Cai

Cybersecurity AI (CAI), the framework for AI Security

Last verified:

Visit Cai

What is Cai?

CAI (Cybersecurity AI) is a lightweight, ergonomic framework for building bug bounty-ready cybersecurity AI tools. It is designed for offensive and defensive security work, with an agent-based architecture that lets users build specialized agents for tasks like reconnaissance, exploitation, privilege escalation, validation, and reporting.

The website emphasizes that CAI is built for security practitioners who want to automate or semi-automate real workflows. It includes built-in security tools, guardrails against prompt injection and dangerous command execution, and logging/tracing for visibility into agent behavior. The framework is positioned as research-backed and battle-tested in CTFs, bug bounties, and real-world case studies.

CAI supports a very wide model ecosystem, with 300+ AI models through providers such as OpenAI, Anthropic, DeepSeek, and Ollama. It can be run from the CLI, configured through .env files, command-line variables, or runtime /config commands, and it exposes environment settings for CTF and workspace-based workflows.

The site also presents CAI PRO, a professional edition for security professionals that adds unlimited use of the alias1 model, iOS mobile access, usage visibility, zero-refusal behavior, European hosting, and professional support. Overall, CAI is aimed at security researchers, bug bounty hunters, red teamers, and organizations that want a specialized AI framework for cybersecurity tasks.

Cai pricing

Pricing model: Freemium

The website says CAI is open source and free for research purposes. For professional or commercial use, including on-premise deployments, the site says users should obtain a license. CAI PRO is listed at €350/month and includes a commercial license, unlimited alias1 tokens, iOS mobile UI access, usage visibility, zero refusals for offensive security work, European hosting, and professional support.

Cai pros

  • Purpose-built for cybersecurity workflows
  • Bug bounty-ready out of the box
  • Agent-based architecture
  • Supports 300+ AI models
  • Works with OpenAI, Anthropic, DeepSeek, and Ollama
  • Built-in reconnaissance tools
  • Built-in exploitation tools
  • Built-in privilege escalation tools
  • Guardrails against prompt injection
  • Guardrails against dangerous command execution
  • Logging and tracing support
  • CLI-first workflow
  • Runtime configuration with /config
  • Environment-variable based setup
  • CTF-focused environment variables
  • Lightweight and ergonomic design
  • Research-backed and battle-tested
  • Can be extended with custom tools
  • Supports custom OpenAI base URLs
  • Supports professional mobile access in CAI PRO

Cai cons

  • Requires manual model API setup
  • No API keys included by default
  • First launch can take noticeable time
  • Active development may cause rough edges
  • Terminal UI is marked deprecated in PRO
  • Android setup is complex
  • Needs Python 3.12 for documented installs
  • Professional edition is expensive
  • Commercial use requires a license
  • Some features depend on external model providers

Frequently asked questions about Cai

What is CAI?

CAI is Cybersecurity AI, an open-source framework for building bug bounty-ready cybersecurity AI tools. The site describes it as lightweight, ergonomic, and designed for security tasks such as reconnaissance, exploitation, privilege escalation, and other agent-driven workflows.

Who is CAI for?

CAI is aimed at security researchers, ethical hackers, bug bounty hunters, red teamers, and organizations that want to build AI-assisted cybersecurity workflows. The website also positions it as useful for researchers and practitioners who want a modular framework for specialized security agents.

What can CAI do?

CAI can help automate or semi-automate cybersecurity tasks through specialized agents and built-in tools. The site highlights use cases such as reconnaissance, exploitation, privilege escalation, validation, reporting, and CTF-style security exercises.

Which AI models does CAI support?

The website says CAI supports 300+ AI models through providers including OpenAI, Anthropic, DeepSeek, and Ollama. It also mentions popular models such as Claude, GPT-4o, GPT-4.5 Preview, DeepSeek V3, DeepSeek R1, and Qwen2.5 variants.

How do you start CAI?

After installation, the quickstart says you launch it by typing cai in the CLI. Once it starts, it opens a CAI prompt where you can begin a security exercise and use the navigation bar for system information.

How can CAI be configured?

The website says CAI can be configured in three main ways: through a .env file, by setting environment variables inline when launching the CLI, or at runtime using /config inside CAI. The quickstart shows CAI_PRICE_LIMIT and CAI_MODEL as examples.

Does CAI include API keys?

No. The installation documentation explicitly says CAI does not provide API keys for any model by default. Users are expected to supply their own model credentials in the environment configuration.

What is CAI PRO?

CAI PRO is the professional edition. The website lists unlimited alias1 tokens, a native iOS mobile interface, usage visibility tools, zero refusals for offensive security use, European hosting, and professional support as part of the paid offering.

Is CAI suitable for CTFs?

Yes. The quickstart and environment-variable documentation include multiple CTF-specific settings such as CTF_NAME, CTF_CHALLENGE, CTF_SUBNET, CTF_IP, and CTF_INSIDE. The site positions CAI as usable for CTF-style security exercises and attack/defense scenarios.

What safeguards does CAI have?

The site says CAI includes built-in guardrails against prompt injection and dangerous command execution. It also mentions logging and tracing for observability, along with defense-in-depth ideas such as sandboxed tools and output guardrails in its research materials.

Categories

Use cases

Browse all AI tools on NeedAnAI