Estimated reading time: 9 minutes
Terra Security announced on July 21 that continuous agentic internal network pentesting is in preview with selected design partners. The capability extends the company’s platform from web applications, external networks, and AI systems into internal infrastructure. Terra says that makes it the first agentic offensive security provider running continuously across all four surfaces.
The claim is worth stating precisely. The internal network capability is in limited preview, not general availability, with a waitlist open. The “first across four surfaces” line rests on a product customers cannot yet buy.
Chief Executive Officer and Co-Founder Shahar Peled framed the expansion as a gap in industry practice. “Attackers do not stop at the perimeter, and neither should Offensive Security,” he said. He added enterprises can now answer a question that matters more than a vulnerability count: “If adversaries attack me today, what can they achieve?”
Why The Internal Network Went Untested
Terra’s case for the expansion is operational. Traditional internal testing often requires staff on site or persistent virtual private network access. It needs scoping negotiations and a fixed test window. The result is a snapshot of an environment that has already changed.
The company argues that infrastructure-as-code, continuous integration pipelines, and AI tooling now reshape internal topology faster than annual assessments can track. That argument is not controversial. It is the same pressure CINI covered in Contrast Security’s CVE Shield launch, where AI systems convert public vulnerabilities into working exploits faster than teams can patch.
Terra says hundreds of specialized agents work in parallel, triggering when code or infrastructure changes. Agents chain findings across surfaces the way an attacker would. Researchers oversee them through a control hub the company calls TORCH.
The Architecture Answer
CINI asked Terra what happens if an agent causes an outage in a production internal network. Is that a client business interruption loss or a Terra errors and omissions claim?
Peled rejected the premise before answering. He said the question assumes fully autonomous agents running unattended, and that Terra’s architecture was built specifically to avoid that. Engagements carry defined objectives, bounded toolsets, and customer-approved rules of engagement. Agents are not routed to the newest available model by default.
Peled described three guardrail layers. The foundation model’s own controls sit at the base. Terra’s platform-level controls sit above them and are deliberately not AI-based. Customer-specific controls sit on top. He argues the middle layer carries the weight, because “the enforcement of Terra’s core safety rules does not depend on the judgment of the same non-deterministic system it is governing.”
Then came a candid line. “No one working with non-deterministic technology can promise 100% predictability, and any vendor who does should not be trusted,” Peled said.
An Industry Pattern, Not A Product Feature
That architecture will sound familiar to readers of last week’s CINI coverage. PortSwigger launched Burp AT on July 27, built on the same principle. Agents propose actions. A deterministic control layer, architecturally separate from the model, decides what executes.
Two vendors reached the same conclusion within a fortnight. The model cannot be trusted to police itself, so a rule-based layer polices it instead. For underwriters assessing agentic tooling, that convergence is more useful than either company’s marketing. It suggests a control standard is forming in offensive security, and it gives risk engineers something specific to ask about.
The Third-Party Risk Question
CINI put the vendor dependency question to Terra directly. Agent swarms with privileged access to internal infrastructure describe the same profile behind this year’s largest supply chain incidents. How does Terra answer a chief information security officer who calls it their most sensitive third party?
Peled called it the right question and proposed a three-part test: depth of access, blast radius if the vendor is compromised, and degree of autonomy inside the customer environment. On blast radius, he drew a distinction that does real work. Peled described Terra as “a single-customer engagement model, not a shared update channel pushing code into thousands of environments simultaneously.” That is the pattern behind the year’s supply chain failures, and the distinction is fair.
Peled also conceded ground. He said “the agentic era does require a refreshed third-party risk framework,” and that Terra would rather help customers build one than argue about rankings inside the old one.
Deployment options include multi-tenant, single-tenant, and on-premises or air-gapped for regulated environments. Customers can bring their own model.
The Certification Worth Asking About
Peled cited three credentials: SOC 2 Type II, CREST, and ISO 42001. The last one deserves more attention than it usually gets.
SOC 2 attests to controls over data. CREST accredits penetration testing capability. Neither says anything about how a vendor governs the AI doing the work. ISO/IEC 42001:2023 does. Published in December 2023, it is the first international management system standard built specifically for AI. It covers the full lifecycle, from design and development through deployment, monitoring, and decommissioning.
The standard applies to organizations that develop, provide, or use AI systems. That covers Terra and its customers alike. Certification is voluntary, and ISO does not issue it. Independent certification bodies do, and those bodies may hold accreditation from national accreditation authorities.
