PPENTER
AI-native pentesting workspace

Pentesting, rebuilt around agents.

Plan, investigate, run tools, inspect requests, validate evidence and report findings from one workspace.

The workspace
penter / engagements / acme-apiLIVE
Investigation···
Target overview
Endpoints 48Requests 126Sessions 3Findings 2
Agents
OrchestratorRecon AgentAuth Agent
Orchestrator

Investigation plan

RUN_0142
Map application surface
Identify authentication flows
Compare object authorization
Validate evidence
Agent activity
10:42:18Loaded target context
10:42:24Captured User A request
10:42:31Replaying as User B
Ask Penter about this run...
Inspector
FINDING CANDIDATE

Object authorization

Investigating
Target
/api/orders/{id}
Session
Test User A → User B
Evidence
2 requests · 1 response diff
PENTER Agent
$ nmap -sV --top-ports 1000 target
443/tcp open · https
8080/tcp open · http-proxy
Agent: 2 services added to target graph
One workspace

The whole engagement, connected.

Agents, tools, requests, sessions, evidence and findings stay connected to the same engagement. No context switching between a scanner, proxy and notebook.

Target surface
ACME-API
Endpoints
GET/api/ordersPOST/api/auth/loginGET/api/users/{id}PUT/api/orders/{id}
Sessions
Test User A Test User B Unauthenticated
Agents

Agents that understand the engagement.

PENTER agents work from structured target context instead of starting every prompt from scratch. Every action remains visible to the operator.

Agent graph1 running
ORCHESTRATOR
Recon Agent CompleteWeb Agent CompleteAuth Agent RunningValidator Waiting
Tools

AI reasoning. Real security tools.

Coordinate registered security tools while commands stay visible and controlled by the operator. PENTER turns output into context, not noise.

Tool activityLIVE LOG
nmapfingerprint-servicesCompleted
httpxdiscover-endpointsCompleted
pentervalidate-authorizationRunning
Risk Low3 services added
Requests

Inspect every request.

A request editor built for the moment where a hunch becomes evidence. Compare sessions, replay safely and ask PENTER for a second read.

GET/api/orders/842
Authorization: Bearer eyJhbGci...Session: Test User AContent-Type: application/json
Findings

Evidence before findings.

Observations, requests, responses and tool output stay attached to the finding so the operator can validate what actually happened.

H-001

Object authorization

HIGH · VALIDATED
Affected
/api/orders/{id}
Evidence
4 requests · 2 response diffs · 1 observation
Control

The operator stays in control.

PENTER helps you move faster without hiding the work. Scoped engagements, approvals and evidence history are part of the workspace.

Scoped engagements
Command approval
Risk classification
Session separation
Evidence history
Usage limits

Penter Cloud

Managed reasoning for the full workspace.

Bring your own key

Use the providers you already trust.

Local with Ollama

Keep models close to the engagement.

Pricing

A workspace that scales with your testing.

Free
€0
  • Local models
  • BYOK
  • Basic workspace
Pro
POPULAR
€19 / month
  • €5 cloud AI included
  • Multi-agent workspace
  • Cloud reasoning
  • Usage analytics
Pro+
€39 / month
  • €15 cloud AI included
  • More concurrent agents
  • Longer autonomous runs
  • Advanced reasoning
Start testing

Start testing with PENTER.