pentes.io continuously scans the infrastructure you've cryptographically proven you own — then an LLM triages every result into a prioritized, plain-English report with a fix. Non-destructive by default. Auditable by design.
Off-the-shelf scanners are loud, dangerous to point at production, and bury you in raw output. Annual pentests are a snapshot that's stale by week two. Most teams end up flying blind between them.
Aggressive flags and exploit modules can knock over the very services you're trying to protect. One wrong setting on prod and you're the incident.
Thousands of unranked, duplicated findings across five tools. No context, no priority — so nothing gets fixed.
A point-in-time report can't see the subdomain you shipped last Tuesday or the cert that expired this morning.
No agents, no network access to your boxes, no standing infrastructure. Prove ownership once, and pentes.io handles the rest from clean, attributed infrastructure.
Drop a DNS TXT record or serve a token file — the same pattern as ACME. We connect outward to confirm control. Verification is re-checked immediately before every scan.
An ephemeral worker — egress locked to your scope — runs nmap, testssl, nuclei and ZAP in passive, non-intrusive modes. No exploitation, no payloads, no DoS. Then it's destroyed.
An LLM reads the structured findings — never your systems — to dedupe across tools, rank by real-world impact, and write each fix in plain English. Grounded in the raw evidence.
Five scanners produce overlapping, contradictory noise. The triage layer correlates them into one ranked story per finding: what it is, why it matters on your asset, and the exact steps to fix it — each with a confidence score and a link back to the raw SARIF evidence.
Every scan diffs against the last. New, persistent, and fixed findings are tracked over time so you see whether your posture is improving — and get alerted the moment something new appears.
Every verification, authorization, and scan is written to an append-only log — the legal cover and compliance trail your security review will ask for.
This is a monitoring product, not an exploitation tool — and the architecture enforces it. If a request would require breaking one of these rules, we don't build the feature.
See the live guardrailsSpin up a scan and follow the pipeline in real time: ownership re-verified, authorization sealed, an ephemeral worker provisioned with egress locked to a single host, scanners run, then the worker is destroyed. Nothing persists.
pentes.io is an early-stage attack-surface monitor built around a non-negotiable rule: a scan never runs until you've cryptographically proven you own the target. We're actively onboarding design partners — if you operate infrastructure and want continuous, attested security coverage without the heavyweight platform footprint, we'd like to talk.
You pay for the assets you monitor — so price scales with the perimeter you're protecting, not the size of your team. Every plan is owner-scoped, non-destructive, and fully auditable.
For prove-it pilots — kick the tires on one asset.
Start freeFor solo builders shipping a real product.
Start with Vibe CoderFor security teams monitoring a real perimeter.
Start with ProVerify one asset and run a full, AI-triaged scan free. No card, no agent, no risk to production.