# Security Arsenal > Security Arsenal is a Dallas, TX-based managed cybersecurity firm providing human-led AI penetration testing, 24/7 Managed SOC, MDR, Incident Response, and the AlertMonitor SIEM platform to businesses across the United States and internationally. ## Organization - Name: Security Arsenal - Type: Professional cybersecurity services firm - Founded: 2000 - Headquarters: Dallas, Texas, USA - Phone: +1-972-999-9900 - Website: https://securityarsenal.com ## What makes Security Arsenal different Security Arsenal delivers **human-led AI penetration testing**. Instead of one or two consultants working sequentially through a fixed hour budget, a supervised swarm of specialized AI agents works the target in parallel — reconnaissance, exploitation, business logic auditing, and (where scoped) original zero-day vulnerability research. An experienced penetration tester is at the controls throughout — not reviewing output at the end, but steering the swarm while it works: redirecting agents onto promising leads, deepening what looks interesting, and pushing it well past where a playbook would stop. That live direction is a capability upgrade rather than a quality-control step, and it is consistently where the findings that matter come from. The practical differences versus a traditional engagement: broader coverage (every endpoint, parameter and workflow rather than a sample), results in days rather than weeks, business logic and novel vulnerabilities that signature-based scanners structurally cannot find, and a remediation retest included rather than billed separately. There is a single engagement tier. Every penetration test is human-led SwarmPT; there is no cheaper unsupervised option, and the price includes the report, the retest, and a 90-day Protection Window afterwards. The earlier AutoPT automated-testing product was retired in August 2026 — SwarmPT supersedes it on speed, depth and accuracy. Measured results from a twelve-site program (August 2026): 84 findings reported, resolving to 76 distinct remediation tasks — 8 critical, 21 high, 47 medium. Median 39 minutes per target from start to a finished report, range 12 minutes to 2h57m, 11h27m total across all twelve including report generation. Every target sat behind a commercial web application firewall in blocking mode; a control CVE scan run beforehand was detected and blocked, and the real engagement was never blocked on any of the twelve. ## Penetration Testing - [Penetration Testing](https://securityarsenal.com/services/penetration-testing): Web application, external and internal network, API, and cloud penetration testing. Ranked findings with proof-of-concept evidence, remediation guidance, compliance-mapped reporting, and retest included. - [AI Penetration Testing](https://securityarsenal.com/services/ai-penetration-testing): The human-led AI agent swarm in detail — agent roles, engagement workflow, safety controls (signed Rules of Engagement, isolated sandbox per engagement, encrypted credential handling, human kill switch), and how it compares to scanners and traditional consultancy engagements. - [Penetration Testing Cost](https://securityarsenal.com/services/penetration-testing/cost): What a penetration test actually costs, broken down by scope, and what drives the price up or down. - [Sample Penetration Test Report](https://securityarsenal.com/services/penetration-testing/sample-report): A real, unedited 23-page penetration test report available as a free PDF with no email gate — 7 confirmed findings, CVSS 3.1 scores and vectors, CWE classification, working proof-of-concept code for each finding, and specific remediation. The target is a business that has since closed, retained deliberately so a genuine report can be published without exposing a live client. - [Penetration Testing Results](https://securityarsenal.com/services/penetration-testing/results): Real measured results from a twelve-site program, including the control experiment showing a commercial WAF blocking an ordinary CVE scan while never detecting the actual engagement, the severity distribution and why its shape indicates proven rather than matched findings, per-target timings, and the cross-target attack path analysis. - [Sentinel](https://securityarsenal.com/products/alertmonitor/sentinel): Blocking configured from confirmed penetration test findings rather than generic signatures, so it recognizes the exact request that succeeded. Blocks apply across every protected host rather than only the one that saw the traffic, and each detection triggers a forensic investigation that closes its own case when nothing got through. Included