IT Brief US - Technology news for CIOs & IT decision-makers
Cybersecurity analyst with ai assistants dark office vuln detection

Terra Portal blends AI agents with human-led pentesting

Wed, 11th Mar 2026

Terra Security has launched Terra Portal, a desktop application that serves as an execution layer for penetration testers overseeing AI-led security testing in live production environments.

Terra positions the product as an agentic gateway that coordinates work between autonomous software agents and human testers. It pairs automated activity with human oversight at decision points where risk and organisational controls require review.

Terra says Terra Portal can cut the cycle from vulnerability discovery to remediation from an industry average of nearly three months to hours. It says this can help customers address critical findings within the Cybersecurity and Infrastructure Security Agency's 15-day expectations.

Agent oversight

Penetration testing has become a focus for organisations seeking more frequent validation of security controls as software and cloud environments change rapidly. AI-driven testing has expanded automation, but it has also raised concerns about accuracy, safety, and governance when tools run against production systems.

Terra Portal aims to balance those trade-offs. It keeps routine tasks automated while routing complex or sensitive actions through a supervised workflow. Terra describes the model as human-governed AI execution rather than a fully autonomous toolset.

"The future of pentesting isn't autonomous versus human," said Shahar Peled, co-founder and CEO of Terra Security. "It's about giving humans leverage. With Terra Portal, this is the first time in history that we can combine depth, scale, and safety in security validation. Pentesters can do more meaningful, strategic work, and firms that adopt this shift will win."

Two agent types

Terra Portal uses two classes of AI agents with separate responsibilities and constraints. The first, which Terra calls ambient AI agents, runs automated activities across the testing lifecycle.

These agents handle reconnaissance, code review, test-case generation, reachability analysis, penetration tests, exploitability validation, documentation, and remediation. The product also includes "Copilot" AI agents that step in when work requires expert judgment or when guardrails require explicit approval.

At that point, a human penetration tester uses the portal to conduct controlled exploitation and produce reporting under an approved process. Terra frames this as a way to keep high-risk decisions and actions under human control while maintaining continuity with the automated workflow.

Services model

The launch also targets security service providers that run penetration tests for clients. Terra argues that a supervised agent model supports a shift from one-off projects to continuous offensive security services, with testing that runs more frequently and tracks ongoing changes in client environments.

Terra says autonomous agents handle execution while human testers provide oversight at critical stages. It says this can help providers increase the number of clients each tester can cover and reduce turnaround times, while maintaining governance to manage operational and reputational risk.

"Highly skilled Pentesters that spend too much time on repetitive and mundane tasks are wasting valuable efforts that can be better spent on strategic judgement," said Gev Hadari, head of adversary services at Terra Security. "The Agentic Gateway turns expert time into a force multiplier, allowing a single Pentester to safely oversee work that previously required entire teams."

Platform integration

Terra Portal integrates with Terra Security's broader agentic penetration testing platform, which uses multiple autonomous agents working in coordination across an environment. Terra says these agents continuously scope systems, identify attack surfaces, generate hypotheses, and validate potential vulnerabilities.

When automated agents reach their limits, the portal lets human testers step into the same workflow with full context on what the agents have already done. Terra says this reduces duplication and improves efficiency when escalation is necessary.

Terra describes its broader offering as continuous penetration testing that tracks code changes and evolving attack surfaces. The company operates from the US and Tel Aviv and works with large organisations across web applications, internal applications, APIs, mobile, networks, cloud, and AI systems.

Terra Portal is available in early access.