Skip to main content

All you need is a URL

No code access. No configuration. No browser plugins. Paste your app URL and Perfai’s agents handle everything — account creation, role discovery, app mapping, and security testing — completely on their own.
Perfai — Test a new app
Hit the arrow button and three agents run in sequence:

01 — Vision Agent

Maps every workflow, API, role & data in minutes.

02 — Security Agent

Runs thousands of custom security tests across roles & tenants.

03 — Fix Agent

Generates & verifies precise fixes via Cursor, Claude & Replit.

What happens step by step

1

Confirm and start

After you paste your URL, Perfai shows a New app setup confirmation with the four tasks it will run automatically:
New app setup — task confirmation modal
Click Continue. You don’t need to configure anything else.
One-time tasks run once to bootstrap your test environment. Continuous tasks re-run automatically on every future scheduled scan as your app evolves.
2

Vision Agent builds the task graph

The Vision tab opens showing the full agent execution plan. Each node in the graph is a task the Vision Agent will complete — in order — before handing off to the Security Agent.
Vision Agent task graph — account creation and role discovery
The right panel renders the live task graph:
The left panel logs every action in real time:
The agent asks one question first: would you like it to auto-sign up accounts using your app URL? Answer Yes for fully automated account creation, provide credentials manually, or skip and add them later. Yes is the right answer for most apps.
3

Vision Agent maps your entire application

With test accounts created and roles confirmed, the Vision Agent takes control of a cloud browser and explores your entire app — clicking through every screen, submitting forms, and recording every API call made along the way.
Vision Agent mapping the application — live browser stream
Watch the live browser stream as it autonomously navigates your app in real time. The left panel tracks every step:
The result is a complete attack surface map — every UI workflow, API endpoint, role permission, and sensitive data type documented automatically.
4

Security Agent runs and results appear

When mapping completes, the Security Agent immediately begins running permission tests across all discovered endpoints. No trigger needed.
When done, switch to the Overview tab to see your full results:
Perfai Overview — security results dashboard
Security Risk shows confirmed findings:Attack Surface shows what was covered:Click any finding to see the affected endpoint, attacking role, expected vs. actual response, and a reproduction step you can run immediately. Click Actions → Generate Reports to export your full security report.
5

Drill into the Security tab for detailed findings

Switch from Overview to the Security tab for the full issues list — every confirmed vulnerability for this specific app, sorted by severity.
Perfai Security tab — per-app issues list with CVSS scores and savings
The three headline cards summarize your exposure for this app:The issues table shows 66 total findings with full detail per row:Use the All Runs / Coverage / AI Logs / Last Run / Errors tabs to dig deeper into test coverage, the agent’s reasoning, and any test execution errors.
The Security tab is scoped to one app. The global Issues page aggregates findings across your entire portfolio — useful for org-wide risk reviews and compliance reporting.

Runs automatically from here

Once registered, Perfai keeps testing your app on a continuous schedule — visible at the top of every app dashboard (Next: Nightly). No manual trigger needed.

Next Steps

Core Concepts

Understand how Perfai models apps, workflows, roles, and issues.

Understanding Issues

Learn how findings are classified, prioritized, and tracked to resolution.