free for 90 days with every engagement. - [Red Teaming](https://securityarsenal.com/services/red-teaming): Unannounced adversary emulation — the client authorizes once and the engagement occurs at an undisclosed point in the following twelve months, because a scheduled test measures defenses only under the one condition that never occurs in a real attack. Includes OSINT-driven social engineering and physical entry testing, under a contractual term that no employee may be disciplined or dismissed as a result. - [Red Teaming](https://securityarsenal.com/services/red-teaming): Objective-based adversary simulation across people, process and technology. ### Penetration Testing Buyer Guides Accurate, framework-by-framework answers — including where a framework does NOT actually mandate penetration testing, which most vendor pages get wrong. - [Penetration Testing vs Vulnerability Scanning](https://securityarsenal.com/services/penetration-testing/penetration-testing-vs-vulnerability-scanning): A scan matches known signatures; a test attempts exploitation and proves impact. Includes how to identify a "penetration test" that is really an automated scan. - [SOC 2 Penetration Testing](https://securityarsenal.com/services/penetration-testing/soc-2-penetration-testing): SOC 2 does NOT explicitly require a penetration test — the Trust Services Criteria never name it — but auditors expect one as evidence for the risk-assessment and monitoring criteria. Covers scope, timing around the observation window, and deliverable requirements. - [PCI DSS Penetration Testing (Requirement 11.4)](https://securityarsenal.com/services/penetration-testing/pci-dss-penetration-testing): PCI DSS explicitly requires internal and external penetration testing at least every 12 months and after significant change, plus separate segmentation testing (annually for merchants, every six months for service providers). Vulnerability scanning under Requirement 11.3 does not satisfy 11.4. - [HIPAA Penetration Testing](https://securityarsenal.com/services/penetration-testing/hipaa-penetration-testing): The HIPAA Security Rule does NOT name penetration testing. It requires a thorough and accurate risk analysis and a periodic technical evaluation of safeguards — which is why covered entities and business associates test. - [How to Prepare for a Penetration Test](https://securityarsenal.com/services/penetration-testing/how-to-prepare-for-a-penetration-test): Scoping, credentials, rules of engagement, who to inform internally, and what to do once the report arrives. ## Certification — SA-APEX Security Arsenal's promise for the program, in their own words: "We prove what you can do. So clients can trust what you say." APEX — the Advanced Penetration Engineering Expert, awarded by Security Arsenal, with credential identifiers and the URL slug using the code SA-APEX — is a performance certification for experienced penetration engineers who use AI on authorized client work. It is NOT a beginner penetration-testing course and NOT a credential about attacking AI systems — it measures an engineer using AI to test everything else, safely. It is deliberately open to practitioners at firms that compete with Security Arsenal, because the client carries the risk when an AI-assisted test is wrong. The structure that distinguishes it: the candidate BUILDS a full enterprise infrastructure (AWS, Azure, VMware, Proxmox, BGP, OSPF, SDN, VPN, firewall, Cloudflare, CDN, Windows, Linux, macOS, managed Apple and Android devices, and VoIP), then BUILDS their own AI testing tooling from a bare Kali server and a single AI API token, then ATTACKS infrastructure built by a different candidate — never their own. Security Arsenal's own swarm then attacks the infrastructure they built while they defend it live. Two of the seven phases run with generative AI disabled entirely. - [SA-APEX Certification](https://securityarsenal.com/certifications/sa-apex): Program overview — what the credential proves, what it explicitly does not, the four promises (manual mastery, safe AI engineering, novel discovery, defensible truth), and the public-standard/private-product boundary that keeps SwarmPT intellectual property out of the certification. - [What It Means For Clients](https://securityarsenal.com/certifications/sa-apex/what-it-means): Written for the person buying the penetration test, not the candidate. What an SA-APEX credential establishes about an engineer: that they can do the engagement with generative AI switched off, that they can build the infrastructure they are attacking, that client data does not reach an unapproved model, that every