Built and Tested by Penetration Testers

AutomatedPentestManagement,
PoweredbyAI.

Secured the way you would secure it.

7 day free trial  ·  No card required

Your own databaseClient data lives in a project you own. If we were breached, it is not in it.
Built by pentestersDesigned and tested by people who attack platforms for a living.
Your AI, your keyDirect to your provider, or on hardware you already own.
Secrets sealed at restProvider keys and mail credentials encrypted on write, in your database.
Ownership

One Line We Cannot Cross.

Pental holds two things: your subscription and your domain routing. Everything else lives in a Postgres project you create, in your own account, in a region you pick.

Pental's serversTwo things
  • Your subscriptionThe account email it belongs to, the plan, and the billing record behind it.
  • Domain routingYour domain and its DNS status, so requests reach your portal.
That is the whole list.
Your Postgres projectEverything else

Every client, engagement, finding, file and report you will ever create.

56tables119policies1account, yours
Your account. Your region. Your keys.

If Pental were breached, your clients' data would not be in it.

See exactly what an attacker would get
Held up byRow-level securityFresh-MFA gatesPer-project keysSealed secretsDual-signed calls
Pricing

Same Product on Every Plan.

Only the limits change. Move up or down any time, pro-rated, from your dashboard.

Nothing sits behind a higher tier. Upgrading changes a number, not your platform.
StarterFree trial
A new consultancy, on a budget
£199/moFreefor 7 days
3 internal users
60 clients
Every feature included

The entire platform, on your own database, priced so a small firm runs on it from day one.

Professional
A growing book of work
£1,499/mo
50 internal users
1,000 clients
Every feature included

Identical platform, more headroom. Move up in one click, pro-rated.

Enterprise
No ceiling, and we set it up with you
Let's talk
Unlimited internal users
Unlimited clients
Every feature included

Identical platform, limits removed, and a team that builds your instance with you until it is exactly right.

Prices include tax. Billed monthly. Cancel any time. Your database is yours either way.

Blog

From the Blog.

No posts published yet. The first one is being written.
Questions

The Things People Actually Ask.

Mostly about where the data goes. Fair enough.

A complete operating system for a penetration testing firm: proposals with e-signature, phased engagements, findings with CVSS and evidence, a reusable library, QA review, branded document generation, a client portal, retests and invoicing.

Three things separate it from the alternatives. Your data lives in a database you own, the AI runs on your key or entirely locally, and everything your clients see is your brand. All three on every plan.

Your data lives in a Postgres project you create, in your own account, in whichever region you pick. Pental holds your account email, subscription state, Stripe customer record and domain status. That is the list.

Every table is protected by row-level security evaluated by Postgres on every query, and every data-access policy also requires a recent second-factor check, so a stale session returns nothing.

Resetting a second factor needs an administrator signed in to your own portal, so control of access stays inside your firm.

Nothing, because your data is not on our systems. A compromise of Pental reaches the account email, the subscription record and the domain routing. Your clients, assessments, findings, evidence and reports live in a Postgres project in your own hosting account.

The same holds if a Pental account were taken over. Reading your data requires a signed-in user of your firm with a recent second-factor check, evaluated by your own database on every query, so there is no credential on our side that unlocks it.

A platform that stores every customer in one database it controls cannot give that answer.

No, and the separation is physical rather than a permissions setting. Every firm runs on its own database, so there is no shared table and no tenant filter to get wrong.

Each project signs its own tokens, so a session from one firm does not fail an authorisation check against another, it fails to validate at all.

No. Setup is a guided step: create the project, paste the script we give you into your own SQL editor and run it, set one dropdown in your project settings, then hand back an ID and a key. After that the portal is the only interface you need.

But the database being genuinely yours means that if you do know Postgres, you can connect to it, query it and back it up on your own schedule.

Nothing, because it was never in our custody. The database is in your account. Cancelling ends the subscription and your access to the software; your project carries on exactly as it was. You can also export everything from the portal at any time.

You decide where it runs. Bring a key for OpenAI, Anthropic or Groq and requests go to your account under your terms. Or run Ollama locally, or any compatible endpoint you host, and nothing leaves your environment.

The key is encrypted on write inside your own database, with a key generated in that same database, and the plaintext column is nulled.

Every generated field has its own editable prompt, with a reset to the default. Configure no provider and the AI is simply absent.

Completely, on every plan. Your domain with TLS issued automatically, your favicon, your login page, your colours for both themes, your fonts, and email from your address through your own relay.

No Pental branding anywhere a client can look, and none where your team looks either.

It will be your template. You upload the Word document you already send, and the platform maps your placeholders, tables and sections to live data. Cover page, styles, headers and appendices stay as you built them.

Rendering is deterministic, so the same engagement produces the same document every time. That matters when a client puts this quarter's report next to last quarter's.

With email and password by default, then a mandatory second factor: a passkey or authenticator app enrolled before the portal opens. Passwords are hashed and stored only in your own database. Google and Microsoft SSO are available, and the sign-in page can be switched to emailed one-time codes instead if you prefer passwordless.

Yes, under UK, EU, US, Canadian and Australian frameworks among others, and every signed proposal keeps a full record of who signed, when, and from where.

Starter has a 7-day free trial, no card required, with every feature inside the Starter limits.

The plans differ by capacity, so upgrading changes a limit and leaves everything else alone. Move between them any time, pro-rated.

Enterprise is arranged directly with us and includes the setup work: we build your branding, domain, email, templates, methodology and AI configuration with you, and you get a named contact who knows your instance.

Contact

Talk to the People Who Built It.

Book a demo, ask about deployment, migration or Enterprise, or ask how a specific part of the architecture works. Small team, real answers.

Emailhello@pental.io
ResponseWithin 24 hours
DemoA walkthrough of the platform, arranged by email
EnterpriseUnlimited users and clients, arranged directly
Protected by reCAPTCHA. Privacy · Terms

Set It Up This Afternoon.

Create the database, point your domain, upload your template. Seven days free, no card, and the database stays yours either way.

See pricing