Plainsea announces the release of v2.0.0. The new version expands its Human-in-the-Loop governance controls, introduces AI-native protection against prompt injection and scope drift, and adds potential exposure tracking, plus centralized asset management.
More Control Over How the Agent Operates
Plainsea's Human-in-the-Loop (HITL) framework, the architectural control plane that keeps every agentic WebApp assessment under human authority, receives significant new depth in v2.0.0. Security teams can now precisely calibrate how much execution autonomy the agent has, choosing from three operating modes:
-
Step-by-step confirmation - the Plainsea agent pauses before each significant action and requests approval. Maximum control for sensitive or production targets.
-
Semi-automated mode - once you have pre-approved certain categories of actions for the duration of the assessment, the agent proceeds autonomously without interruption. Speed and oversight in balance.
-
Fully automated mode - the agent completes the full assessment and delivers a finished report without interruption. Suited for staging and development environments.
Guardian Agent: Protection Against Injection and Scope Drift
Autonomous agents running web app assessments operate in adversarial conditions by definition - and two threats are particularly difficult to contain: prompt injection attacks embedded in target page content, and scope drift that causes the agent to test assets beyond its authorized boundary.
Therefore, Plainsea v2.0.0 ships with a Guardian Agent - an AI safety layer that monitors all agent actions in real time, enforces the defined scope perimeter, and neutralizes injection attempts. Every assessment stays lawful, authorized, and fully contained, regardless of what the agent encounters during testing.
Potential Exposure Identification
Not every vulnerability is exploitable today - but conditions change. The new Plainsea version tracks potential exposures the agent could not fully exploit in their current state, flagging them with a warning: if a specific configuration changes (a firewall rule, a server setting, an access control), this becomes a high-risk finding. Security teams get visibility into what is one step away from critical, before that step happens.
Centralized Asset Inventory and Scope Management
You cannot secure what you do not know you own, so the new Asset Inventory module introduces better asset ownership and management to the platform.
Before any asset enters the testing inventory, users complete an ownership-claim flow that verifies control over that asset. This protects organizations and third parties from unauthorized testing - a non-negotiable legal and ethical requirement. Scope definition, adjustments, and slot management all live within the same module, creating a clear, auditable chain of authorization for every assessment.
Availability
Plainsea v 2.0.0 is available now! You can contact our team at contacts@plainsea.com to schedule an online meeting and get a personalized walkthrough. Or if you're in London, you can see how it works live at Booth B72 in the Discovery zone at Infosecurity Europe 2026, 2-4 June.
