Security briefingTerra launches Prevention · August 2026WELL Health reports 10× coverageAI agents · Human control

Company / Offensive security

Terra Security’s AI hackers come with a human veto

WELL Health says Terra expanded its web testing coverage tenfold without increasing its budget. The interesting part is who gets to tell the AI hackers to stop.

Iain Paterson was an awkward customer for a company selling AI hackers. Before becoming chief information security officer at WELL Health, he had run Cycura, a penetration testing firm that WELL later acquired. He knew the craft. He also knew its arithmetic: more applications, more changes, more work for the people hired to break them. The problem was keeping that knowledge in circulation between scheduled tests.

The story in three moves
  • Terra tests for exploitable weaknesses continuously, with AI agents and human oversight.
  • WELL Health reports tenfold web attack surface coverage within its existing budget.
  • The product now reaches beyond discovery into network testing and temporary exploit blocking.

In Terra’s June 2026 case study, Paterson described moving beyond quarterly pentests toward continuous coverage. “Terra has 10X our web attack surface coverage,” he said. That is a customer’s reported result, rather than a benchmark for every deployment. Still, the buyer matters. A former pentesting chief was purchasing a different way to distribute expert attention.

The buyer who knew what a pentest should do

Penetration testing means giving authorized attackers permission to try to defeat your defenses. A useful test reveals how a weakness becomes a consequence. Could someone move between accounts? Reach protected information? Combine several modest mistakes into a serious intrusion? The report should help developers understand both the route and the repair.

WELL’s difficulty was that periodic assessments left gaps as applications changed. Alerts added another chore: deciding which problems were actually exploitable. Terra’s proposition connects those two frustrations. Keep testing as the environment evolves, and deliver evidence about what can be used against it. A longer list of suspicions would merely give Paterson another queue to manage.

10×
Web attack surface coverage

Reported by WELL Health’s CISO, within the same budget. Customer statement, June 2026.

A machine that must ask permission

Terra’s architecture divides the labor. Ambient agents handle background work such as reconnaissance, code review, test generation and exploit validation. Copilot agents take direction from a pentester investigating a particular target or sensitive question. TORCH, the Terra Offensive Research Collaboration Hub, is the desktop application where that direction and supervision happen.

This distinction answers an uncomfortable question. An AI authorized to investigate a production application might also be capable of disrupting it. Terra says its guardrails separate permitted actions, actions requiring explicit human approval, and forbidden actions. Permissions sit outside the model. Actions and human decisions are logged. The platform’s ambition depends on those boundaries holding during execution.

“The future of pentesting isn’t autonomous versus human.”

Shahar Peled, co-founder and CEO · March 2026

The result is a service for security teams that want more testing without giving an agent unlimited discretion. Terra emphasizes application workflows, authentication and business context. Those details matter because a technically ordinary action can become dangerous when performed by the wrong user, against the wrong account, in the wrong sequence.

How a suspicion becomes a repair
  1. 01Map changes
  2. 02Test an attack path
  3. 03Validate evidence
  4. 04Fix and retest
Human oversight governs sensitive decisions across the workflow
Permission before consequence. A conceptual view of the workflow, not a performance chart.

Sell the work, keep the responsibility

Founded in 2024 by CEO Shahar Peled and CTO Gal Malachi, Terra sells continuous testing through annual subscriptions. In a January 2026 founder interview, Peled described targeting existing outsourced testing budgets. He reported reaching $1 million in annual recurring revenue roughly one quarter after launching the continuous product. That is a historical founder claim, not a statement of current revenue.

The commercial idea is easy to grasp: buy a testing outcome rather than staff every repetitive task yourself. Today, Terra offers its own pentesters, supports internal teams, and markets a partner program to security service providers. Buyers can consider it alongside autonomous offensive platforms such as XBOW, expert-led providers such as Cobalt, or their existing consultancy.

Terra’s distinction is the combination of continuous execution, business context and accountable human control. Riskified’s published case study makes the buyer’s tension explicit: increasing testing depth while retaining reviewed, signed reports and oversight suitable for audit processes. The human remains part of the deliverable. Software expands the work that person can oversee.

Terra team members wearing orange company shirts on an outdoor terrace
The humans are still in the picture. Terra’s team in a company press photograph. The orange shirts make supervision easier to spot.

The attack does not respect your org chart

Terra announced an $8 million seed round in April 2025, followed by a $30 million Series A led by Felicis that September. The company put total funding at $38 million. It also won the 2025 AWS and CrowdStrike cybersecurity accelerator, presented with NVIDIA Inception. The funding announcement identified broader attack coverage as a priority.

The subsequent releases follow that plan. External network validation entered public preview in May 2026. An internal network testing waitlist opened in July. The current platform presents web applications, AI systems and networks together. The logic is straightforward: an attacker may begin at an exposed service and continue through an application or identity weakness. Separate reports can obscure the connection.

Terra also researches the agents themselves. Its researchers disclosed CVE-2026-25724, a Claude Code permission bypass involving symbolic links. The company’s account says Anthropic fixed the issue in version 2.1.7 and later. A tool intended to inspect a repository could follow a link to restricted information. Delegating investigation makes the investigator’s permissions worth investigating too.

Buying time for the fix

Discovery does not immediately produce a repair. Engineering teams have release schedules and approval processes. In August 2026, Terra launched Prevention to address that interval: test whether existing controls block a confirmed exploit, then generate and validate a specific WAF or firewall rule where they do not. A security team implements the control, with human governance for sensitive changes.

This is temporary protection while permanent remediation proceeds. Its usefulness depends on the control matching the actual attack path and being deployable in the customer’s environment. A successful blocking rule still leaves the underlying defect to fix. Otherwise, a helpful interim measure becomes a rather permanent guest.

The useful thing to copy

The practical lesson is to demand a chain of evidence: authorized scope, a reproducible finding, business impact, a named repair owner and a retest. Before expanding continuous testing, decide which actions require approval and where code and findings may travel. Terra documents shared SaaS, customer-controlled cloud and isolated deployment options, plus customer-supplied models.

The economics depend on how much manual effort those choices remove. Continuous testing helps most when applications change frequently and teams can act on results. Poor access, thin context or an unattended remediation queue can limit its value. Faster discovery needs someone available to make the next decision. Paterson’s experience suggests the scarce resource is that person’s attention.