Intelligence

AI on your key, your hardware, and your terms.

AI in a security product usually means your findings become someone else's traffic. Here you choose the provider, hold the key, and requests go direct. Or run the model yourself and let nothing leave. No marked-up tokens, no seat fees, on any plan.

Choose one, or none

Three routes. Every one of them is yours.

Hosted, your key

OpenAI, Anthropic or Groq

your portalyour keyprovider

Paste a key from your own account. Requests go to the provider directly, under your agreement, your data-handling terms and your billing. Pental never proxies your findings through an account of ours, so there is no pooled quota to queue behind and no middleman reading traffic.

Local

Ollama, on your hardware

your portalyour networkyour model

Point the platform at an Ollama instance inside your environment and no engagement data leaves your network for any AI provider, full stop. For the firms whose clients ask that question first, this is the answer that ends the conversation.

Any endpoint

Compatible APIs you host or trust

your portalyour endpointyour model

Any OpenAI-compatible or Anthropic-compatible URL works: a gateway you run, a regional provider, a fine-tuned deployment. Model name, request format and token ceiling are all yours to set.

The part everyone gets wrong

Your key never touches a Pental server.

An AI key is a credential to your provider account and your spend. Here is its entire life, start to finish.

  1. 01You paste the key into your own portal, on your own domain.
  2. 02It is encrypted on write, inside your own database, using a key generated in that same database. The encryption key never leaves your project and is not known to us.
  3. 03The plaintext column is nulled. What is at rest is ciphertext only.
  4. 04When a generation runs, the key is decrypted in memory for that request and used to call your provider directly.
  5. 05At no point in any of this does the key, or the finding it is used on, pass through Pental's servers. There is nothing on our side to breach, subpoena or mishandle.
Same treatment, all secrets

The AI key is one of nine secret columns handled this way, alongside SMTP passwords and integration tokens. The mechanism is described in full on the security page.

Air-gapped ambitions

Local models are a first-class citizen, not a checkbox.

The local route is not a degraded mode. In one important way it is the better one: with no per-token bill and no provider rate limits to design around, the platform can afford slower, more careful passes over your engagement when drafting, which shows in the output.

  • Nothing leavesPrompts, evidence and drafts travel between your portal and your Ollama instance inside your network. There is no third party in the diagram to put in a data-processing agreement.
  • Your model choiceRun whichever model your hardware carries and your quality bar accepts, and change it whenever the state of the art moves. GPU hardware you already operate for password auditing runs these models comfortably.
  • No meteringGeneration costs you electricity, not tokens. Regenerate freely, run longer passes, and never think about a usage bill again.
  • Same platformEverything the AI does on the hosted routes it does locally: findings, summaries, custom sections, all of it.
Scope of work

What it drafts, and what it never touches.

The AI writes prose from the evidence you gathered. It does not invent findings, it does not score them, and nothing it produces reaches a client without a human deciding it should.

It drafts
findings
The written fields of a finding, description, impact, remediation and their companions, from your evidence, in your house voice.
summaries
Executive and retest summaries built from the findings actually present in the assessment, not a generic preamble.
sections
Custom report sections you define, each with its own prompt.
It does not
test
It does not scan, exploit or conclude. The judgement your clients pay for stays with your testers.
publish
Output lands as a draft in the editor, to be kept, reworked or discarded. Release remains a human act, behind QA if you use it.
learn on you
Your engagements train nothing of ours. On the hosted routes your data is governed by your agreement with your provider; on the local route it never leaves.
Your voice

Every prompt is yours to rewrite.

Each generated field has its own prompt, visible and editable in settings. House style, structure rules, banned phrases, the level of detail your clients expect: put it in the prompt once and every draft follows it. A reset returns any prompt to the shipped default, so experimenting is safe.

Why this matters

A fixed, hidden prompt produces the same beige paragraph for every firm in the industry. Your wording is part of your product. The prompts being yours is what makes the drafts sound like you rather than like everyone.

One-time cleverness

Your report template, understood once.

Upload the Word report you already send. The platform reads its structure and maps your placeholders, tables and sections to live engagement data. From then on, rendering is deterministic: the same engagement produces the same document, byte for byte, with no AI in the loop at render time.

  1. 01Upload the DOCX you send clients today, cover page, styles, appendices and all.
  2. 02Review the mapping: which placeholder receives which field, which table receives the findings, which section repeats per finding.
  3. 03Generate forever. Rendering is mechanical from here, so what varies between two reports is the engagement, never the machinery.
No hostage-taking

The off switch is a real off switch.

Configure no provider and the AI is simply absent: no buttons, no nags, no degraded mode. Proposals, engagements, findings, QA, reports, the portal and invoicing all work completely without it, because the platform was built to run a firm first and to draft prose second. Turn it on later, or never, and change routes whenever you like.

Bring a key, or bring a model.

Either way it is configured in minutes from your portal, and either way the key material and the findings stay on your side of the boundary. Seven days free on Starter, no card.