Built and Tested by Penetration Testers

AutomatedPentestManagement,
PoweredbyAI.

One purpose-built platform for reporting, QA, client delivery and retesting. Less admin, more time testing, and a client experience that matches the quality of the work.

Start free trial

7 day free trial  ·  No card required

Demonstration portals. The four firms are invented; every screen is the real software.

ReportingFindings drafted from evidence, rendered into your own Word template or the built-in PDF, and read back in after you edit.
QAA review queue with comments anchored to the text, suggested changes, and a named sign-off before anything leaves.
Client deliveryA portal under your brand where clients read findings as you release them, comment in context and request retests.
RetestingEvery finding tracked as fixed, still open or new, and a retest report that is a delta rather than a rewrite.
The Problem

The Way Most Firms Still Deliver.

Word documents passed around by email, a review that depends on who is free, and a client who only ever sees a PDF. Here is what each of those becomes once the engagement runs through one system.

Messy, manual reportingFindings are written once, from evidence, and rendered into your template the same way every time.
No structured delivery processScope, phases, findings, review, sign-off, release and retest all sit on one engagement record.
Inconsistent QAEvery report goes through the same review queue, with comments anchored to the text and a named sign-off.
No central vulnerability libraryA findings library the whole team reuses, scoring and remediation intact, that improves with every edit.
Repetitive adminAttestation letters and vulnerability reports are generated from the engagement rather than retyped from the last one.
A poor client experienceClients get a portal under your brand that stays open between engagements, rather than a PDF in an email.
Client data held by a third partyClient data lives in a Postgres project you own. Pental cannot read it, and a breach of Pental would not reach it.
Platforms priced for large consultanciesFrom one tester upwards, with every feature on every plan. Only the capacity changes as you grow.
Processes that break as the team growsThe same workflow, templates and review at one tester as at fifty. Upgrading changes a limit, nothing else.
Under Your Brand

One Engagement, Start to Finish, With Your Name on It.

This is the software running at four firms that set it up differently. Their domain, their logo, their colours, their severity scale, their typeface. Follow one engagement through: the page a client signs in to, the desk your testers work at, and what that client reads when you release it.

Demonstration portals. The four firms are invented. Every screen is the real software.

01

Your Client Signs In to You

On your domain, with your logo, your colours and your wording. There is no Pental branding on the page they sign in to, and none on any page behind it.

  • Your hostname, with TLS issued automatically
  • Your heading and the line under it, set in Settings
  • Email and password, then a mandatory second factor

Calderwood SecurityWhat their client signs in to

A sign-in page carrying one firm’s logo, colours and wording.
02

Your Team Opens the Work, Not a Folder

Every engagement in flight, who leads it, what is waiting on QA and what is ready to go out. The number your team argues about is on the screen rather than in somebody’s head.

  • Assessments by state, with the lead named
  • A QA queue with a count, not a convention
  • The latest findings across every engagement

Calderwood SecurityTheir team

A testing firm’s dashboard: active tests, pending QA, their own and their team’s assessments, and the latest findings by severity.
03

Findings Are Written Once and Released on Purpose

Severity, CVSS, category and status on one row. Two switches decide the rest: whether a finding is still a draft, and whether the client can see it yet.

  • Draft until a required field is filled in
  • Client visible is a decision, not an accident
  • Severity colours are yours, carried through to the report

Calderwood SecurityTheir team

A findings table with severity, CVSS, status, and the draft and client-visible switches that decide what a client can see.
04

Your Client Reads It in Your Portal

Standing access rather than a PDF in an email. They see their own assessments, their open findings and what they have already fixed, and they can come back next quarter.

  • Only what you released, and only their own
  • Remediation progress they can show their board
  • A retest requested with one button

Calderwood SecurityTheir client, signed in

A client’s view of the same portal: their assessments, their open findings and their remediation progress.
05

And the Finding Itself, in Your Words

What was found, what it means, the evidence behind it and what to change. The same record your report renders from, so the two cannot disagree.

  • Description, impact, remediation and evidence
  • Every affected asset, not the first three and a count
  • Request a retest from the finding

Calderwood SecurityTheir client, reading a finding

One finding as a client reads it: severity, CVSS, status, description, remediation advice, evidence and the affected assets.
06

A Different Firm. The Same Software.

Nothing above is a theme we chose for them. This firm changed the accent, both theme colours, the whole severity scale and the typeface, from the same settings screen.

  • Your palette for light and dark, set separately
  • Critical through informational in your own colours
  • Your fonts for headings, body and code

VantrellTheir team

The same dashboard again, with the theme colours, accent, severity scale and typeface all changed by the firm.
07

And a Third, in the Other Direction

A light theme, a teal accent and a severity scale repainted for a firm whose clients are utilities and insurers. Same table, same code, same release two minutes ago.

