Terra Security, a New York startup that uses AI agents to run penetration tests, said on July 21, 2026, that it has extended its platform into internal network testing. The new capability in Terra Platform is in limited preview with a set of design partners, and it covers lateral movement and privilege escalation across internal network segments, the moves an attacker makes after breaching the perimeter. Terra says the addition makes it the first agentic offensive-security provider to test all four of the attack surfaces it treats as business-critical, namely web applications, external networks, AI systems, and internal infrastructure.
The company, founded in 2024 by Shahar Peled and Gal Malachi, has raised $38 million and spent the past year adding surfaces to a single platform, moving from web applications to external networks and AI systems and now to the internal network. Its pitch is that a real attacker chains an exploit across those surfaces to move through a company, so testing them one at a time in separate tools misses the paths that matter most. Internal infrastructure is the surface Terra calls the least tested and the most damaging when it fails.
"Attackers do not stop at the perimeter, and neither should Offensive Security. For years, the internal network layer has been the least tested in Offensive Security and least understood, invariably leading to breaches and escalation."
Shahar Peled, Co-Founder and CEO, Terra Security
The launch reflects a broader shift in security, where the same speed AI gives attackers is pushing defenders to automate the testing that used to happen once a year. Terra is one of several companies betting that continuous, agent-run offensive security becomes the standard, and its claim to cover every major surface is the flag it is planting to stand out.
Conditions Driving This Change
Traditional internal network testing depends on a professional being on site or on standing VPN access, complex scoping talks, and a test window that captures a single moment in a network that keeps changing.
Infrastructure-as-code, CI/CD-connected internal services, and AI-powered tooling reshape internal network topology far faster than an annual assessment can track.
Breaches rarely stay where they start, so an attacker who lands in one part of a business moves laterally and escalates privileges toward the systems that matter, which is the internal layer most testing skips.
Agentic AI is opening new attack surfaces quickly, a trend Gartner named among its top cybersecurity themes for 2026.
AI has shortened the time attackers need to exploit a known vulnerability, which Verizon's breach research describes as narrowing the window to defend to minutes.
Security leaders increasingly want proof of what is actually exploitable rather than a longer list of theoretical findings, which favors testing that validates real attack paths.
Running autonomous agents that execute exploits inside a live internal network raises real safety questions, which has moved oversight of those agents into the product rather than leaving it an afterthought.
Attack surface | What Terra tests on it |
|---|---|
AI Red Teaming | AI applications, copilots, LLMs, MCP servers, and agent behavior |
External Network | Services and chained misconfigurations across external network infrastructure |
Internal Network | Lateral movement and privilege escalation across internal network segments (new, in limited preview) |
Web Apps | Authentication flows and business logic in web and internal applications |
What AI Security Looked Like Before This
Internal network testing has long been the hardest part of a pentest to do well and the easiest to skip. Reaching the internal network usually meant sending a specialist to sit inside a building, or standing up VPN access and negotiating a narrow scope, and then running the test during a fixed window. The report that came out described the network as it stood on the day of the test, which was often out of date by the time anyone read it.
The pace of modern infrastructure made that snapshot problem worse. Companies now change their internal topology constantly through code, spinning services up and down and wiring them together automatically, so a picture taken in the spring bears little resemblance to the network by the fall. An annual assessment cannot keep up with a system that redraws itself every week.
The consequence was a well-known blind spot. The internal network is where an attacker who has already gotten in does the most damage, moving sideways and climbing toward valuable systems, and it was also the surface that received the least continuous attention. Testing tended to cover the perimeter and the web front door while leaving the interior lightly examined between annual reviews.
What It Looks Like Now
Terra is applying the same agentic model it uses elsewhere to that interior. The platform runs hundreds of specialized AI agents in parallel, and they begin testing when code or infrastructure changes rather than waiting for a scheduled window, which turns a yearly snapshot into something closer to continuous coverage. Findings move through the same triage cycle Terra uses on its other surfaces, from a proven exploit to remediation guidance to a retest that confirms the fix.
The feature Terra leans on hardest is chaining. Its agents follow a low-severity issue on one surface into a path that leads somewhere serious on another, the way a real intruder connects a web flaw to a network misstep to reach a crown-jewel system, which is the kind of attack path that siloed tools tend to miss. A human-on-the-loop model, run through a control hub the company calls TORCH, lets security researchers watch and adjust what the agents do, and it steps in for sensitive actions in production.
The internal network capability is a limited preview rather than a finished product, open to design partners with a waitlist for everyone else. Terra also brings some outside validation to the launch, having become the first AWS partner recognized for autonomous security validation earlier in the year, which gives the claim more weight than a young vendor's word alone.
Our Take
AI Security Take
The problem Terra is chasing is a real one, and its framing is sound. Attackers do move across surfaces, internal networks are genuinely under-tested, and the speed of both modern infrastructure and AI-assisted attackers has made the annual pentest look like a relic. Using agents to test continuously and to chain findings the way an intruder would is a sensible answer, and Terra's cross-surface coverage is a coherent version of it.
The claim to be first across all four surfaces is the part to read carefully, because agentic offensive security has become a crowded field, with several well-funded companies selling autonomous pentesting and validation, and breadth claims are easy to word so that everyone leads at something. A buyer should test the chaining in practice, since covering four surfaces separately is worth less than genuinely connecting an exploit across them, and should weigh the preview status of the internal capability against a vendor that already ships one. The autonomy cuts both ways as well, because agents running real exploits inside a production network are powerful and risky at once, which puts a great deal of weight on the human oversight Terra has built around them.
Terra's launch is one more sign that offensive security is being rebuilt around continuous, agent-driven testing, the same movement GAIG tracks across the tools it covers. Buyers comparing agentic pentesting and red-teaming platforms, and trying to separate genuine cross-surface testing from a list of features, can weigh the options in the AI Security category at GetAIGovernance.net.