Operator drives. AI co-pilots.
Pause at any planner step. Inject a hint, redirect the loop, or reject a candidate. The AI's reasoning trace renders inline with the run, never in a separate panel you forget exists.
Autopilot agents start a scan and disappear for four hours. lecram lets you pause, inject a hint, or redirect the AI mid-step. Findings ship as Issues, not flat run rows. Container-per-tool isolation. Bring your own key.
What it is
Most "AI pentest" products start a scan and walk away. lecram is built for the operator who stays in the loop and treats the AI like a teammate.
Pause at any planner step. Inject a hint, redirect the loop, or reject a candidate. The AI's reasoning trace renders inline with the run, never in a separate panel you forget exists.
Findings, evidence, knowledge, methodology, one substrate. Stop juggling Burp, Notion, and a screenshot folder.
Every tool runs in its own image. scope_guard refuses out-of-scope targets before the container even starts.
HackTricks, OWASP WSTG, Trail of Bits AppSec preloaded into a sidebar. Cross-engagement memory: the planner remembers what got promoted last time.
The product
Not stock mockups. Actual surface. Scroll the four scenes, the canvas listens.
The lane
XBOW, NodeZero, Pentera ship autopilot. Operator hands off, scan returns four hours later. Burp Pro is operator-only with no AI. PlexTrac and AttackForge are reporting layers, they don't run scans. lecram is the only product where an operator can drive a real engagement against a real customer's app, with real test accounts, and have the AI learn what works.
Capabilities
A non-exhaustive view of what's already shipping in v1.
Pricing
Free is the operator's tier: fully featured, single-engagement, BYO API key. Team and Enterprise unlock seats, integrations, and SSO. Real numbers post v1.1.
$0
Self-host. The operator's tier.
$179/ seat / month
For consulting shops and small AppSec teams.
Custom
For internal red teams and security orgs.
We open access in cohorts. Tell us a bit so we can route invites to the right people first.