// Autonomous penetration testing

It starts on the open internet. It stops at your domain controller.

Everything in between happens on its own. One click, no operator, no credentials handed over. A funded attacker's playbook, working for you.

// Ways to buy a pentest

01 · External subscription

Unlimited external penetration tests, as often as daily or whenever you need one. Breach reports and social engineering are included at no extra cost. Run them with the pentest, or on their own.

02 · Internal subscription

Unlimited Active Directory and Azure tests.

03 · Tanuki Lite

A monthly scorecard.

04 · One-time

A single external or internal engagement. Sold separately.

// Autonomous

No human at any stage. On a subscription, unlimited tests at the click of a button.

// Black box

Starts from the outside. No credentials, no network access, and nothing installed.

// Patented in

Canada, the United States, India, and Australia. European patent pending.

// Trusted by and partnered with

TELUS Health standardized on Tanuki across 30,000+ healthcare businesses.

Customers include Mizuho Bank, Scotiabank, VersaBank, Exxon, Fujitsu, Commonwealth Wealth Management, and OpenText.

  • TELUS
  • Mizuho Bank
  • Ingram Micro
  • Deloitte
  • MSP Corp
  • Hensall Co-op
  • Scotiabank
  • Raymond Johnston Equipment
  • VersaBank
  • StarTech.com
  • Exxon
  • ISS of BC
  • Fujitsu
  • Commonwealth Wealth Management
  • OpenText

// The problem

A yearly pentest is a snapshot.

Attackers keep scanning. A consulting window ends, and the network keeps changing. The useful question is what is true this week.

  1. 01

    The report expires

    A manual pentest describes one week. New hosts, new misconfigurations, and newly stolen credentials show up after the consultants leave.

  2. 02

    Scope gets cut

    Time and budget push teams to leave systems out. Anything outside that window stays untested.

  3. 03

    The retest is another project

    A fix is not proven until you test again. That usually means a new scope, a new team, and a new invoice.

  4. 04

    Priced as a one-off

    A traditional engagement buys a single snapshot. A Tanuki subscription is unlimited retesting, without paying again every time.

// Since your last pentest

Your last pentest is already out of date.

See everything that's gone public since your last pentest, and how much of it attackers are already exploiting.

Count from

July 7, 2026 through October 4, 2026, 90 days. CVEs published: 36,759. Added to CISA KEV: 103. A new CVE every 3.5 min.

July 7, 2026 through October 4, 2026, 90 days.

CVEs published

36,759

Added to CISA KEV

103

A new CVE every

3.5 min

In the last 90 days, 36,759 new vulnerabilities were published. In the same period, CISA confirmed attackers are actively exploiting 103 vulnerabilities.

Source: NVD (opens in a new tab) and CISA KEV catalog (opens in a new tab). Data as of October 4, 2026.

A count shows what was published. Tanuki shows what an attacker can actually reach, from the open internet to your domain controller.

Book a demo

Attacks come from anywhere on the internet.

So does Tanuki.

We've deployed Tanuki systems on a global scale, giving Tanuki a global network to obfuscate its efforts and emulate a modern-day adversary who might be launching their attacks across multiple infected computers to avoid law enforcement. One Tanuki can handle one step while another takes the next. It's paced like a real attack, never a flood of traffic.

Have data or compliance concerns? We can localize Tanuki to the geographic region you choose.

// Platform

How Tanuki works.

Tanuki utilizes deep neural networks and machine learning to continuously improve. It gets smarter and more capable with every engagement.

01

Reconnaissance

OSINT and breach data are used, not just collected. A stolen password becomes a login in the same operation.

02

External

This is the black-box test. It starts on the internet-facing estate. You provide no credentials and no network access, and nothing is installed: no agent and no Docker. Where MFA blocks a password, Tanuki captures the live session token and continues.

03

Internal

The objective of Active Directory and Azure testing is Domain Admin, by lateral movement. An external test can also continue inside if it gets a foothold.

04

Social engineering

Included with the external subscription. Phishing against real targets, such as a VPN or a workstation.

External subscription

// Every test produces

  • Audit-ready pentest report
  • Validated by real exploitation and chained attack paths
  • Prioritized by exploitability and business impact
  • Remediation guidance for each finding

Every test follows NIST SP 800-115, the US government's technical guide to security testing, so reports hold up for compliance and audits. Findings come from real exploitation, not a theoretical list.

// Offerings

Pick the testing that fits.

Enterprise testing, priced for the mid-market. Every offering is available directly or through our reseller partners, including TELUS, Ingram Micro, and MSP Corp.

One traditional engagement often costs $15,000 to $30,000. A subscription covers unlimited tests.

External pentest subscription

Unlimited tests, as often as daily or whenever you need one, starting from the open internet. It can continue inside if it gets a foothold. Breach reports and social engineering are included at no extra cost. Run them fully integrated with the pentest, or on their own whenever you need them.

Internal pentest subscription

Unlimited Active Directory and Azure tests.

Tanuki Lite

A monthly scorecard.

One-time external pentest

A single test from the open internet. No subscription needed.

One-time internal pentest

A single Active Directory and Azure test. No subscription needed.

Breach reports

Finds your team's stolen credentials in fresh breach data, the same leaks attackers use to get in.

Social engineering

Real phishing campaigns that show what happens when one of your people takes the bait.

Book a demo

// Who uses Tanuki

From global banks to local clinics.

Tanuki scales up and down the market. Large enterprises run it alongside their own security teams, and smaller teams get the same testing without needing a security department.

  1. 01

    Enterprise

    Banks and global companies like Mizuho Bank, Scotiabank, Exxon, Fujitsu, and OpenText test against the same attacker playbook.

  2. 02

    Mid-market

    Enterprise testing at a price a mid-sized team can run whenever it needs to.

  3. 03

    Small business and healthcare

    TELUS Health offers Tanuki to clinics.

  4. 04

    MSPs and resellers

    Offer Tanuki to your clients. See Partners.

// Patents

Patented in four countries.

Tanuki is patented in Canada, the United States, India, and Australia. A European patent is pending.

  • CanadaPatented
  • United StatesPatented
  • IndiaPatented
  • AustraliaPatented
  • EuropePending

// Partners

Offer Tanuki to your clients.

Tanuki is built for resale. Licensing is simple, enablement is light, and partners don't need to staff pentesters.

// Become a partner

MSPs and security resellers start here.

Name the clients you already support.

Talk to partnerships

// Leadership

Who is accountable for Tanuki.

EzoTech Inc. is led by Xristos Silaidis and Mike Picard. To book a test, use the form. For anything else, write to info@ezotech.net.

// Co-Founder and Chief Executive Officer

Xristos Silaidis

// Co-Founder and Chief Technology Officer

Mike Picard

// Book a demo

Tell us what you need tested.

No chatbot, no ticket queue. Tell us a bit about your environment, and someone from our team will reply from info@ezotech.net to set up a time.

Canadian company. No account, no upload, and no data stored by this form. Privacy questions go to legal@ezotech.net.

Opens your email app, addressed to info@ezotech.net. Nothing is stored on this website.