Cyrex Penetration Testing - AI-Augmented Security Assessments
Cyrex · Cybersecurity & IT
Certification per AWS Marketplace.
Evidence tier Source Confirmed · 4 captures on record
What the publisher says
As described on AWS Marketplace.
## Cyrex Penetration Testing - AI-Augmented Offensive Security
Cyrex delivers penetration testing for organizations operating complex digital products and infrastructure on AWS and beyond. Each engagement is performed through the Renewed Pair Hacking methodology, where senior security engineers work alongside proprietary AI agents that automate reconnaissance, generate attack paths, and expand test coverage - while expert human judgment drives exploitation, validation, and strategic analysis.
Show the rest of the publisher’s description (37 more lines)
## What We Test
Cyrex assessments cover modern technology stacks including:
- **Web applications and SaaS platforms** - authentication flows, session management, business logic, and multi-tenant isolation
- **APIs and microservices** - REST, GraphQL, gRPC, and custom protocols
- **AWS cloud environments** - Amazon EC2, AWS Lambda, Amazon EKS, Amazon S3, AWS IAM policies, VPC configurations, and serverless architectures
- **Network infrastructure** - internal and external perimeter testing, segmentation validation
- **Web3 ecosystems** - smart contract exploitation, DeFi protocol analysis, bridge vulnerabilities
- **Online multiplayer games** - anti-cheat bypass testing, real-time protocol fuzzing, game economy manipulation
## How an Engagement Works
A typical Cyrex engagement follows a structured lifecycle:
- **Scoping call** - Cyrex conducts a discovery session to understand your architecture, threat model, and compliance requirements
- **Engagement planning** - Testing windows, access provisioning, and rules of engagement are agreed upon
- **Offensive testing** - Senior engineers and AI agents execute coordinated attacks across the defined scope
- **Vulnerability validation** - Every finding is manually verified to eliminate false positives
- **Reporting** - A detailed technical report with executive summary, finding severity ratings, and step-by-step remediation guidance is delivered
- **Advisory and retesting** - Post-engagement consulting, remediation support, and verification testing confirm fixes are effective
Engagements typically run two to four weeks depending on scope complexity.
## What You Receive
- Detailed technical findings report with proof-of-concept exploits
- Executive summary suitable for board-level stakeholders
- Remediation roadmap prioritized by risk severity
- Post-engagement consulting session
- Verification retest to confirm remediation effectiveness
## Use Case: SaaS Platform Preparing for Compliance
A SaaS company preparing for SOC 2 or ISO 27001 certification engages Cyrex to validate their security posture before the audit. Cyrex scopes the assessment around the platform's AWS infrastructure (EC2, Lambda, S3, IAM), customer-facing APIs, and authentication mechanisms. The engagement identifies exploitable vulnerabilities and provides a remediation roadmap that directly maps to compliance control requirements, enabling the customer to close gaps before their audit window.
## Prerequisites and Buyer Responsibilities
To begin an engagement, buyers must provide:
- Written authorization for testing (scope agreement and rules of engagement)
- Environment access credentials or test accounts as applicable
- Architecture documentation or diagrams for scoped systems
- A designated point of contact for coordination during testing
## Scope Boundaries
Standard engagements do not include physical security testing, social engineering campaigns, or denial-of-service simulation unless explicitly scoped and authorized.
## Data Protection
All engagement data - including credentials, architecture diagrams, findings, and reports - is encrypted in transit and at rest. Cyrex follows strict data retention policies with defined deletion timelines post-engagement. Non-disclosure agreements are executed before any sensitive information is exchanged.
## Get Started
Contact Cyrex through AWS Marketplace to schedule a free scoping call and receive a tailored proposal for your environment.
Highlights
Highlighted by the publisher on AWS Marketplace.
Penetration testing delivered through Renewed Pair Hacking, combining senior security engineers with proprietary AI agents for deeper and more consistent coverage.
Tailored security assessments across applications, APIs, SaaS platforms, cloud environments, networks, custom protocols, Web3, and online multiplayer games.
End-to-end support from scoping and offensive testing to vulnerability validation, reporting, remediation guidance, consulting, and strategic security advisory.
Preview
1 imageAgent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Vendor
External enrichment
Sources
Publisher resources
3 linksLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

