Classic penetration test
annual time window · manual effort
- Snapshot instead of trend view
- Hard to reproduce between audits
- Findings go stale between tests

RedMentis makes security testing more repeatable and reveals attack paths in context, as a complement to classic penetration tests.
One audit per year, then 11 months of flying blind in between. RedMentis aims to close that gap, without replacing the classic pentest.
annual time window · manual effort
repeatable · isolated · automated
RedMentis combines operational security, the management view and offensive testing in one platform, with clearly separated roles and a shared data foundation.
RedMentis is built in two successive phases, with a clear focus on pilot readiness before expansion.
Pilot version for AI-orchestrated, repeatable security validation, focused on network & Active Directory as well as web/API.
Building an isolated research and lab environment for attack patterns, detection engineering and security research.
An AI-assisted decision logic models possible attack paths, evaluates intermediate results and prioritizes risks in context.
Defined scope, isolated test environment, clear rules of engagement.
AI-assisted modeling of possible attack paths across identities, configurations and interfaces.
Tests run repeatably in an isolated environment. Intermediate results are evaluated and prioritized.
Technical findings with remediation, management reports with clear context.
The entire process runs under two non-negotiable rules:
We're happy to talk about pilot setups, research partnerships or initial use-case assessments, aligned with the current stage of development.