28 answers about Nebula, autonomous pentesting, pricing, and integration.
05 questions
BreachLine Labs is a UK security company. We build Nebula, an AI security engineer you hire to prove security against a written scope. You brief it; you do not log in to run it. A UK engineer signs every report.
Nebula is an autonomous AI security engineer. You hire it against a written approved scope. It plans and executes tests, proves findings with a working exploit inside that scope, and a UK engineer signs off every report before release. Risky production moves wait on your approval.
Brief Nebula. Share what you need tested by email, or book a short call on Zoom, Google Meet, or Microsoft Teams. We agree a written scope and authorisation, then Nebula runs inside that scope. Findings reach you as they are proven; a UK engineer signs the report.
Three things: written authorisation to test the target, which the law and our Terms of Service both require; a clear scope (URL, IP or CIDR range, and any systems in bounds); and credentials if you want signed-in surfaces covered. Meetings can be Zoom, Google Meet, or Microsoft Teams.
After the brief and written scope, Nebula works the target inside approved bounds. Proven findings come through with steps to reproduce. The full report follows when the run finishes, signed by a UK engineer. A free retest is available after you fix.
05 questions
It runs a reason-then-act loop. It reads what has come back so far, decides which lead is worth following, runs the tool that follows it, then re-plans against the result. That is roughly how a pentester works through a target, and the loop is what lets it change direction rather than finish a fixed checklist.
Each agent gets its own sandboxed container with a full offensive toolkit already installed, covering reconnaissance through to post-exploitation. Which tools run, and in what order, is decided from what the target gives back rather than from a fixed playbook.
Nebula's orchestrator dispatches work to specialist agents (XSS hunter, SQLi specialist, SSRF expert, cloud misconfiguration detector, etc.) in three execution modes: sequential for methodical depth, parallel for speed, and swarm mode for complex multi-vector attack chains where agents share context.
Everything it learns is kept for the length of the engagement: hosts, endpoints, what it has already tried, and what it has confirmed. Later phases read that history, so the exploitation stage starts from what reconnaissance found instead of rediscovering it.
Yes. It posts into Slack as it works, so criticals arrive as they are proven rather than at the end. You can reply in the thread to ask what it is doing or to widen and narrow the scope while it runs.
05 questions
All data is encrypted at rest (AES-256) and in transit (TLS 1.3). Each customer's scan environment is isolated at the container level. Enterprise customers can deploy Nebula on-premise for complete data residency control with zero external telemetry.
Yes, always, and we cannot waive it. Testing a system without written authorisation is a criminal offence under the Computer Misuse Act 1990 in the UK, the CFAA in the US and equivalents elsewhere. Our Terms of Service require you to hold that authorisation before a scan starts.
Yes. BreachLine Labs Limited is a UK-registered company operating under GDPR. We process only the data necessary to perform scans, provide clear data retention policies, and support data deletion requests. Enterprise customers with on-premise deployment retain full data sovereignty.
Yes. Nebula maps findings to OWASP Top 10, PCI-DSS, SOC 2, ISO 27001, NIST, and CWE in its reports. Mapping is a reporting feature, not a claim that BreachLine holds those certifications.
BreachLine Labs Limited is registered in England and Wales, headquartered at 60 Tottenham Court Road, Office 1377, Fitzrovia, London W1T 2EW. Cloud infrastructure is hosted in EU and UK regions by default, with configurable data residency for Enterprise customers.
04 questions
Injection of most kinds (SQLi, XSS, SSRF, XXE, command injection), authentication and session handling (OAuth, JWT, SAML, MFA bypass), broken access control (IDOR, privilege escalation), API-specific issues across REST and GraphQL, and business-logic flaws. It also chains several of those together where one leads into the next, which is usually where the real impact is.
Yes. Give it session tokens, API keys or a login and it will sign in and test what is behind the login: admin panels, per-user endpoints, horizontal and vertical privilege escalation, and the business logic an unauthenticated scan never reaches.
Yes. Nebula tests REST and GraphQL APIs for injection, broken authentication, excessive data exposure, and rate limiting issues. For cloud environments, it identifies misconfigurations in exposed services, storage buckets, IAM issues visible from an external perspective, and cloud-specific attack vectors.
Yes. Nebula joins Zoom, Google Meet, and Microsoft Teams live. Brief it there the way you brief a colleague. Email and Slack still work for everything else.
04 questions
Four plans: Individual, Team, Business, and Enterprise. Individual is one engineer, one asset, from £399 per month ex VAT. Team is a shared engineer for a small team, from £899 per month. Business covers a growing org attack surface, from £2,299 per month. Enterprise is per seat and metered, from £199 per seat per month (minimum 5 seats). Every plan includes the Nebula engine, UK engineer sign-off on reports, free retests after a fix, an email address for each AI staff member, and live meeting join on Zoom, Google Meet, and Microsoft Teams. The full comparison is on /pricing.
Individual includes 400 credits per month, 1 AI staff member, 1 named seat, one web or API app tested continuously, and 100 alerts investigated with evidence. Team includes 1,000 credits, 1 AI staff member, 3 named seats, three web or API apps, and 150 alerts. Both roll unused credits for one month, bill overage at £1.00 per credit, and include email support next working day. See /pricing for the full table.
Business includes 2,800 credits per month, 1 AI staff member, 10 named seats, four web or API apps plus one network or cloud environment and one mobile app on a physical handset, and 500 alerts, with email support the same day. Enterprise is £199 per seat per month (minimum 5 seats), usage metered in arrears at £0.95 per credit, unlimited applications, network, cloud and mobile on usage, additional AI staff at £549 each, and a named engineer on priority response. Contact us via /contact for Enterprise.
Not a self-serve trial, but we will run a guided demo against a target you authorise, so what you are looking at is your own infrastructure and your own findings rather than a canned example. Request one via /contact.
05 questions
Nebula connects to your Slack workspace via Socket Mode (no public URL required). It sends critical findings in real time, posts scan progress updates, and accepts commands directly in channel. You can ask Nebula questions, adjust scan scope, or request status updates, all within Slack.
HTML reports with a summary for the board and the technical detail underneath it: reproduction steps for every finding, CVSS scores, framework mappings (OWASP, PCI-DSS, SOC 2, ISO 27001, NIST, CWE) and remediation ordered by what to fix first. They export cleanly for sending on.
Yes. The BreachLine API lets you trigger scans, poll for status, and retrieve findings programmatically. This means you can integrate Nebula into your CI/CD pipeline to run security scans on every deployment to staging, blocking releases that introduce critical vulnerabilities.
Scan data is retained for the duration of your subscription. Enterprise customers can configure custom retention. All data can be deleted on request in compliance with GDPR.
Yes. Criticals and highs go out by email as they are proven, with a summary when a run finishes and a weekly digest if continuous monitoring is on. You can set the severity threshold per scan.
Reach out to our security engineering team. We typically respond within a few hours.