Skip to main content
BattleTest gives developer teams enterprise-grade security coverage at a fraction of the cost of a traditional pentest engagement. Two products, one platform: automated PR security review and autonomous live infrastructure testing.

PR Security Review

Every pull request gets a full security analysis — CVE detection, secret scanning, injection analysis, config hardening checks — posted as a GitHub comment within minutes.

Live BattleTest

An AI agent autonomously crawls and probes your running infrastructure, discovering endpoints, testing for active vulnerabilities, and generating a findings report.

What you get on every pull request

When a developer opens a PR, BattleTest runs automatically and posts a review like this within 2–4 minutes:
No configuration. No CI pipeline changes. No scheduled scans to remember to trigger. The two products share one finding record, so a vulnerability caught in a PR and later confirmed in a live scan is linked — and a resolved issue that resurfaces is flagged as a regression. For the reasoning behind this design, read About BattleTest.

Where to start

Get your first PR review

Connect a repo and see a real security review in under 5 minutes.

Run your first live battletest

Add a domain, run a discovery scan, and read a confirmed finding. Requires Startup plan.

How the docs are organised

The documentation follows four distinct sections:
  • Tutorials — step-by-step learning guides that take you through a complete task from start to finish. Start here if you’re new.
  • Concepts — explanations of how BattleTest works, why it’s designed the way it is, and how to interpret what it produces. Read these when you want to understand, not just do.
  • How-to guides — task-focused instructions for specific goals: configuring settings, managing findings, exporting reports. Assumes you know your way around the product.
  • Reference — complete technical specifications: finding fields, scan report structure, GitHub App permissions, limits, and webhook payload format.