I lead how Ingram uses Strix, an open source AI pentesting CLI that runs full recon-to-PoC scans inside a sandboxed container. Built an MCP + REST layer on top so we could offer it as a hosted scanning product (tiers, API keys, Stripe billing), and set up the workflow where manual pentest findings get fed back in for the agent to independently confirm - one run turned close to 30 whitebox findings into a dozen confirmed, reproducible vulns with evidence attached.

Various blog posts on the security of web applications and pentests, made in collaboration with Dan:
https://ingram.tech/posts/ai-pentesting-in-the-wild
https://ingram.tech/posts/ai-pentesting-what-i-found
https://ingram.tech/posts/making-vibe-coded-apps-production-ready