XBOW vs Lory: Autonomous AI Pentesting vs a Human-Signed Engagement | Lorikeet Security Skip to main content
Back to Blog
Vendor Comparison

XBOW vs Lory: Autonomous AI Pentesting vs a Human-Signed Engagement

Lorikeet Security · September 7, 2026 · 10 min read
Disclosure: This is written by Lorikeet Security. The XBOW column reflects XBOW's public product pages, press releases, and 2026 news coverage (the Microsoft Security Copilot integration in March 2026 and the Accenture investment in May 2026 among them). Anything not stated publicly is marked not published rather than guessed at.

The One-Line Difference

XBOW is a fully autonomous, multi-agent AI pentester with no human in the test loop by design, built to scale web application testing to a speed and breadth no human team can match.

Lory is an AI pentester that runs the same kind of automated testing, but a named Lorikeet Security pentester reads the evidence and signs every finding before it reaches you - and covers more than web applications.

Both are genuinely autonomous, AI-native products, not scanners with an AI label bolted on. The difference is what happens after the agent finds something, and how far the scope of what it can reach actually extends.


At a Glance

DimensionXBOWLory by Lorikeet
ModelFully autonomous, no human in the test loop by designAutonomous testing, human-signed before findings ship
Target requirementInternet-accessible only - internal, staging, and VPN-gated assets are out of scopeExternal and internal (via a mesh connector), plus staging when declared in scope
Validation modelAutomated peer-review agents confirm exploitability with a working exploitAutomated evidence, then a named human pentester signs every finding
Speed and scaleScales across hundreds of targets simultaneouslyScoped per engagement; scale comes from scheduling, not parallel target fan-out
On-demand pricingLightspeed from $4,000 per test, full report within 5 business daysPrepaid credits, itemised quote within 24 hours
Track record#1 on HackerOne's US leaderboard (June 2025); Microsoft Security Copilot integration (March 2026); Accenture investment (May 2026)Not published in comparable third-party terms
Asset coverageWeb applications (primary focus)Web, API, mobile, network (internal and external), cloud, source code
Business logic and novel chainingBy XBOW's own description, no human context layer for theseHuman pentester reviews the chain and context before signing
Recurring coverageContinuous offensive testing is core to the platformWeekly, biweekly, monthly, quarterly, or yearly, queued and started automatically

Coverage, Side by Side

Asset TypeXBOWLory
Web app (internet-facing)Yes, the core focusYes
APINot called out separately from webYes, crawl, auth testing, injection, access control
Internal network / staging / VPN-gatedArchitecturally out of scopeYes, via the mesh connector
External networkNot published as a distinct product lineYes, services, versions, exposure
MobileNot publishedYes, iOS and Android plus their backends
CloudNot publishedYes, AWS, Azure, GCP, Kubernetes, containers, serverless
Source code reviewNot publishedYes, secret hunting, sink tracing, supply chain
PhysicalNot offeredHuman-led, never run by Lory

Where XBOW Differentiates


Where Lory Differentiates

Honest Weak Spots for Lory XBOW's human-free model is faster by design - there's no review queue between a validated exploit and the report. Its published on-demand pricing ($4,000, 5 business days) is more transparent up front than a scoped quote. And its HackerOne leaderboard result and Microsoft/Accenture backing are concrete, independently-verifiable proof points of technical strength at scale that we can't currently match with a comparable public benchmark.

Picking Between Them

XBOW may fit if...
  • Your scope is internet-facing web applications and you want maximum speed and scale
  • You want a published on-demand price and a fast turnaround
  • You already run Microsoft Security Copilot or Sentinel and want pentesting inside that stack
  • Throughput matters more to you than a named human countersignature
Lory may fit if...
  • You need internal network, mobile, cloud, or source code coverage alongside web
  • You need a named person to stand behind every finding for a customer, auditor, or board
  • You want business-logic and novel-chain judgment calls reviewed by a human before they ship
  • You want a scheduled, recurring engagement across your whole estate under one credit balance

Both are legitimate AI-native approaches to the same underlying problem. The honest dividing line is whether you need a human countersignature and coverage beyond internet-facing web apps, or whether speed and scale against exactly that surface is what you're optimising for.

See a Signed Engagement in Action

Book a scoping call and we'll walk you through what a Lory engagement covers beyond web - internal network, mobile, cloud, and source code - and how a named pentester signs off before anything reaches your report.

Book a Consultation
-- views
Link copied!
Lorikeet Security

Lorikeet Security Team

Penetration Testing & Cybersecurity Consulting

Lorikeet Security helps modern engineering teams ship safer software. Our work spans web applications, APIs, cloud infrastructure, and AI-generated codebases — and everything we publish here comes from patterns we see in real client engagements.