finding survived independent reproduction, and that the report states what was NOT tested. Also carries five questions any buyer can put to any tester, certified or not — including what AI was used, what it saw, and whether there is a log of what was sent to it. - [Can AI replace a penetration tester?](https://securityarsenal.com/certifications/sa-apex/what-it-means): Security Arsenal's position: not yet. AI tooling makes it possible to hand a penetration test to somebody who has never run one — point the right setup at a network and findings, severities and a report come out. That is a result, not a test. The years are what tell an engineer which attack path is worth pulling on, what is only suspicious if you know how a technology is normally deployed, and what is absent. Used properly by an experienced engineer, AI means they miss considerably LESS, because they cover volume no human could work through unaided while still supplying the judgment. Until something genuinely replaces an engineer, human-led testing has to be the standard. - [Build and Break](https://securityarsenal.com/certifications/sa-apex/build-and-break): The core exam structure. You cannot break what you cannot build. Covers every required infrastructure component, how cross-candidate target assignment is kept fair (build conformance gate, post-acceptance defect seeding, anonymous platform-controlled assignment, a reference infrastructure pool for solo candidates), and why builds are scored on conformance and comprehension rather than on how hard they are to break. - [The Performance Exam](https://securityarsenal.com/certifications/sa-apex/exam): Seven phases — manual foundation (AI disabled), build the infrastructure, defend it while Security Arsenal's swarm attacks it, build your own tooling from a bare Kali server and one API token, attack infrastructure you did not build, evidence-locked reporting, and a live oral defense (AI disabled). The defense phase is not scored on whether the swarm gets in — a determined adversary with time gets in — but on whether the candidate saw it, understood it, responded proportionately, and can account afterwards for which design decisions held and which did not. Includes the competency domains and weights, the non-compensable manual gate, and the seven immediate fail conditions. - [The OSEE Bridge](https://securityarsenal.com/certifications/sa-apex/osee-bridge): An active OSEE (OffSec EXP-401, Advanced Windows Exploitation) satisfies the SA-APEX manual foundation gate and waives that phase only. It does NOT waive the build phase, the VoIP requirement, the software development requirement, or any AI phase. This is Security Arsenal's own admissions decision and is not a partnership, endorsement or affiliation with OffSec. - [Prerequisites](https://securityarsenal.com/certifications/sa-apex/requirements): Admission evidence — documented authorized offensive work, three languages spanning scripting/systems/application development, hands-on infrastructure administration, engagement ownership, code reasoning, and professional conduct. Includes the readiness gates and the immediate fail conditions. - [Eligibility Check](https://securityarsenal.com/certifications/sa-apex/eligibility): A thirteen-question self-assessment that runs entirely in the browser. No email gate, nothing submitted, and it is capable of returning "not the intended level". - [Client-Data Protection Standard](https://securityarsenal.com/certifications/sa-apex/data-protection): Default-deny data policy, five data classes with permitted AI destinations, eleven required controls, and the six adversarial leakage tests every candidate builds and passes (cross-tenant retrieval, canary, prompt-injection exfiltration, tool boundary, retention verification, provider failover). - [The Evidence Standard](https://securityarsenal.com/certifications/sa-apex/validation): Working code, or it is not a finding. Every issue submitted in the SA-APEX exam carries an executable proof of concept the candidate wrote, that a reviewer independently runs in a clean environment and that visibly crosses the claimed security boundary — not a description, a screenshot, a CVSS score, a copied request, or model-generated exploit code the candidate cannot explain. Also covers How false positives are controlled — the finding state machine, the twelve-field validation packet, independent replay, coverage obligations, and the seven evaluation metrics. AI confidence is not evidence, and model agreement is not independent confirmation. - [Policies and Candidate Rights](https://securityarsenal.com/certifications/sa-apex/policies): Code