Two mutually reinforcing engines, a regulation-driven market, defensible advantages: consulting engagements feed the product with real use cases, and the product multiplies the billing capacity of our senior consultants.
A two-engine thesis
- Cybersecurity services and development. Offensive audit, Red Team, compliance, training, software development. Our senior consultants have worked at Airbus, Pierre Fabre, TotalEnergies, CNRS and BPCE.
- DarkMoon, an offensive AI platform. An autonomous, open-core pentest agent, runnable locally for total sovereignty: 50 sub-agents, 80+ orchestrated tools, recurring revenue (Pro / MSSP) and a managed service.
A market driven by regulation
NIS2 and DORA mandate more frequent security testing, while the shortage of pentesters worsens and makes continuous, automated pentesting indispensable. AI automation of penetration testing directly answers this need for continuous offensive security, in a fast-growing cybersecurity market.
Traction, in figures
Growing open-source adoption, international press recognition and verified technical proof: traction that is documented, measured and defensible point by point.
- 862 stars, 149 forks on GitHub. An open-source community (GPLv3, ASCIT31/Dark-Moon) that has grown without interruption since launch.
- 48 media mentions, in four languages. TF1 (national TV), Help Net Security, SecurityBrief UK, Cyber Security News, Japanese press.
- Verified technical proof. On the reference OWASP Juice Shop environment: 56 vulnerabilities detected, 36 exploited; Privacy Gateway test suite validated 22 out of 22.
- 50 agents, 80+ tools. A master agent profiles the target and dispatches specialised sub-agents (web, Active Directory, cloud, IoT) running real offensive operations.
- Public recognition. Innovation recognised by the French Ministry of Higher Education and Research; presence at MWC Barcelona (French pavilion) and at the FIC (Occitanie pavilion).
The product
- Multi-agent orchestration. A master agent profiles the target and dispatches specialised sub-agents (web, Active Directory, cloud, IoT) that carry out real offensive operations.
- Evidence discipline. Each finding is classified EXPLOITED, Confirmed or unconfirmed signal. The AI is never the source of truth: the evidence collected on the target is.
- Security by action. The model never has a free shell: every action goes through an MCP gateway and a tool allow-list. The barrier is the action.
- Privacy Gateway. Local tokenisation of sensitive data: the AI provider never sees your real IPs, hosts or credentials.
- Publishable reports. Findings scored with CVSS 3.1, mapped to MITRE ATT&CK, exportable to ISO 27001 / HackerOne / Bugcrowd formats.
- Sovereign and local. Can run 100% locally (on-premises AI model), with an air-gap option, zero telemetry. Open-source GPLv3 core, auditable.
Defensible advantages
- Security by action. MCP and allow-list, not a shell handed to the model.
- Privacy Gateway. Data never leaves the client.
- Continuously offensive. Continuous offensive security, integrated into CI/CD.
- Evidence-first. ISO 27001 / NIST / MITRE / CVSS reports.
- Open-core. Community adoption then Pro / MSSP conversion.
- Sovereign alternative. A European alternative to US tools.
An open-core model, from free to recurring
The free Community edition creates adoption then converts to Pro, MSSP and a managed service: a low-cost open-core engine. Stripe billing, Cryptolens licences (EU), European infrastructure on OVH and IONOS.
- Community — open source (GPLv3). Autonomous CLI agent, MCP-mediated execution, Privacy Gateway. Self-hosted, free forever. The adoption and community engine.
- Pro — €149/month. Web dashboard, hardware-bound licence, hardened runtime, signed PDF reports, CI/CD, SSO. Recurring revenue.
- Custom / MSSP — on quotation. Multi-seat, white-label, partner programme, onboarding and SLA. Large-group and reseller accounts.
- Pentest on Demand — €799 / engagement. A pentest managed by our experts, legal framework included, CVSS report, encrypted video debrief. A gateway to recurring revenue.
Governance and founding team
ASC-IT is led by its two co-founders, engineers rooted in the Toulouse aerospace ecosystem — a critical-industry background that is rare for a cybersecurity vendor.
Aurélien Strich — Co-founder, Product Owner and Cybersecurity Project Lead
Electronics, robotics and industrial computing engineer (Polytech Montpellier, Erasmus Linköping). A software architect and cybersecurity expert, he has worked in aeronautics, space and maritime. He was an IoT/OT Product Owner at Marlink (serving the client CMA CGM), led DevSecOps R&D at Kratos Communications on satellite data, designed IoT solutions at Sierra Wireless and served as technical reference and Java architect at the CNRS. He speaks regularly at conferences, from KubeCon EU 2024 to Oracle Code One 2019.
Mehdi Boutayeb — Co-founder, Cybersecurity and AI Architect, DarkMoon Lead Engineer
A cybersecurity and AI architect, DevSecOps. He designed DarkMoon's architecture and develops its core (MCP host, offensive agents, Privacy Gateway). A former pentester, he works in aeronautics and cloud. Infrastructure and AI architect then cybersecurity consulting architect at Airbus, he led DevSecOps and Cloud Security at Pierre Fabre, ran offensive web, Active Directory and network campaigns as a pentester, and teaches cybersecurity and DevOps at Ynov, IPI and EPSI.