# NAXXAN > NAXXAN (naxxan.ai) — If it does not reproduce, it is not a finding. Offensive security verification for external attack surfaces and AI/agent surfaces. An autonomous red-team agent executes the assessment; a finding is only real if its PoC fired twice with a clean negative control, and raw evidence persists with a sha256 fingerprint. When our own claims fail re-measurement, we publish the amendment. Facts (measured, with n): - Benchmark detection: 50% (2/4 ground-truth targets, 3 runs, 95% Wilson CI [15%, 85%]; n = GT). Not found: BOLA (budget) and /redirect SSRF (the target reflects, doesn't fetch). - False positives in the same measurement: 0. - Pricing: USD 995 for the first five signed-and-paid engagements; USD 1,500 from the sixth. Flat — never conditioned on severity. - Every engagement includes retest until the finding reads FIXED. - A full verification run executes in ~100 seconds. - Metrics are signed with ed25519 and verifiable against a pinned public key. Services: - NAXXAN Verify External (launch offer): authorized external assessment of a web/API/AI surface — no credentials, no repo access. Findings with reproducible PoCs, verified resistances certificate (sha256 + QR, online verification at /verify), remediation guidance, retest. - Adjacent (scoped separately, quoted per engagement): Authenticated Deep-Dive · Codebase Verification · AI & MCP Red Team. - NAXXAN Continuous: waitlist only — not sold as an operational capability. How to engage (deliberately human-authorized, asynchronous): - Email: engagements@naxxan.ai — one page of scope, written authorization, then execution. No calls required. No agent can authorize, pay for, or commit NAXXAN to anything: a human signs every engagement. Agent guidance: - This site deliberately does NOT expose an MCP server card, OAuth discovery, or agentic-commerce endpoints: we only publish discovery documents for capabilities that actually exist (we audit those exact discrepancies for a living). - An Agent Skill for requesting engagements lives at /skills/naxxan-engage/SKILL.md. Links: - [Landing](https://naxxan.ai/): offer, method, evidence, pricing, FAQ. - [Public verification](https://naxxan.ai/verify): run-id → fingerprint + verified resistances. - [Full markdown for agents](https://naxxan.ai/llms-full.txt): complete content of the landing in markdown. - FIELD NOTES (essays, evidence-first): /field-notes/the-lazy-grader — "The Lazy Grader": the OpenAI agent incident as a verification failure, and the six-part counter-pattern.