of ethics, exam rules, anonymized grading, appeals independent of the original decision, credential lifecycle, accommodations, and published data retention. - [Open Decisions](https://securityarsenal.com/certifications/sa-apex/decisions): The published log of what has NOT been decided yet — exam length, pass standard, price, credential term, proctoring model and accreditation. Design targets are not presented as settled numbers. - [Apply](https://securityarsenal.com/certifications/sa-apex/apply): Application form. No payment is taken and no account is created at application time; eligibility is reviewed by a person first. - [Security AI Engineering Course](https://securityarsenal.com/training/security-ai-engineering): The prerequisite curriculum — twelve modules, each with a required lab artifact, covering private model routes, secure model gateways, agent and tool design, retrieval isolation, false-positive engineering, coverage accounting and AI-assisted reporting. Course completion is explicitly NOT certification. - [SA-APEX for Teams](https://securityarsenal.com/enterprise/sa-apex): Team qualification and private cohorts, open to internal security teams, consultancies and competing testing firms, with no exposure of SwarmPT intellectual property. - [Who May Direct SwarmPT](https://securityarsenal.com/swarmpt/engineer-standard): Why the public credential and the internal SwarmPT Lead Authorization are separate things. Passing the exam grants no product access and no permission to operate on a client. - [Verify a Credential](https://securityarsenal.com/verify): Public credential verification. Requires BOTH the holder's name and their credential number — a number alone returns nothing, so the registry confirms what a verifier already knows and cannot be scraped into a directory of certified engineers. ## Other Services - [Managed SOC](https://securityarsenal.com/services/managed-soc): 24/7 Security Operations Center staffed by certified analysts. Continuous threat monitoring, alert triage, and escalation. - [Managed Detection and Response (MDR)](https://securityarsenal.com/services/mdr): Active threat hunting, endpoint telemetry analysis, and rapid containment. - [Incident Response](https://securityarsenal.com/services/incident-response): Emergency breach containment, forensics, recovery, and post-incident reporting. - [Incident Response Retainer](https://securityarsenal.com/services/incident-response-retainer): Pre-negotiated IR retainer ensuring guaranteed SLA response times. - [Security Audits](https://securityarsenal.com/services/security-audits): Gap analysis against NIST CSF, CIS Controls, PCI-DSS, HIPAA, and SOC 2. - [Managed Security](https://securityarsenal.com/services/managed-security): Ongoing managed security program for SMBs without an internal security team. - [Physical Security Testing](https://securityarsenal.com/services/physical-security): On-site physical penetration testing and social engineering. - [APT Defense](https://securityarsenal.com/services/apt): Advanced persistent threat detection and response. ## Products - [AlertMonitor](https://securityarsenal.com/products/alertmonitor): AI-augmented SIEM and alert triage platform. Reduces false positives, integrates with existing EDR/SIEM tools, and provides real-time analyst dashboards. - [AI Incident Engine](https://securityarsenal.com/products/alertmonitor/ai-incident-engine) - [Alert Triage](https://securityarsenal.com/products/alertmonitor/alert-triage) - [Security Validation](https://securityarsenal.com/products/alertmonitor/security-validation): Nightly CVE and supply-chain scanning across every managed device. - [Supply Chain Monitoring](https://securityarsenal.com/products/alertmonitor/features/supply-chain) - [AWS Health Monitoring](https://securityarsenal.com/products/alertmonitor/features/aws-health) - [AI Forensics](https://securityarsenal.com/products/alertmonitor/features/forensics) - [Network Mapping](https://securityarsenal.com/products/alertmonitor/network-mapping) - [Website Monitoring](https://securityarsenal.com/products/alertmonitor/website-monitoring) - [Software Monitoring](https://securityarsenal.com/products/alertmonitor/software-monitoring) - [Automation](https://securityarsenal.com/products/alertmonitor/automation) - [Phishing Outlook Add-in](https://securityarsenal.com/products/alertmonitor/phishing) - [Global Search](https://securityarsenal.com/products/alertmonitor/global-search) - [Help Desk](https://securityarsenal.com/products/alertmonitor/help-desk) - [One Time Share](https://securityarsenal.com/products/alertmonitor/one-time-share) - [HoneyBadger](https://securityarsenal.com/products/honeybadger): Digital