About

What pentes.io is, and why it exists

Last updated: 2026-06-13

pentes.io is an attack-surface monitoring platform built around one rule: a scan never runs until the customer has cryptographically proven they own the target. Everything else in the architecture — the worker, the audit log, the LLM triage pipeline — exists to enforce that rule and produce evidence that it held.

The problem we're solving

There are two ways to find out whether the app you shipped is safe, and neither one is built for the person who shipped it:

Between them is the person we built this for: you shipped something with Cursor, Lovable, v0, Claude Code or Replit, it works, it has real users and probably real payments, and there is no security budget and no security person. The honest default in that position is doing nothing — and doing nothing is what the vibe-coded apps that got breached in 2026 were all doing. Free, non-destructive, owner-verified scanning exists so the default can be something better than nothing.

The non-negotiable rule

We do not run a scan until you have proven you own the target, and our worker re-verifies that proof at the moment of the scan. No "fire-and-forget" pentest mode, no exploitation modules, no auth brute-forcing, no intrusive nuclei templates. The non-destructive posture is architectural, not policy: the worker enforces it, the audit log records it, and we built the product around the constraint from day one.

If you want a tool that can be turned into an exploitation framework, pentes.io is not it — by design.

The operator

pentes.io is currently operated by Adnan Bassem as a sole proprietor, working with design partners ahead of GA. The legal entity will be formed pre-GA; this page and the Terms will be updated when that happens.

How we make money

Subscriptions, billed monthly via Stripe. Three tiers: Free (5 scans / mo), Vibe Coder ($14.99 / 100 scans / mo), Pro ($99 / 1000 scans / mo). No long contracts, no enterprise sales motion at this stage. See the pricing section for current details.

We don't sell data, we don't monetize findings, we don't run ads. If we ever change that, you'll hear about it loudly and have a clean exit path.

Where we are today

Early-stage. The platform is operational on dedicated infrastructure in Falkenstein (Hetzner), the MVP scanner set (nuclei, OWASP ZAP, testssl.sh) is in production, and we're actively onboarding design partners. If you want to know what your own app is exposing, start a free scan — 5 scans a month, no card, and nothing runs until you have proved the domain is yours. You can also try the free tools first, which need no account at all. If you would rather talk to a human: hello@pentes.io.

Why "pentes.io"?

Short for pentesting, which is what people search when they think about the problem we adjacency-solve. We are not a pentesting agency and we are not a Pente.io board-game site (which exists at a different domain) — we're an attack-surface monitoring platform, and the .io TLD anchors us in the security-tooling category visually and semantically.