Owner-scoped attack-surface monitoring

Find what's exposed before attackers do.

pentes.io continuously scans the infrastructure you've cryptographically proven you own — then an LLM triages every result into a prioritized, plain-English report with a fix. Non-destructive by default. Auditable by design.

Verify one asset and scan it free — no card, no agent to install.
pentes — scan live
Built on the same tooling your security team already audits:
The problem

Scanning your own infrastructure shouldn't be this risky.

Off-the-shelf scanners are loud, dangerous to point at production, and bury you in raw output. Annual pentests are a snapshot that's stale by week two. Most teams end up flying blind between them.

Raw scanners are dangerous

Aggressive flags and exploit modules can knock over the very services you're trying to protect. One wrong setting on prod and you're the incident.

Output is overwhelming

Thousands of unranked, duplicated findings across five tools. No context, no priority — so nothing gets fixed.

Pentests go stale fast

A point-in-time report can't see the subdomain you shipped last Tuesday or the cert that expired this morning.

How it works

Three steps to a report you can act on.

No agents, no network access to your boxes, no standing infrastructure. Prove ownership once, and pentes.io handles the rest from clean, attributed infrastructure.

A creature inserts a hash-key token into a gate slot — without a verified ownership token, the scanner never opens.
Ownership Gate
1 Prove ownership

Verify the asset is yours

Drop a DNS TXT record or serve a token file — the same pattern as ACME. We connect outward to confirm control. Verification is re-checked immediately before every scan.

A creature dusts a glass jar with a feather duster while a sledgehammer is crossed out — scans observe, never exploit.
Non-Destructive Probing
2 Run a safe scan

Non-destructive checks only

An ephemeral worker — egress locked to your scope — runs nmap, testssl, nuclei and ZAP in passive, non-intrusive modes. No exploitation, no payloads, no DoS. Then it's destroyed.

A creature slides a SARIF paper into a sealed glass box and receives a JSON report — the AI reads findings only, with no access to your systems.
AI in a Glass Box
3 Get an AI report

Triaged, ranked, explained

An LLM reads the structured findings — never your systems — to dedupe across tools, rank by real-world impact, and write each fix in plain English. Grounded in the raw evidence.

The platform

Attack surface monitoring: everything you need to watch your perimeter — and nothing you don't.

AI triage that reasons, not just lists

Five scanners produce overlapping, contradictory noise. The triage layer correlates them into one ranked story per finding: what it is, why it matters on your asset, and the exact steps to fix it — each with a confidence score and a link back to the raw SARIF evidence.

High deduped · zap + nuclei → 1
Missing HSTS header
88% confidence

Continuous diffs, not snapshots

Every scan diffs against the last. New, persistent, and fixed findings are tracked over time so you see whether your posture is improving — and get alerted the moment something new appears.

Immutable audit log

Every verification, authorization, and scan is written to an append-only log — the legal cover and compliance trail your security review will ask for.

The hard boundaries

Built to never cross the line.

This is a monitoring product, not an exploitation tool — and the architecture enforces it. If a request would require breaking one of these rules, we don't build the feature.

See the live guardrails
Owner-scoped only
No scan runs until ownership is proven — and re-verified inside the job.
Non-destructive by default
Passive analysis and safe active checks. No payloads, no fuzzing-to-failure.
The AI never touches your systems
It reads structured findings only — no shell, no network access to targets.
No exploitation or DoS — ever
No attack-chaining, no PoC payloads, no stress testing. By design.
Live scan

Watch it run — on a worker that vanishes when it's done.

Spin up a scan and follow the pipeline in real time: ownership re-verified, authorization sealed, an ephemeral worker provisioned with egress locked to a single host, scanners run, then the worker is destroyed. Nothing persists.

  • Egress locked to your scope — no pivoting
  • Hard 10-minute timeout with auto-kill
  • Clean, attributed egress IP — not your laptop
app.pentes.io/scan/4471
app.northwind.io Scanning
Ownership re-verified token matched
Worker provisioned egress → 1 host
nuclei — templated checks 412 templates
AI triage & correlation

pentes.io is an early-stage attack-surface monitor built around a non-negotiable rule: a scan never runs until you've cryptographically proven you own the target. We're actively onboarding design partners — if you operate infrastructure and want continuous, attested security coverage without the heavyweight platform footprint, we'd like to talk.

AB
Adnan Bassem
Founder, pentes.io
Pricing

Priced by attack surface, not headcount.

You pay for the assets you monitor — so price scales with the perimeter you're protecting, not the size of your team. Every plan is owner-scoped, non-destructive, and fully auditable.

Free
$0/ mo

For prove-it pilots — kick the tires on one asset.

Start free
  • 5 scans per month
  • 1 verified asset
  • Full AI-triaged reports
  • Immutable audit log
Pro
$99/ mo

For security teams monitoring a real perimeter.

Start with Pro
  • 1,000 scans per month
  • Unlimited verified assets
  • Priority Slack & webhook alerts
  • Audit-log export + SARIF download
  • Continuous + scheduled scans
14-day money-back guarantee Cancel anytime No card to start
Questions

The things security reviewers always ask.

Yes — that's the entire design premise. Scans are non-destructive: passive analysis plus safe, non-intrusive active checks only. There's no exploitation, no payload delivery, no fuzzing-to-failure, and no load or DoS testing. Intrusive modules are disabled at the worker level, not just by configuration.
A pentest is a deep, point-in-time engagement that includes active exploitation by humans. pentes.io is continuous monitoring — it surfaces and triages exposure on an ongoing basis without ever exploiting anything. They're complementary: use pentes.io to stay aware between pentests and to verify that issues a pentest found stay fixed.
No — and that's deliberate. Every asset must pass ownership verification (DNS-01, an HTTP token file, or an inbound port token) before it can be scanned, and ownership is re-confirmed inside each scan job. This keeps the product owner-scoped and keeps you on the right side of the law.
Never. Deterministic scanners do the detection and write structured findings (SARIF). The LLM only reads those findings to triage, prioritize, and explain. It has no shell, no execution, and no network access to your targets — and every claim it makes links back to the raw evidence.
No agents, ever. Verification is a one-time DNS record or token file. Scans run from our own clean, attributed, isolated infrastructure with a dedicated egress IP — so there's nothing to install on your side and nothing left running.
One asset is one verified domain, host, or IP that you monitor — for example app.example.com. You pay for the size of the surface you're watching, not the number of people on your team or how often you scan. Subdomains you verify separately each count as their own asset.
Start in minutes

See what's exposed on your perimeter today.

Verify one asset and run a full, AI-triaged scan free. No card, no agent, no risk to production.