MindFort is an autonomous security assessment platform that deploys AI-driven agents to continuously perform penetration testing, vulnerability evaluation, and remediation across applications, source code, infrastructure, and cloud environments. The platform executes scheduled or on-demand tests within isolated, containerized environments, employing white-box and black-box methodologies to scan web applications, APIs, code repositories, endpoints, network configurations, and cloud components. Agents simulate attacks against live targets, chain multiple vulnerabilities, and produce validated exploits that are re-verified by a separate judge agent. The platform supports configurable assessment methods (Balanced, Deep, Ultra), attack surface discovery, software composition analysis, cloud misconfiguration remediation, and dual-credential assessments for access control testing. Contextual assets—including network diagrams, API specifications, architecture reviews, and prior reports—can be uploaded to inform agent behavior.
The platform exposes RESTful APIs and a Model Context Protocol (MCP) server for programmatic management of targets, assessments, findings, and reports, secured via OAuth-based bearer token authentication with organization membership and feature flag validation. Target management supports creation, retrieval, update, and deletion with configurable attributes including type, domains, IP addresses, and credentials. The findings API provides vulnerability descriptions, impact assessments, evidence, reproduction steps, remediation guidance, status tracking, and retest metadata. Administrative capabilities include profile management, team administration, subscription handling, credit allocation, target capacity controls, and SSO integration (Okta, Azure AD, Google Workspace). Enterprise controls encompass role-based access, tenant isolation, and private deployment on AWS, Azure, or GCP with encryption at rest and in transit. Integration support extends to Jira, Linear, Slack, and GitHub for ticket creation and automated remediation workflows, with CI/CD pipeline integration enabling automatic vulnerability scans on code changes. The platform includes a Coverage view for test metrics, an Overview Dashboard for health scores and trends, and an Agentic Control System with version control, approval workflows, and audit trails for remediation actions.