Why cyber insurance underwriters should care.
Agentic vendors are proliferating faster than any submission form tracks them. ISO 42001 is currently the closest thing to a portable, auditable answer to the question of whether a vendor governs its AI at all. Regulators are already treating international standards as benchmarks, and the European Union’s AI Act conformity assessment procedures reference standards including this one. That gives it weight in UK and EU placements before it gets weight in US ones.
Why it proves less than it appears to.
This is a management system standard, not a product safety certificate. It certifies that governance processes exist and get audited. It does not certify that any particular agent will behave on any particular engagement. The distinction is the same one that separates ISO 27001 from an actual absence of breaches, and underwriters already know how that story goes.
The useful move is to treat it as a filter rather than a finding. A vendor without it should explain why. A vendor with it should still answer what its agents can do without a human gate.
What Terra Did Not Say
CINI asked the sharpest insurance question first. Continuous validation creates a dated record of every exploitable path a vendor found. If a client is breached through a finding flagged 60 days earlier, does that record support the claim or hand the carrier a denial?
Peled declined to engage. “Coverage outcomes are governed by policy language, and cyber policies vary substantially by carrier, industry, and insured,” he said. He added that “how any specific scenario gets handled will depend on the specific policy, the specific incident, and the specific facts.”
Both statements are true. Neither is an answer. The same pattern held on the outage question, where Peled described the guardrails in detail and never said which policy responds.
This is not evasion unique to Terra. It is the market’s default position, and Cyber Insurance News has documented it repeatedly. Willis found most cyber policies carry no AI exclusion and still fail to respond to several AI loss categories. The Economist Enterprise and Rubrik found nearly all firms running agents had an incident, and few could reconstruct one. The unresolved question of who acted when an agent causes the loss sits underneath all of it.
What Cyber Insurance Underwriters Should Take From This
Terra has built something genuinely useful for risk selection. Continuous validated evidence of exploitable paths beats a self-assessment questionnaire. The dated audit trail is an underwriting asset before it is a claims liability.
It is also both. Every finding logged is a finding someone can later prove the insured knew about. That cuts toward better pricing and toward harder conversations at claim time. Peled will not say which way it cuts, and it is not his job to say. It is the carrier’s.
Ask vendors where the deterministic layer sits. Ask what the agent can do without a human gate. Then ask your broker which policy responds when the answer turns out to be wrong.
FAQ – Agentic Pentesting
Continuous agentic internal network pentesting, in limited preview with selected design partners as of July 21, 2026. It extends Terra’s platform from web applications, external networks, and AI systems into internal infrastructure. Terra says this makes it the first agentic offensive security provider covering all four surfaces.
A person supervises the automated system and can intervene, but does not approve every individual action. Human-in-the-loop means a person signs off on each step. The difference matters at claim time, because it shapes who was actually in control when something went wrong.
Terra describes three guardrail layers: the foundation model’s own controls, Terra’s platform-level controls that are rule-based rather than AI-based, and customer-configured controls. The company says the rule-based middle layer is the important one, because enforcement does not depend on the same non-deterministic system it governs.
ISO/IEC 42001:2023 is the first international management system standard for artificial intelligence, published in December 2023. It covers the full AI lifecycle and applies to organizations that develop, provide, or use AI systems. Certification is voluntary and issued by independent accredited bodies. It certifies that AI governance processes exist and get audited, not that a given AI system is safe.
Terra declined to say which policy responds, noting correctly that outcomes depend on specific policy language, incident, and facts. That leaves the allocation between a client’s business interruption cover and a vendor’s errors and omissions cover unresolved. Risk managers should map the scenario with their broker before an engagement begins.
Related Cyber Insurance Posts
- Angsty Teenagers With Privileged Access: Beazley Security’s Francisco Donoso On Agentic AI Risk
- UK Enterprises Turn to Software-Based Pentesting Amid Rising Cyber Threats(Opens in a new browser tab)
- Cyber Insurance Compliance Demands Drive Enterprise Shift to Software Pentesting in 2025 | Key Findings(Opens in a new browser tab)
- MSPs Warned: Be Careful About Giving Clients Cyber Insurance Advice (Opens in a new browser tab)
- Diligent’s New Board Dashboard Raises a Question Insurers Should Love(Opens in a new browser tab)