Thursday, 17 September 2026

Protectt.ai Launches AI-Powered Offensive Security Platform that Mimics Real-World Attacks on BFSI Apps

TechnologyK Puspa17 Sept 2026

Mumbai, Sep 17: Protectt.ai, a mobile application and AI security company serving banks, NBFCs and insurers, today announced the launch of its AI for Security Platform, which uses autonomous AI agents to simulate real-world cyberattacks on web and mobile applications.

Media Release | Protectt.ai Launches AI-Powered Offensive Security Platform that Mimics Real-World Attacks on BFSI Apps

The agents act like attackers, continuously probing applications for weaknesses, trying different ways to exploit them and assessing how multiple weaknesses could be used together. This brings red-team testing, where security teams think and act like an attacker to uncover security gaps, into the software release cycle, allowing financial institutions to test applications every time they are updated.

The launch comes as banks, NBFCs and fintechs increasingly release application updates weekly or even daily, while traditional security assessments are often conducted periodically. This creates a gap between assessments, during which new vulnerabilities can potentially be introduced. Protectt.ai’s platform is designed to close this gap by enabling organisations to continuously test new releases rather than waiting for the next scheduled assessment.

“Security cannot be a quarterly exercise when financial applications are changing every day,” said Manish Mimani, Founder and CEO, Protectt.ai. “With autonomous AI agents, organisations can put their applications under attack continuously, not just look for vulnerabilities, but see how a real attacker could find, connect and exploit them. The goal is to make red-team testing a part of every release, so security teams can identify the path to an attack before an attacker does.”

The company’s AI for Security Platform brings together three capabilities. RedPilot is an autonomous red-teaming solution that acts like a real-world attacker, finding and connecting security weaknesses to demonstrate how an application could potentially be compromised. WebScan tests web applications, networks, infrastructure and APIs against more than 30 real-world attack scenarios and identifies validated security issues. AppScan, Protectt.ai’s mobile application security product, has been enhanced with AI to run more than 140 automated security tests on every application build.

The platform is designed for use by regulated organisations. The AI agents can operate within a bank’s own environment, including on-premises, private cloud or hybrid setups. Application code and security findings are not sent to external AI services. All testing is authorised and controlled by the organisation’s security team.

The platform is designed to complement, rather than replace, human security experts. Areas such as social engineering, physical security and certain business-logic issues still require human judgement. The AI agents are intended to automate repeatable security testing and make it practical to test applications each time a new version is released.

Additionally, platform generates reports with evidence of identified security issues and guidance for remediation, helping security teams understand the risk, fix vulnerabilities and track improvements across releases.

For regulated financial institutions, the platform can support ongoing security testing alongside existing regulatory and independent assessment requirements. Under the RBI’s Master Direction on IT Governance, Risk, Controls and Assurance Practices, critical systems require vulnerability assessments at least twice a year and penetration testing at least once a year, as well as after a major change. The platform is intended to complement, not replace, independent assessments such as those required by regulators or boards.