Ridge Security has announced that it has been named an IDC Innovator in the IDC Innovators: Autonomous Penetration Testing for DevSecOps, 2026 report. The recognition highlights Ridge Security's agentic autonomous penetration testing platform, RidgeGen, which uses stateful, multi-agent architecture to preserve context through assessments and adapt testing strategies as new evidence emerges.
Ridge Security named an IDC Innovator for agentic autonomous penetration testing in the 2026 IDC Innovators report.
RidgeGen uses a stateful, multi-agent architecture designed to preserve context through an assessment and adapt testing strategies.
The platform reasons beyond CVE-based detection to understand business logic, application workflows, and attack paths.
Key capabilities include agentic reasoning, stateful context-aware testing, multi-agent orchestration, and autonomous exploit validation.
Customers can define objectives, testing boundaries, AI models, and agents for governance and flexibility.
Ridge Security serves enterprises worldwide across financial services, government, telecommunications, and other critical industries.
Ridge Security today announced that it has been named an IDC Innovator in the IDC Innovators: Autonomous Penetration Testing for DevSecOps, 2026 (doc # US54175326, July 2026) report.
As modern applications become increasingly distributed, API-driven, cloud-native, and frequently updated, security teams face a fundamental challenge: traditional penetration testing cannot always keep pace with the speed of modern software development. While periodic assessments remain valuable, they often leave organizations with gaps between testing cycles or generate large volumes of findings without proving whether vulnerabilities can actually be exploited.
Agentic autonomous penetration testing addresses this challenge by enabling AI agents to reason, plan, and adapt throughout an assessment. Rather than executing a predefined sequence of tests, agentic systems establish objectives, formulate hypotheses, validate attack paths, and continuously adjust their strategy as new evidence emerges.
Ridge Security's RidgeGen applies this through a stateful, multi-agent architecture designed to preserve context through an assessment. As agents uncover new information about an application or environment, the platform adapts its testing strategy, pursues deeper attack paths, and validates how multiple weaknesses can be chained into meaningful exploits.
"Agentic AI changes the equation for penetration testing because the technology is no longer limited to executing a fixed catalog," said Lydia Zhang, President and Co-Founder of Ridge Security. "RidgeGen is designed to reason beyond CVE-based detection. It understands business logic, application workflows, and attack paths to uncover risks that traditional automated tools often miss, significantly reducing false negatives."
"Running more security tests isn't enough," said Nick Mo, CEO and Co-Founder of Ridge Security. "The real challenge is understanding what each discovery means and deciding what to investigate next. RidgeGen's stateful, multi-agent architecture continuously builds on what it learns, making autonomous penetration testing more intelligent, targeted, and effective."
Agentic reasoning that enables autonomous decision-making throughout penetration testing
Stateful, context-aware testing that preserves knowledge gathered during an assessment
Multi-agent orchestration for discovering, validating, and chaining exploitable risks
Adaptive testing that changes strategy based on application behavior and newly discovered evidence
Autonomous exploit validation that distinguishes confirmed exploitable risk from theoretical findings
Customer-defined objectives, testing boundaries, AI models, and agents for governance and flexibility
The IDC Innovators report profiles seven vendors operating in autonomous penetration testing for DevSecOps. Unlike traditional automated testing, which executes predefined security checks, agentic systems continuously reason about the environment, determine which attack paths to pursue, and adjust based on what they learn.
About Ridge Security
Ridge Security empowers CISOs to build cyber resilience through AI-native continuous offensive security. By helping organizations continuously validate their security posture, focus on proven cyber risks, and accelerate remediation, Ridge Security enables security teams to stay ahead of evolving threats while maximizing the effectiveness of their existing security investments. Recognized by Gartner, IDC and Frost & Sullivan, Ridge Security serves enterprises worldwide across financial services, government, telecommunications, and other critical industries.