HOG3 is a continuous AI pentesting platform for security and engineering teams protecting applications, APIs, and infrastructure.
We find exploitable weaknesses, show what an attacker could reach, and help your team resolve them. After a fix, we repeat the attack to check that it works.
We build for companies whose software handles money, identities, sensitive information, and access to other systems. In those environments, understanding the consequences of a vulnerability matters as much as finding it.
Why we built HOG3
Your last pentest tells you about the systems that were tested at that time. Since then, you may have shipped a release, changed a permission, or connected a new service. A vulnerability discovered in a dependency can create exposure even when your own code hasn’t changed.
Security teams have to keep up with all of this while helping engineers decide what needs attention.
We built HOG3 to make that work easier. Autonomous agents investigate weaknesses and follow the paths between them. The findings give your team evidence to act on, and retesting shows whether the changes have blocked the demonstrated attack.
WHAT HOG3 DOES
From finding a weakness to verifying a fix
Show what an attacker could do
HOG3 tests within your authorized scope, investigating how applications, permissions, and services behave. It connects weaknesses to demonstrate their impact, such as reaching another customer’s account, exposing sensitive records, or gaining administrative access.
Each finding includes evidence your team can review and reproduce.
We explain the attack path, the affected systems, and the changes needed to address the weakness. Priorities reflect the demonstrated access and potential business impact.
Your engineers own the implementation. HOG3 provides remediation guidance without making changes to your code or production systems.
Check the result
Once your team has made a change, HOG3 repeats the relevant attack. The retest records whether the path is blocked or further work is needed.
That gives security and engineering a shared, verifiable answer to whether the issue has been resolved.
HOG3 is designed for teams responsible for systems where unauthorized access has serious consequences:
Financial services and identity
Payment flows, customer accounts, onboarding, and identity verification.
Cloud and security platforms
Administrative controls, integrations, credentials, and privileged access to customer environments.
Enterprise software
Applications holding confidential business information and sensitive customer records.
You may already have scanners, an internal security team, or a pentesting provider. HOG3 can work alongside them, adding recurring testing and verification between scheduled assessments.
The people behind HOG3
HOG3 grew out of our work building autonomous AI agents. Our founders previously worked together at Metana and brought that experience in product development and engineering into security testing.
Cofounder
Harsha Abegunasekara
Harsha previously founded Metana. At HOG3, he leads product direction and company strategy, working with customers to understand where security testing needs to improve.
Chamaru previously led research and development at Metana. He leads HOG3’s engineering, including the reliability of its agents, the quality of its findings, and the controls that govern testing.
We begin by understanding your environment and what you need to protect. Together, we agree on the systems to test, the access required, the testing boundaries, and the cadence.
Testing starts with explicit authorization. Your team receives evidence, remediation guidance, and retest results. Human validation and signed reports can be included in the engagement.
Subscriptions are tailored to the agreed scope, with monthly and annual options.
HOG3 is a continuous AI pentesting platform for security and engineering teams protecting applications, APIs, and infrastructure. HOG3 provides evidence of exploitable weaknesses, remediation guidance, and retesting after fixes.
What is the relationship between HOG3 and Donely?
HOG3 is the security brand and platform operated by Donely Inc. HOG3 stands for Hunt. Observe. Guard.
Who founded HOG3?
HOG3 was founded by Harsha Abegunasekara and Chamaru Amasara, who previously worked together at Metana. Harsha leads product direction and company strategy; Chamaru leads engineering.
How much does HOG3 cost?
HOG3 offers monthly and annual subscriptions tailored to the agreed scope, testing cadence, and engagement requirements. A scoped free pentest may be available by agreement before a paid subscription.
Does HOG3 change our code or production systems?
No. HOG3 provides evidence and remediation guidance, while your engineers own the implementation. After your team makes a change, HOG3 retests the relevant attack to check whether the path is blocked.
Do we need to replace our existing pentesting provider?
No. HOG3 can work alongside your security team, scanners, and existing pentesting provider. It adds recurring testing and verification between scheduled assessments, within an agreed scope and cadence.