About HOG3

HOG3 is a continuous AI pentesting platform for security and engineering teams protecting applications, APIs, and infrastructure.

We find exploitable weaknesses, show what an attacker could reach, and help your team resolve them. After a fix, we repeat the attack to check that it works.

We build for companies whose software handles money, identities, sensitive information, and access to other systems. In those environments, understanding the consequences of a vulnerability matters as much as finding it.

Why we built HOG3

Your last pentest tells you about the systems that were tested at that time. Since then, you may have shipped a release, changed a permission, or connected a new service. A vulnerability discovered in a dependency can create exposure even when your own code hasn’t changed.

Security teams have to keep up with all of this while helping engineers decide what needs attention.

We built HOG3 to make that work easier. Autonomous agents investigate weaknesses and follow the paths between them. The findings give your team evidence to act on, and retesting shows whether the changes have blocked the demonstrated attack.

WHAT HOG3 DOES

From finding a weakness
to verifying a fix

Show what an attacker could do

HOG3 tests within your authorized scope, investigating how applications, permissions, and services behave. It connects weaknesses to demonstrate their impact, such as reaching another customer’s account, exposing sensitive records, or gaining administrative access.

Each finding includes evidence your team can review and reproduce.

Explore example findings

Help your engineers resolve it

We explain the attack path, the affected systems, and the changes needed to address the weakness. Priorities reflect the demonstrated access and potential business impact.

Your engineers own the implementation. HOG3 provides remediation guidance without making changes to your code or production systems.

Check the result

Once your team has made a change, HOG3 repeats the relevant attack. The retest records whether the path is blocked or further work is needed.

That gives security and engineering a shared, verifiable answer to whether the issue has been resolved.

See how retesting works

Who we build for

HOG3 is designed for teams responsible for systems where unauthorized access has serious consequences:

  • Financial services and identity

    Payment flows, customer accounts, onboarding, and identity verification.

  • Cloud and security platforms

    Administrative controls, integrations, credentials, and privileged access to customer environments.

  • Enterprise software

    Applications holding confidential business information and sensitive customer records.

You may already have scanners, an internal security team, or a pentesting provider. HOG3 can work alongside them, adding recurring testing and verification between scheduled assessments.

The people behind HOG3

HOG3 grew out of our work building autonomous AI agents. Our founders previously worked together at Metana and brought that experience in product development and engineering into security testing.

Cofounder

Harsha Abegunasekara

Harsha previously founded Metana. At HOG3, he leads product direction and company strategy, working with customers to understand where security testing needs to improve.

LinkedIn

Cofounder

Chamaru Amasara

Chamaru previously led research and development at Metana. He leads HOG3’s engineering, including the reliability of its agents, the quality of its findings, and the controls that govern testing.

LinkedIn

HOG3 is operated by Donely Inc.

How we work with your team

We begin by understanding your environment and what you need to protect. Together, we agree on the systems to test, the access required, the testing boundaries, and the cadence.

Testing starts with explicit authorization. Your team receives evidence, remediation guidance, and retest results. Human validation and signed reports can be included in the engagement.

Subscriptions are tailored to the agreed scope, with monthly and annual options.

Explore pricing and scope

Company facts

Brand
HOG3 · Hunt. Observe. Guard.
Operating company
Donely Inc.
Product
Continuous autonomous AI pentesting
Founders
Harsha Abegunasekara and Chamaru Amasara
Testing scope
Applications, APIs, and infrastructure, as agreed with your team
Subscriptions
Monthly or annual, with pricing tailored to scope and cadenceView pricing
Website
hog3.com

Frequently asked questions

What is HOG3?

HOG3 is a continuous AI pentesting platform for security and engineering teams protecting applications, APIs, and infrastructure. HOG3 provides evidence of exploitable weaknesses, remediation guidance, and retesting after fixes.

What is the relationship between HOG3 and Donely?

HOG3 is the security brand and platform operated by Donely Inc. HOG3 stands for Hunt. Observe. Guard.

Who founded HOG3?

HOG3 was founded by Harsha Abegunasekara and Chamaru Amasara, who previously worked together at Metana. Harsha leads product direction and company strategy; Chamaru leads engineering.

How much does HOG3 cost?

HOG3 offers monthly and annual subscriptions tailored to the agreed scope, testing cadence, and engagement requirements. A scoped free pentest may be available by agreement before a paid subscription.

Does HOG3 change our code or production systems?

No. HOG3 provides evidence and remediation guidance, while your engineers own the implementation. After your team makes a change, HOG3 retests the relevant attack to check whether the path is blocked.

Do we need to replace our existing pentesting provider?

No. HOG3 can work alongside your security team, scanners, and existing pentesting provider. It adds recurring testing and verification between scheduled assessments, within an agreed scope and cadence.