TL;DR

Cracken launched a self-serve tier of its proactive security platform at $199 a month, its first public access outside contracts

Cracken launched a self-serve tier of its proactive security platform at $199 a month, its first public access outside contracts

Cracken, a San Francisco-based applied AI lab focused on offensive cybersecurity, has launched a self-serve version of its proactive security platform. Enterprise security teams and individual practitioners can now create an account and start testing their own organisations against real attack paths without a procurement cycle or sales call. It is the first time the company’s tooling has been available outside a contracted engagement.

The launch comes weeks after AI models from both OpenAI and Anthropic broke out of their test environments and compromised real companies, incidents that have sharpened industry focus on proactive defence. Cracken’s pitch is that traditional security tools test individual components, while attackers chain entire organisations, and its platform is designed to find the organisational vulnerabilities, threats, and risks that component-level testing misses.

The self-serve tier covers what Cracken calls the discovery and remediation side of its work, including an operator workflow for mapping organisational risk and a “Cybergraph” that holds every asset, finding, and piece of evidence. Human-in-command controls govern every engagement: scope locks on the defined target, approval gates before any non-reversible action, and full audit logging.

The company’s more aggressive offensive capabilities remain behind the enterprise paywall. Those include Cracken Red, the company’s unrestricted AI model built specifically for offensive cybersecurity, as well as restricted sensitive playbooks and air-gapped deployment options. Cracken says the split is deliberate, given the sensitivity of full kill-chain offensive tooling.

Reactive cyber is dead, and organisations need to change fast while their own bureaucracy moves slow,” said Artem Sorokin, founder and CEO of Cracken. “There are limits, since offensive cybersecurity is a sensitive subject, and some of our work stays with our enterprise customers, but you can get a feel for the platform and use it for legitimate proactive security right now.

Cracken was founded in 2023 and has raised $5 million from Form Ventures and Frontline Ventures, according to Crunchbase. Sorokin, a former software engineer with an MIT MBA background, has described his approach to cybersecurity as shaped by witnessing nation-state cyberattacks during the invasion of Ukraine. The company also released two open-source tools this week: Project Blacksea, a honeypot system designed to detect and counter AI-driven attackers, and RedlineBench, a benchmark for evaluating AI systems on offensive cybersecurity tasks.

The self-serve platform starts at $199 a month and is initially available in the United States, Canada, the United Kingdom, the European Economic Area, Ukraine, Taiwan, Japan, South Korea, Australia, and New Zealand. The broader AI cybersecurity market is attracting significant investment, as enterprises scramble to secure both the AI tools they deploy and the AI-powered threats they face.

Get the most important tech news in your inbox each week.