page to meet your autonomous pentester, see how the five-stage engine works, and start an engagement. Every finding is human-reviewed, mapped to 12+ compliance frameworks, and grounded in 1,969+ vulnerability signatures -so you get autonomous speed without the false-positive noise.

For human-led pentesting, visit our PTaaS portal to see the onboarding flow, feature overview, and the step-by-step guide: select your scope, sign contracts, track real-time findings, and download your compliance-ready report.


See a Real Pentest Report

Transparency is core to how we work. Preview an example deliverable so you know exactly what to expect.

What's Inside Our Reports

Every engagement produces a comprehensive, audit-ready report. No fluff, no generic scanner output - just clear findings with actionable remediation guidance your developers can act on immediately.

  • Executive summary for leadership and stakeholders
  • Detailed vulnerability findings with severity ratings
  • Step-by-step proof-of-concept reproductions
  • Remediation guidance with code examples
  • Compliance mapping (SOC 2, PCI-DSS, ISO 27001)
  • Risk-based prioritization for your dev team

Ready to Put Lory to Work?

Start an autonomous engagement with Lory AI for continuous, 24/7 testing, or book a human penetration test for deep expert analysis. Both start with a simple conversation.

-- views
Link copied!
Lorikeet Security

Lorikeet Security Team

Penetration Testing & Cybersecurity Consulting

Lorikeet Security helps modern engineering teams ship safer software. Our work spans web applications, APIs, cloud infrastructure, and AI-generated codebases — and everything we publish here comes from patterns we see in real client engagements.

Lory waving

Hi, I'm Lory! Need help finding the right service? Click to chat!