The One-Line Difference
XBOW is a fully autonomous, multi-agent AI pentester with no human in the test loop by design, built to scale web application testing to a speed and breadth no human team can match.
Lory is an AI pentester that runs the same kind of automated testing, but a named Lorikeet Security pentester reads the evidence and signs every finding before it reaches you - and covers more than web applications.
Both are genuinely autonomous, AI-native products, not scanners with an AI label bolted on. The difference is what happens after the agent finds something, and how far the scope of what it can reach actually extends.
At a Glance
| Dimension | XBOW | Lory by Lorikeet |
|---|---|---|
| Model | Fully autonomous, no human in the test loop by design | Autonomous testing, human-signed before findings ship |
| Target requirement | Internet-accessible only - internal, staging, and VPN-gated assets are out of scope | External and internal (via a mesh connector), plus staging when declared in scope |
| Validation model | Automated peer-review agents confirm exploitability with a working exploit | Automated evidence, then a named human pentester signs every finding |
| Speed and scale | Scales across hundreds of targets simultaneously | Scoped per engagement; scale comes from scheduling, not parallel target fan-out |
| On-demand pricing | Lightspeed from $4,000 per test, full report within 5 business days | Prepaid credits, itemised quote within 24 hours |
| Track record | #1 on HackerOne's US leaderboard (June 2025); Microsoft Security Copilot integration (March 2026); Accenture investment (May 2026) | Not published in comparable third-party terms |
| Asset coverage | Web applications (primary focus) | Web, API, mobile, network (internal and external), cloud, source code |
| Business logic and novel chaining | By XBOW's own description, no human context layer for these | Human pentester reviews the chain and context before signing |
| Recurring coverage | Continuous offensive testing is core to the platform | Weekly, biweekly, monthly, quarterly, or yearly, queued and started automatically |
Coverage, Side by Side
| Asset Type | XBOW | Lory |
|---|---|---|
| Web app (internet-facing) | Yes, the core focus | Yes |
| API | Not called out separately from web | Yes, crawl, auth testing, injection, access control |
| Internal network / staging / VPN-gated | Architecturally out of scope | Yes, via the mesh connector |
| External network | Not published as a distinct product line | Yes, services, versions, exposure |
| Mobile | Not published | Yes, iOS and Android plus their backends |
| Cloud | Not published | Yes, AWS, Azure, GCP, Kubernetes, containers, serverless |
| Source code review | Not published | Yes, secret hunting, sink tracing, supply chain |
| Physical | Not offered | Human-led, never run by Lory |
Where XBOW Differentiates
- Proven at genuine scale and speed. Becoming the first autonomous system to reach #1 on HackerOne's US leaderboard, ahead of every human participant, is a hard, independently verifiable benchmark most vendors in this space can't point to.
- Deep platform integration. The March 2026 integration into Microsoft Security Copilot and the Sentinel data lake puts continuous pentesting inside a security stack teams already run, rather than a separate portal to check.
- Institutional validation. Accenture's May 2026 strategic investment and partnership is a strong signal of enterprise credibility for a company built around removing humans from the loop.
- Fast, published on-demand pricing. A test starting at $4,000 with a report inside 5 business days is a clear, comparable number - something a lot of pentest vendors, ourselves included on bespoke scopes, don't put on a page.
- No human bottleneck. Removing the review step entirely means findings surface as fast as the agents can validate them - a real advantage if throughput matters more to you than a countersignature.
Where Lory Differentiates
- A human signs every finding. XBOW's own materials describe "no human context layer for business logic, compliance, or novel chaining." Lory's human step exists specifically to catch what a purely automated peer-review loop is built to miss.
- Internal networks are in scope. XBOW requires internet-accessible targets by design; staging and VPN-gated assets are architecturally out of reach. Lory's mesh connector extends testing to internal ranges.
- One vendor covers the whole estate. Mobile, cloud, and source code review sit alongside web and network in the same engagement and the same credit balance - a buyer standardising on XBOW for web still needs separate coverage for the rest.
- A coverage record. Every Lory run reports which vectors were planned, run, and never reached, and why.
- Scope as an enforced gate. Every tool call is checked against a signed allowlist before it fires - useful for anyone who has to explain an autonomous tool's behaviour to a regulator or a customer.
Picking Between Them
- Your scope is internet-facing web applications and you want maximum speed and scale
- You want a published on-demand price and a fast turnaround
- You already run Microsoft Security Copilot or Sentinel and want pentesting inside that stack
- Throughput matters more to you than a named human countersignature
- You need internal network, mobile, cloud, or source code coverage alongside web
- You need a named person to stand behind every finding for a customer, auditor, or board
- You want business-logic and novel-chain judgment calls reviewed by a human before they ship
- You want a scheduled, recurring engagement across your whole estate under one credit balance
Both are legitimate AI-native approaches to the same underlying problem. The honest dividing line is whether you need a human countersignature and coverage beyond internet-facing web apps, or whether speed and scale against exactly that surface is what you're optimising for.
See a Signed Engagement in Action
Book a scoping call and we'll walk you through what a Lory engagement covers beyond web - internal network, mobile, cloud, and source code - and how a named pentester signs off before anything reaches your report.
Book a Consultation