Overview
Recent Engagements
| Name | Target | Status | Findings | Created |
|---|---|---|---|---|
🎯 No engagements yetStart your first pentest engagement | ||||
Engagements
| Name | Target | Scope | Status | Findings | Created | Actions |
|---|---|---|---|---|---|---|
🎯 No engagementsCreate your first engagement to start pentesting | ||||||
Findings
| Severity | Title | Target | Status | Tool | ||
|---|---|---|---|---|---|---|
🔍 No findings yetFindings will appear here when engagements are run | ||||||
Attack Chains
| Name | Severity | Steps | Impact | Status |
|---|---|---|---|---|
⛓️ No attack chainsChains will be discovered during engagements | ||||
Reports
| Engagement | Format | Generated | Actions |
|---|---|---|---|
📋 No reportsGenerate reports from completed engagements | |||
Team
| Member | Role | Joined | Actions | |
|---|---|---|---|---|
API Keys
Generate a key, export it, and pentest-ai will auto-sync every scan's findings to this workspace.
pip install pentest-ai
# auth (or set PENTESTAI_API_KEY)
pentest-ai auth login
# scan, findings sync automatically
pentest-ai scan https://your-authorized-target.com
| Name | Created | Last Used | Expires | Actions |
|---|---|---|---|---|
Billing
Current Plan: Loading...
Loading billing info...
$29/mo
For solo pentesters & bug bounty hunters.
- ✓ Cloud-synced engagement workspace
- ✓ Unlimited history + search
- ✓ 1-click branded PDF reports
- ✓ Scan-complete notifications
- ✓ Priority email support
Launches May 15
$49/seat/mo
3-seat min · consultancies & red teams.
- ✓ Everything in Pro
- ✓ Shared workspace + triage
- ✓ Audit log · SSO
- ✓ Jira / Linear / Slack / GitHub
- ✓ Managed Anthropic key (+$39/seat)
Launches May 15
Let's talkfrom $1,500/mo
Compliance-ready for security teams.
- ✓ Everything in Team
- ✓ SAML / SCIM
- ✓ On-prem option
- ✓ Dedicated CSM
- ✓ Custom agent development
Friendly 30-day refund policy. Cancel any time. Read the policy →
Managed Anthropic key
limited accessSkip managing your own Anthropic account. For +$39/seat/mo, your scans run through our Anthropic proxy — we handle the billing and rate-limit pooling. Available to Team-tier customers on request.
Account
Exercise your data rights under CCPA. Download everything we hold about your account, or permanently delete it.
Download your data
Full JSON bundle of your profile, organizations, engagements, findings, sessions, API keys, and audit logs.
Delete account
This immediately removes your profile and all engagements you own. Teammates keep access to shared organizations. We retain a forensic archive for 30 days, then purge.
Active Sessions
Devices and browsers signed in to your account. Revoke any session you don't recognize.
| Device | IP | Last seen | Expires | Status | Actions |
|---|---|---|---|---|---|
SSO & SCIM
Enterprise-only. Connect Okta, Entra ID, or Google Workspace for SSO and auto-provisioning.
OIDC setup
Point your IdP at the endpoints below. OIDC discovery is standard.
| Redirect URI | — |
| Metadata URL | — |
| Grant types | — |
SCIM tokens
Bearer tokens for SCIM 2.0 auto-provisioning. Paste into your IdP's SCIM integration.
| Name | Created | Last used | Status | Actions |
|---|---|---|---|---|
IP allowlist
Restrict dashboard and API access to trusted IPv4 addresses or CIDR blocks. Owners bypass this check so a bad config never locks you out.
Audit Log
Every privileged action in your organization. Admins can export this log for SOC 2 or customer compliance evidence.
| Time | Actor | Action | Resource | IP |
|---|---|---|---|---|
AI Red Team
LLM Security Findings
| Category | Attack Type | Model | Severity | Status | Created |
|---|---|---|---|---|---|
🤖 No AI security findingsRun an AI security scan to test your LLM applications | |||||
Attack Surface
Discovered Assets
| Type | Value | Risk Score | Status | First Seen | Last Seen |
|---|---|---|---|---|---|
🌐 No assets discoveredStart an attack surface scan to discover assets | |||||
Compliance
Framework Compliance
| Framework | Control | Status | Finding | Evidence |
|---|---|---|---|---|
✅ No compliance dataRun engagements to generate compliance mappings | ||||
Executive Dashboard
MITRE ATT&CK Coverage
MITRE coverage will appear after engagements
CI/CD Pipelines
Quick Setup
GitHub Actions
Add security scanning to your GitHub workflows
GitLab CI
Integrate with GitLab CI/CD pipelines
Jenkins
Add to Jenkins pipeline stages
Pipeline Runs
| Pipeline | Trigger | Status | Findings | Created |
|---|---|---|---|---|
🔄 No pipeline runsConfigure CI/CD to see pipeline runs here | ||||
Bug Bounty
Bounty Submissions
| Program | Title | Severity | Status | Reward | Submitted |
|---|---|---|---|---|---|
🐛 No bounty submissionsCreate a bug bounty program to start receiving submissions | |||||
Integrations
Jira
Auto-create tickets for findings
GitHub
Create issues from findings
Slack
Get notified on critical findings
Splunk
Push detection rules to Splunk
Elastic
Push KQL rules to Elastic SIEM
Teams
Microsoft Teams notifications
White-Label Branding
🛡️ Admin Panel
👥 User Management
| Name | Plan | Admin | Sub Ends | Verified | Created | Actions | |
|---|---|---|---|---|---|---|---|
🏢 Organizations
| Name | Slug | Plan | Max Members | Created |
|---|---|---|---|---|
⚙️ System Settings
Database
D1 Database: pentest-ai-prod
Stripe
Webhook: Active
GitHub OAuth
Status: Coming Soon
Deployment
Cloudflare Pages
📋 Recent Activity
| Action | User | Resource | Details | Time |
|---|---|---|---|---|
📋 No recent activity | ||||