  • Every feature on every plan, including all of this
  • No tier gates the branding
  • Set up in your first week, changed whenever you like

Thornbury CyberTheir team

A findings table with the severity scale repainted in the firm’s own colours.
Nothing Shared

The Same Page, Three Firms, No Family Resemblance.

The sign-in page is the first thing a client ever sees, and almost all of it is yours to set: logo, heading, the line underneath, the colours and the button. Here it is at three firms that have never met.

A sign-in page carrying one firm’s logo, colours and wording.
Calderwood Security
A third firm’s sign-in page, near-black with a violet accent.
Vantrell
A fourth firm’s sign-in page, in a deliberately quiet corporate palette.
Ashgrove Assurance
Getting Started

Setup Guide

The whole setup recorded end to end, every step in the order you will do them.

Registering, signing in, and the free trial0:00
  1. 0:00Registering, signing in, and the free trialSigning up on pental.io. The address you use here becomes the first admin of the portal. MFA is required: a security key, or an authenticator app, and a key still needs an app as a backup. No card for the trial.
  2. 0:51Your name and your firm’s nameThe two fields the portal and its documents carry from here on.
  3. 0:57Custom domainThe first half of white-labelling: the address your portal runs on, which has to be a domain you own. A CNAME for a subdomain, an A record for a root domain. Verification polls by itself and can take up to fifteen minutes.
  4. 1:45Bring your own databaseCreating a Supabase project, running the setup SQL with RLS, registering the access token hook, then pasting the project ID and publishable key. The free tier is enough to start; the schema sets RLS on every table itself.
  5. 4:07Your own email serverThe second half of white-labelling. Connecting a Microsoft 365 mailbox (sign in with an account that has Send As rights if it is a shared mailbox), or SMTP with a password. Then the test email.
  6. 5:36Branding, and finishing setupLogo at roughly 4:1, favicon at 1:1, light and dark themes with a logo each if you want, and the support address your clients see on the login page.
  7. 6:25Signing in as the first adminThe same account that set the portal up. If the first email did not arrive, Forgot password sets one instead. Then the same MFA steps as before.
  8. 7:34Updating and maintaining the databaseWhen a release needs a schema change, a banner says so: copy the SQL, open the editor, run it. Your clients never see it and the portal keeps working; only the new features wait.
Open the full setup guide, with what each part covers
Withoutmessy Word documentswhite-label platform feesbuilding your owna third party holding client data
What We Believe

Five Things We Built It Around.

Pental is written by people who deliver penetration tests for a living. These are the positions the product takes, and every screen in it follows from one of them.

01

Pen testers should spend their time testing, not formatting reports and repeating admin.

02

A structured delivery and QA process should not be reserved for large consultancies with expensive platforms.

03

Your client delivery experience should reflect the quality of the penetration testing behind it.

04

You should not have to choose between an expensive third-party platform and building your own.

05

The tools running a pentesting business should be built around how pentesting actually works.

06

And one line we cannot cross: your clients' data is never ours to hold.

See the boundary

Where your data actually lives.

A delivery platform holds the most sensitive thing a firm has: its clients' vulnerabilities. So Pental holds two things, your subscription and your domain routing, and everything else lives in a Postgres project you create, in your own account, in a region you pick.

Pental's serversTwo things
  • Your subscriptionThe account email it belongs to, the plan, and the billing record behind it.
  • Domain routingYour domain and its DNS status, so requests reach your portal.
That is the whole list.
Your Postgres projectEverything else

Every client, engagement, finding, file and report you will ever create.

56tables119policies1account, yours
Your account. Your region. Your keys.

If Pental were breached, your clients' data would not be in it.

See exactly what an attacker would get
Held up byRow-level securityFresh-MFA gatesPer-project keysSealed secretsDual-signed calls
Pricing

Same Product on Every Plan.

From a solo tester to a fifty-seat consultancy, only the limits change. Move up or down any time, pro-rated, from your dashboard.

Nothing sits behind a higher tier. Upgrading changes a number, not your platform.
Solo
For one tester
£75/mo
Free for 7 days, no card needed
1 internal user
20 clients
Every feature included

The whole platform for a person working alone. Your own database, your own brand, your own reports.

Starter
For a small team
£199/mo
Free for 7 days, no card needed
3 internal users
60 clients
Every feature included

The whole platform for a firm of two or three, on your own database.

Team
For a growing team
£499/mo
Free for 7 days, no card needed
10 internal users
200 clients
Every feature included

Room for the testers, a reviewer and whoever runs the sales side.

