What pentes.io is, and why it exists
pentes.io is an attack-surface monitoring platform built around one rule: a scan never runs until the customer has cryptographically proven they own the target. Everything else in the architecture — the worker, the audit log, the LLM triage pipeline — exists to enforce that rule and produce evidence that it held.
The problem we're solving
There are two ways to find out whether the app you shipped is safe, and neither one is built for the person who shipped it:
- Hire a human penetration tester — genuinely the best answer, and it starts around $5,000 and averages roughly $18,300. If your product makes $400 a month, that is not a decision you get to make.
- Buy an enterprise platform (Qualys, Tenable, Rapid7, Detectify) — priced and designed for a company that already employs someone whose job title contains the word security. Onboarding assumes that person exists.
Between them is the person we built this for: you shipped something with Cursor, Lovable, v0, Claude Code or Replit, it works, it has real users and probably real payments, and there is no security budget and no security person. The honest default in that position is doing nothing — and doing nothing is what the vibe-coded apps that got breached in 2026 were all doing. Free, non-destructive, owner-verified scanning exists so the default can be something better than nothing.
The non-negotiable rule
We do not run a scan until you have proven you own the target, and our worker re-verifies that proof at the moment of the scan. No "fire-and-forget" pentest mode, no exploitation modules, no auth brute-forcing, no intrusive nuclei templates. The non-destructive posture is architectural, not policy: the worker enforces it, the audit log records it, and we built the product around the constraint from day one.
If you want a tool that can be turned into an exploitation framework, pentes.io is not it — by design.
The operator
pentes.io is currently operated by Adnan Bassem as a sole proprietor, working with design partners ahead of GA. The legal entity will be formed pre-GA; this page and the Terms will be updated when that happens.
- Founder / engineer: Adnan Bassem · adnan@pentes.io
- Security and disclosure: security@pentes.io · see policy
- Privacy: privacy@pentes.io
- General: hello@pentes.io
How we make money
Subscriptions, billed monthly via Stripe. Three tiers: Free (5 scans / mo), Vibe Coder ($14.99 / 100 scans / mo), Pro ($99 / 1000 scans / mo). No long contracts, no enterprise sales motion at this stage. See the pricing section for current details.
We don't sell data, we don't monetize findings, we don't run ads. If we ever change that, you'll hear about it loudly and have a clean exit path.
Where we are today
Early-stage. The platform is operational on dedicated infrastructure in Falkenstein (Hetzner), the MVP scanner set (nuclei, OWASP ZAP, testssl.sh) is in production, and we're actively onboarding design partners. If you want to know what your own app is exposing, start a free scan — 5 scans a month, no card, and nothing runs until you have proved the domain is yours. You can also try the free tools first, which need no account at all. If you would rather talk to a human: hello@pentes.io.
Why "pentes.io"?
Short for pentesting, which is what people search when they think about the problem we adjacency-solve. We are not a pentesting agency and we are not a Pente.io board-game site (which exists at a different domain) — we're an attack-surface monitoring platform, and the .io TLD anchors us in the security-tooling category visually and semantically.