Mattia Dalla Piazza, Zoran Gorgiev
Table of contents #
Equixly was named an IDC Innovator in IDC Innovators: Autonomous Penetration Testing for DevSecOps, 2026 (IDC #US54175326, July 2026).
The recognition comes as the application attack surface itself is changing. Modern products increasingly span web applications, APIs, LLM-powered features, and MCP servers: distinct surfaces that often operate as parts of the same system. Attackers do not treat them in isolation, and effective testing cannot either.
That approach is reflected in IDC’s assessment of Equixly:
“Equixly’s model is purpose-built to simulate how attackers actually probe and exploit applications. It is trained on offensive security techniques, such as attack patterns, exploit chains, authorization failures, business logic abuse, and API interaction sequences.”
For Equixly, the recognition marks a milestone in a direction the company has been building toward from the start: continuous offensive testing that can keep pace with applications and attackers as they change.
What Equixly tests #
Modern software is not one surface. A web front end, the APIs behind it, an LLM feature, and an MCP server can all belong to the same product now, and an attacker moves between them freely.
Equixly tests across that whole range:
Surfaces: It probes single-page and server-rendered web applications; REST, GraphQL, and SOAP APIs; genAI and LLM applications; and the MCP servers through which agents reach real tools and data.Visibility: The platform provides a live picture of endpoints, parameters, services, and dependencies, with depth coming from the relationships between them.Autonomous exploitation: Equixly’s offensive agentic workflows pursue a goal over many steps, which is how the platform exposes authorization gaps, privilege escalation, and logic abuse: weaknesses in how the application enforces permissions and business rules.Validation: Every finding arrives with the path that produced it, and Equixly retests remediations until it confirms the path is closed.
These targets keep changing, so Equixly keeps testing them. It does not assess applications once and move on.
Running this model costs your environment very little. Equixly installs no agents and needs no access to source code. Tests can fire from a CI/CD pipeline, and findings can flow into the vulnerability management system a team already uses.
The platform also connects to application security platforms, such as Checkmarx, which pairs code analysis with continuous offensive validation of the running system. Reports map to OWASP, ASVS, PCI DSS, PSD2, and ISO 27001.
Together, these are the properties that let continuous autonomous penetration testing sit inside a DevSecOps workflow instead of running beside it.
Autonomy that stays inside its limits #
An autonomous adversary operating in your own estate is only an asset if you can account for what it did. Equixly answers that requirement in three ways:
The operators set the boundaries. Scope, maximum depth, duration, and rate limiting are configured per project. Equixly then paces itself within those settings, easing off when a target pushes back instead of forcing its way through.Every finding carries the path that produced it. That path is reproducible, so it also serves as a record of what the platform attempted and what it demonstrated.The offensive model is built in-house and runs on Equixly’s own infrastructure. Endpoints, traffic, and findings therefore stay inside that boundary, and testing does not depend on an external provider’s policies.
Closing thoughts #
Software changes faster than the practices meant to validate it.
That gap becomes more important as applications extend beyond traditional web and API architectures into LLM features, agentic workflows, and MCP-connected systems.
Equixly was built for that condition. It runs continuously against LLM features, MCP servers, web applications, and APIs. It shows what is exploitable, confirms that fixes hold, and works within the limits its operators set.
Being named an IDC Innovator is recognition of that approach and of a model of penetration testing designed to operate continuously across the application surfaces modern teams are now responsible for.
See what continuous autonomous penetration testing finds in your environment. Book a demo.
Disclaimer
IDC Innovators: Autonomous Penetration Testing for DevSecOps, 2026 (IDC #US54175326, July 2026).
IDC Innovators publications highlight emerging vendors in a technology market. IDC does not endorse any vendor, product, or service, and inclusion is not a ranking. The views expressed in this article are those of Equixly and not those of IDC.
[
]
Mattia Dalla Piazza
CEO & FOUNDER
Mattia's fascination with cybersecurity began in the early 2000s during his school days when he discovered vulnerabilities in school systems. With over 15 years in the Information Technology domain, he has built a notable career that includes leadership roles, such as heading a System Engineering Centre of Excellence for UniCredit Bank and being an International IT Manager at IBM. Mattia's expertise also extended to a NASDAQ-listed company, where he oversaw the management of its data centers as a System Engineer. Mattia is well-known for his ability in information network design, security, and infrastructure architecture. His robust problem-solving skills and forward-thinking vision underscore his commitment to enhancing service efficiency and fortifying his clients' security posture.
[
]
Zoran Gorgiev
Technical Content Specialist
Zoran is a technical content specialist with SEO mastery and practical cybersecurity and web technologies knowledge. He has rich international experience in content and product marketing, helping both small companies and large corporations implement effective content strategies and attain their marketing objectives. He applies his philosophical background to his writing to create intellectually stimulating content. Zoran is an avid learner who believes in continuous learning and never-ending skill polishing.