AI validation
What the agent does, what it costs, how to set ceilings.
Umbra’s AI agent runs real exploitability checks against your services and writes one-page proofs you can hand to the team that needs to fix the issue. This page is what it does, what it costs, and how to keep spend predictable.
What the agent actually does
For each CVE you click Verify on, the agent:
- Pulls every public CVE record + advisory + exploit-DB entry it can reach.
- Builds a working hypothesis: “to exploit CVE-X against this service, send this kind of request and look for this kind of response.”
- Issues a small number of non-destructive test requests against your service (no data modification, no auth abuse, no DoS, just the minimum signal needed to confirm exploitability).
- Writes one of three verdicts:
- exploitable: chain reproduced, here’s the proof
- not exploitable: chain attempted, here’s why it failed (often: “service is patched”, “behind WAF”, “wrong version”)
- inconclusive: couldn’t determine safely; manual review needed
The full transcript (every tool call, every response sniffed) is saved in the run record so you can audit what the agent did. Verdicts come with a markdown proof you can paste into Jira.
What it costs
One Check, whatever the run does:
- Per-CVE validation — 1 Check
- Full-agent run (point the agent at a service with no specific CVE and let it discover what it can) — 1 Check
- Re-testing a finding Umbra already reported — free, and never counted
Each paid plan includes a monthly allowance of Checks. One Check is one verification — proving a service is exploitable, or that a reported CVE is real.
| Tier | Checks / month |
|---|---|
| Starter | 15 |
| Essential | 50 |
| Standard | 200 |
| Scale | 600 |
| Enterprise | negotiated |
Checks reset at billing-cycle close (use-it-or-lose-it). Re-testing a finding Umbra already reported to you is always free and never counted.
When you run out
Checks reset at the close of each billing month, and the app shows the reset date. If you need more before then, moving up a plan raises the allowance immediately.
Deep Audit is counted separately, in Audits — one Audit per scan, whatever the size of the application, with up to ten related backends included.
What the agent will not do
- Modify data: no PUT/POST/DELETE on real customer endpoints unless explicitly opted in per-target.
- Test credentials brute-force: no login attempts; that’s a
separate
the detection ruleset default-credsworkflow that lives outside the AI budget. - Resource abuse: no DoS, no traffic flooding, no API quota burn. A run that requires that gets reported as “manual review needed” instead.
Disabling AI entirely
If your security policy forbids LLM-assisted testing, the agent can be disabled for the entire org from Settings → AI → Disable AI. The Verify button disappears from the Findings page; all other Umbra functionality continues to work.