How 11x replaced the annual pentest with a security program that runs 365 days a year

Amartya Jha

Aug 24, 2026

11x team photo
11x logo
11x team photo
11x logo

"CodeAnt went deeper than any penetration test we've ever commissioned. The most thorough offensive security platform we've used."

Portrait of Jeson Patel
Portrait of Jeson Patel

Jeson Patel

CTO, 11x (Series B, $75M+ Raised )

CTO, 11x (Series B, $75M+ Raised )

In this Case Study

No headings found on page

INDUSTRY

AI & Software

SERVES

Enterprise revenue organizations

ENGAGEMENT

Offensive and defensive security, one platform

11x builds AI digital workers for the world's largest go to market teams. Their customers are enterprise revenue organizations.

CHALLENGE

The agent has production access. So does anyone holding its credentials.

11x sits on top of hundreds of millions of B2B contact records, connected CRMs, mailboxes, phone infrastructure, and messaging channels. When your product is an autonomous agent acting on a customer's behalf, a single leaked credential does not expose a record. It exposes the customer's entire pipeline.

WHY CODEANT

They wanted the loop closed between offense and defense.

11x asked for a cybersecurity program, not a report. Offensive and defensive security in one platform, with every AI agent they run attacked continuously, and everything that attack finds turned straight into a code level fix and a permanent defensive rule. So the same class of issue cannot ship twice.

On the offensive side, three things a point in time test structurally cannot deliver:

Attack surface management. A live map of everything 11x actually exposes, not a list frozen on day one.

Shadow IT discovery. The staging environments, forgotten subdomains, and internal tools that ship faster than the security review does.

Credential and session token exposure. If a session token or a set of test credentials ever leaks into a JS bundle, a public repo, or a source map, they want to know where it is and act on it the same day.

WHAT WE RAN

What the attack proves, the review enforces

The same engine that runs the attacks sits in the pull request. What the offensive side proves is exploitable becomes the rule the defensive side enforces before the next release ships.

WHAT CHANGED

Compliance was never the goal here. Proactive fixing was, before an agent with production access becomes someone else's foothold.


[GET STARTED]