Classic penetration test
annual time window · manual effort
- Snapshot instead of trend view
- Hard to reproduce between audits
- Findings go stale between tests

RedMentis makes security testing more repeatable and reveals attack paths in context, as a complement to classic penetration tests.
One audit per year, then 11 months of flying blind in between. RedMentis aims to close that gap, without replacing the classic pentest.
annual time window · manual effort
repeatable · isolated · automated
RedMentis combines operational security, the management view and offensive testing in one platform, with clearly separated roles and a shared data foundation.
An AI-assisted decision logic models possible attack paths, evaluates intermediate results and prioritizes risks in context.
Defined scope, isolated test environment, clear rules of engagement.
AI-assisted modeling of possible attack paths across identities, configurations and interfaces.
Tests run repeatably in an isolated environment. Intermediate results are evaluated and prioritized.
Technical findings with remediation, management reports with clear context.
The entire process runs under two non-negotiable rules:



An AI-orchestrated security validation. RedMentis does not just take a snapshot, it looks at weaknesses in the context of possible attack paths and makes that check repeatable. RedMentis is our research and development initiative, not a finished mass-market product.
No. RedMentis complements the classic pentest, it does not replace it. The value lies in repeatable checks between audit cycles and in the view of connected attack paths instead of isolated findings.
In a controlled, isolated test environment. Every action is bound to a role, every access is logged. Production systems stay untouched and the results stay traceable.
Findings are mapped to ISO 27001, NIS 2 and the EU AI Act. A technical result becomes evidence that fits directly into audit and management requirements.
RedMentis is in active development. We are open about the current status and assess first use cases or a pilot setup together with you, matched to your environment.
We're happy to talk about pilot setups, research partnerships or initial use-case assessments, aligned with the current stage of development.