tripwires that fire the moment an attacker touches a decoy file. - [Arsenal Shield](https://securityarsenal.com/products/arsenal-shield): No-logging VPN for staff, free for customers. - [Arsenal Tunnel](https://securityarsenal.com/products/arsenal-tunnel): Granular zero-trust access — one device, one port, one time window. - [Stop The Hacker](https://securityarsenal.com/products/stop-the-hacker): Free security awareness education game. ## Industries Served - [Healthcare Cybersecurity](https://securityarsenal.com/industries/healthcare): HIPAA-compliant SOC monitoring, ransomware protection, and EHR security for hospitals and clinics. - [HIPAA Security Monitoring](https://securityarsenal.com/industries/healthcare/hipaa-security-monitoring) - [Healthcare Incident Response](https://securityarsenal.com/industries/healthcare/incident-response) ## Locations Security Arsenal is headquartered in Dallas, Texas and delivers testing and monitoring remotely across the United States, Canada, Latin America, Europe, the Middle East and Asia-Pacific. There is no local price premium — an engagement is priced by scope, not postcode. - [All Locations](https://securityarsenal.com/locations): Index of every metro area served. - [Dallas-Fort Worth (DFW)](https://securityarsenal.com/locations/dfw): Primary service area. On-site IR and assessments available. - Per-city penetration testing pages follow the pattern `https://securityarsenal.com/locations/{city-slug}/penetration-testing` — for example [Dallas](https://securityarsenal.com/locations/dallas/penetration-testing), [Houston](https://securityarsenal.com/locations/houston/penetration-testing), [New York City](https://securityarsenal.com/locations/new-york/penetration-testing), [Chicago](https://securityarsenal.com/locations/chicago/penetration-testing), [Los Angeles](https://securityarsenal.com/locations/los-angeles/penetration-testing), [Atlanta](https://securityarsenal.com/locations/atlanta/penetration-testing), [London](https://securityarsenal.com/locations/london/penetration-testing). ## Threat Intelligence & Blog - [Security Blog](https://securityarsenal.com/blog): Daily cybersecurity news with Sigma rules, KQL hunt queries, Velociraptor VQL, and defender remediation guides. - [Intel Hub](https://securityarsenal.com/hub): Curated threat intelligence resources organized by security domain. - [From The Dark Side](https://securityarsenal.com/darkside): Underground intel — ransomware gangs, credential markets, dark web threats. - [Managed SOC Intel](https://securityarsenal.com/intel/managed-soc) - [MDR Intel](https://securityarsenal.com/intel/mdr) - [Incident Response Intel](https://securityarsenal.com/intel/incident-response) - [Healthcare Security Intel](https://securityarsenal.com/intel/healthcare-security) - [Alert Fatigue Intel](https://securityarsenal.com/intel/alert-fatigue) - [RSS Feed](https://securityarsenal.com/feed.xml) ## Key Topics Covered - AI penetration testing and agentic offensive security - Penetration testing methodologies (web, network, API, cloud, physical) - Zero-day vulnerability research and coordinated disclosure - Red teaming and adversary simulation - Managed Security Operations Center (SOC) - Managed Detection and Response (MDR) - Security Information and Event Management (SIEM) - Extended Detection and Response (XDR) - Endpoint Detection and Response (EDR) - Threat Hunting and Detection Engineering - Sigma Rules, KQL, Velociraptor VQL - MITRE ATT&CK framework - CVE vulnerability analysis and remediation - Ransomware defense and recovery - HIPAA, PCI-DSS, SOC 2, NIST CSF compliance - Digital Forensics and Incident Response (DFIR) - Dark web monitoring and credential exposure alerts - Certification of AI-assisted penetration testing practitioners - Secure AI architecture for offensive security engagements - Preventing client data leakage to language models during security testing - Evidence standards and false-positive control in AI-assisted testing - Novel (non-CVE) vulnerability discovery through code audit - Enterprise infrastructure engineering as a prerequisite for offensive testing ## Pricing - [Pricing Overview](https://securityarsenal.com/pricing) - [Penetration Testing Cost](https://securityarsenal.com/services/penetration-testing/cost) ## Contact & Engagement - [Contact](https://securityarsenal.com/contact) - [Client Portal](https://securityarsenal.com/portal) - [Sign Documents](https://securityarsenal.com/sign) - Phone: +1-972-999-9900 ## Social - LinkedIn: https://www.linkedin.com/in/securityarsenal - X (Twitter): https://x.com/SecurityAr58409