Penetration testing

We test web applicationsfrom an attacker’sperspective.

Layer8's AI and security engineers assess web applications and APIs for paths that could lead to unauthorized access or actions. Before testing, we agree on the scope and operating conditions. The final report covers evidence, impact, and remediation guidance for confirmed vulnerabilities.

  • Web applications and APIs
  • One-off and recurring assessments
  • Black-box and gray-box testing

What we do

We begin with the target systems and risks to assess. Before testing, we agree on the scope and operating conditions, and the same team remains responsible through post-remediation verification.

From consultation to reporting

Testing begins after the scope, operating conditions, and communication procedures are agreed. We can retest remediated issues after reporting when required.

  1. Initial discussion

    We review the systems, risks to assess, preferred timing, and internal procedures.

  2. Scope and operating conditions

    We document target URLs, test accounts, testing windows, traffic limits, and prohibited actions.

  3. Assessment and validation

    Testing remains within the agreed scope. Only vulnerabilities whose impact and reproducibility have been confirmed are included in the report.

  4. Reporting and retesting

    We deliver the assessment report and retest remediated issues when required.

Assessment controls

Outbound traffic from the AI agents passes through execution controls. The agreed targets, traffic limits, and prohibited actions are reflected in the execution-layer configuration.

Review the report structure

Out-of-scope traffic is blocked

The agreed scope is configured in the execution layer, which blocks all out-of-scope traffic.

Load and hazardous actions are limited

Request rates, concurrency, testing windows, permitted protocols, and prohibited actions are configured for each engagement.

Execution is recorded and stoppable

Traffic and execution logs are retained, and stop procedures and communication paths are agreed before testing begins.

Performance record

8,000+

Vulnerabilities identified by Layer8's AI

#1

HackerOne global VDP ranking

Q3 2026

View leaderboard
16

Reports triaged by the U.S. Department of Defense

Accepted as valid vulnerability reports

View l8_trident's profile

About Layer8

Layer8 Co., Ltd. is based in Minato-ku, Tokyo. We provide penetration testing for web applications and APIs using AI developed in-house and security engineers.

Company information
Company
Layer8 Co., Ltd.
Location
Mitsuhashi Bldg. 3F, 1-3-3 Kita-Aoyama, Minato-ku, Tokyo 107-0061, Japan
CEO
Takumasa Okamoto

Technical notes and company news

We publish notes on AI-agent design and evaluation, results from real-world testing, and company announcements.

View all articles

Contact

Discuss an assessment or technical collaboration

You can contact us before the target systems, validation goals, or timing are fully defined. We will review the information available and define the next steps.