Professional
For an established consultancy
£999/mo
Free for 7 days, no card needed
25 internal users
500 clients
Every feature included

Twenty-five seats and five hundred client records, with every engagement, review and retest on one system.

Premium
For a large consultancy
£1,499/mo
Free for 7 days, no card needed
50 internal users
1,000 clients
Every feature included

Fifty seats and a thousand client records. The same platform the Solo plan runs on, with more room.

Enterprise
For firms that need more than fifty seats
Let's talk
Unlimited internal users
Unlimited clients
Every feature included

The same platform with the limits removed, and we set it up with you: branding, domain, email, templates and methodology.

Prices include tax. Billed monthly. Cancel any time. Your database is yours either way.

Questions

The Things People Actually Ask.

Mostly about where the data goes. Fair enough.

A delivery platform for penetration testing firms: one purpose-built system for reporting, QA, client delivery and retesting, with phased engagements, a findings library and a client portal around it.

It runs on a database you own, the AI runs on your key or entirely locally, and everything your clients see is your brand. Every feature is on every plan, from a solo tester to a fifty-seat consultancy.

Walk through the platform

On your first engagement. Setting up your portal is a stepped wizard in your Pental account, and the generated PDF is there from the start if you want an engagement running before anything else is in place.

Your own Word report becomes the template: set the variables on it yourself, or let the Report Builder place them for you. Cover page, styles, headers and appendices stay as you built them, and rendering is deterministic, so the same engagement produces the same document every time. That matters when a client puts this quarter's report next to last quarter's.

Watch the setup guide

Your data lives in a Postgres project you create, in your own account, in whichever region you pick. Pental holds your account email, subscription state, Stripe customer record and domain status. That is the list.

You do not need to know Postgres to run it. Setup is a guided step: create the project, paste the script we give you into your own SQL editor and run it, set one dropdown in your project settings, then hand back an ID and a key. The database being genuinely yours does mean that if you do know Postgres, you can connect to it, query it and back it up on your own schedule.

How your own database works

No, and it is the database that refuses rather than the interface. Every table is protected by row-level security evaluated by Postgres on every query, and every data-access policy also requires a recent second-factor check, so a stale session returns nothing. Resetting a second factor needs an administrator signed in to your own portal, so control of access stays inside your firm.

A compromise of Pental reaches the account email, the subscription record and the domain routing. Your clients, assessments, findings, evidence and reports sit in your own hosting account, and there is no credential on our side that unlocks them.

Another firm using Pental cannot see them either, and that separation is physical rather than a permissions setting: each project signs its own tokens, so a session from one firm does not fail an authorisation check against another, it fails to validate at all.

What a breach of Pental would reach

You decide where it runs. Bring a key for OpenAI, Anthropic or Groq and requests go to your account under your terms. Or run Ollama locally, or any compatible endpoint you host, and nothing leaves your environment.

The key is encrypted on write inside your own database, with a key generated in that same database, and the plaintext column is nulled.

Every generated field has its own editable prompt, with a reset to the default. Configure no provider and the AI is simply absent.

How the AI runs on your key

Completely, on every plan. Your domain with TLS issued automatically, your favicon, your login page, your colours for both themes, your fonts, and email from your address through your own relay.

No Pental branding anywhere a client can look, and none where your team looks either.

What white-labelling covers

With email and password by default, then a mandatory second factor: a passkey or authenticator app enrolled before the portal opens. Passwords are hashed and stored only in your own database. Google and Microsoft SSO are available, and the sign-in page can be switched to emailed one-time codes instead if you prefer passwordless.

How credentials are handled

Every plan has a 7-day free trial, no card required, with every feature inside that plan's limits. One trial per account, so pick the size you expect to run at.

The six plans differ by capacity and nothing else: Solo is one tester and twenty clients, then Starter, Team, Professional and Premium add seats and client records up to fifty and a thousand. Move between them any time, pro-rated, from your dashboard. Enterprise removes the limits and is arranged directly with us, including the setup work: we build your branding, domain, email, templates, methodology and AI configuration with you, and you get a named contact who knows your instance.

Cancelling ends the subscription and your access to the software, and nothing else. The project is in your own account, so it carries on exactly as it was, and you can export everything from the portal at any time.

Compare the six plans
Contact

Talk to the People Who Built It.

Book a live demo, ask about deployment, migration or Enterprise, or ask how a specific part of the architecture works. Small team, real answers.

Emailhello@pental.io
ResponseWithin 24 hours
DemoA walkthrough of the platform, arranged by email
EnterpriseUnlimited users and clients, arranged directly
Protected by reCAPTCHA. Privacy · Terms

Set It Up Before Your Next Engagement.

A proper delivery platform is essential infrastructure for a growing pentesting company, and it should not cost a fortune. Seven days free, no card, and the database stays yours either way.