Background

A career built on breaking things (legally)

I am Elias Marquez, CEO and Founder of Achilleus, a penetration testing firm built from the ground up. Over the past decade-plus in offensive security, I have done it all: network pentesting, web applications, mobile, physical engagements, hardware and IoT hacking, social engineering, and plenty of things that do not fit neatly into a category. If it had an attack surface, there is a reasonable chance I have looked for weaknesses in it at some point.

That experience gave me a very specific lens for evaluating security tools. That same lens would eventually become the source of considerable professional frustration.

The Origin

A chatbot, a client request, and a slow-building frustration

In July 2023, I built what was essentially a highly knowledgeable pentesting assistant. A smart chatbot, deeply trained on offensive security knowledge, useful for augmenting security work. It was a solid first experiment. More importantly, it planted ideas far bigger than the tool itself.

By August 2024, clients at Achilleus were asking a consistent question: could they get automated pentesting? The market was buzzing with it. So I did what any responsible operator would do and started evaluating vendors to potentially integrate into the Achilleus platform.

That evaluation did not go well. For the vendors, at least.

What I found, repeatedly, were vulnerability scanners dressed in AI marketing clothing. They could only do what they were explicitly programmed to do: follow predefined scripts, run known checks, generate tidy reports. There was value in that, sure. But was the pricing justified compared to simply purchasing a solid vulnerability scanning solution? I could not make that case. And the scope limitations compounded the problem: this product covers web apps, that one handles networks. Nobody was building a single unified platform for web application testing, internal network, external network, and attack surface management together. I kept asking myself why not. I never got a satisfying answer.

Then there was the pricing. OEM licensing from these vendors was not cheap. Passing those costs through to Achilleus clients meant the end price would have been, frankly, difficult to justify with a straight face. The technical limitations were already a problem. The economics made it worse. Between an underwhelming product and an eye-watering price tag, the decision to build something ourselves started feeling less like ambition and more like the only logical option. Partially out of genuine innovation. Partially, I will admit, out of pettiness. But then again, that is reportedly how Netflix got started too, so I am in reasonable company.

The Decision

The sentence that started everything

September 2024. Another evaluation. Another product that was technically competent but creatively uninspiring.

Screw this, I'll just create it myself.

Not the most elegant origin story. But it was genuine, decisive, and it set everything in motion.

The vision was clear from the start: not another collection of predefined scripts masquerading as AI, but something that could genuinely reason, adapt, and execute like a skilled human pentester. The internal reference point I kept returning to was Skynet from Terminator, strictly minus the part about ending humanity. The goal was a platform that could think rather than just execute; learn rather than just recall; and operate continuously without fatigue or knowledge limits. In short, I wanted to build a cloned, better version of myself. Or better yet, hundreds of them.

Development

October 2024 onward: building, tearing down, and building again

Development started in October 2024. It was a real journey. Multiple systems were built and scrapped. I immersed myself in the technical landscape: RAG systems, MCPs, LangGraph and LangChain, Knowledge Graphs, fine-tuning, training, and reinforcement learning through human feedback. There was a great deal to learn. I learned most of it the hard way.

A few core architectural decisions shaped what Canima became:

Decision 01: Specialized agents over monolithic models

Canima operates with hundreds of AI agents, each a specialist in its own domain: specific vulnerabilities, attack techniques, and exploitation paths. Stuffing everything into one context window causes context rot. Precision suffers. Focused agents, fine-tuned per domain, maintain genuine expertise at scale.

Decision 02: No third-party AI providers

Sending client pentest data to OpenAI or Anthropic is not a minor footnote; it is a fundamental security risk. Your engagement data, findings, and infrastructure details should not be training someone else's model. Canima runs on purpose-built proprietary models.

Decision 03: A single source of truth

Graph knowledge bases give every agent consistent, reliable, and interconnected intelligence. No contradictions, no knowledge gaps between agents. One backbone powering the whole network.

Decision 04: A continuously evolving R&D function

Canima includes a dedicated AI R&D team that constantly learns and updates attack techniques, feeding that knowledge back into the broader agent network. The platform learns. Continuously.

The Road

It was not a straight line

I would be less than honest if I described this as a clean, linear path from idea to launch. There were real ups and downs. Life happened, as it tends to do. Development stretched across months of iteration, second-guessing, and occasional ground-up rebuilds.

But the work continued. We secured patent-pending status in March 2025, a meaningful milestone that validated the novelty of the architecture and the time invested in getting it right. Alpha testing followed with a select group of users whose feedback sharpened things considerably. Canima was also formally separated from Achilleus during this period, becoming its own independent entity and a partner rather than a product line. That felt right. What we had built had grown well beyond the scope of a feature for an existing platform.

The Launch

March 2026: Canima is officially here

One unified platform covering web application testing, internal network, external network, and attack surface management. Hundreds of specialized AI agents. Purpose-built proprietary models that keep your data where it belongs: with you. A graph knowledge base ensuring every agent operates from a consistent, accurate foundation. And a patent to back it all up.

I have watched with genuine interest over the past several months as others have entered the "AI pentester" space. Some are building credible products. Some are mostly marketing collateral with an API key in the back end. A few appear to have proprietary models, which I respect. But the pattern I consistently see is fragmentation: web apps over here, network over there, and heavy reliance on third-party AI infrastructure throughout.

We remain the only platform that brings all of it together in a single product. The patent is not just a legal document; it is the record of when we figured that out and built it.

What Comes Next

This is just the beginning

The goal was never to replace human pentesters. Human intuition, creativity, and judgment are irreplaceable, and anyone telling you otherwise is selling something. The goal was always to extend those capabilities; to give clients access to something that operates at a genuinely high level, continuously, and at scale. The real-life Skynet scenario, minus the existential threat and with considerably better reporting.

We think we got there. We are excited to show you what Canima can do.


Elias Marquez

CEO & Founder, Canima  |  Achilleus