AI in a security product usually means your findings become someone else's traffic. Here you choose the provider, hold the key, and requests go direct. Or run the model yourself and let nothing leave. No marked-up tokens, no seat fees, on any plan.
Paste a key from your own account. Requests go to the provider directly, under your agreement, your data-handling terms and your billing. Pental never proxies your findings through an account of ours, so there is no pooled quota to queue behind and no middleman reading traffic.
Point the platform at an Ollama instance inside your environment and no engagement data leaves your network for any AI provider, full stop. For the firms whose clients ask that question first, this is the answer that ends the conversation.
Any OpenAI-compatible or Anthropic-compatible URL works: a gateway you run, a regional provider, a fine-tuned deployment. Model name, request format and token ceiling are all yours to set.
An AI key is a credential to your provider account and your spend. Here is its entire life, start to finish.
The AI key is one of nine secret columns handled this way, alongside SMTP passwords and integration tokens. The mechanism is described in full on the security page.
The local route is not a degraded mode. In one important way it is the better one: with no per-token bill and no provider rate limits to design around, the platform can afford slower, more careful passes over your engagement when drafting, which shows in the output.
The AI writes prose from the evidence you gathered. It does not invent findings, it does not score them, and nothing it produces reaches a client without a human deciding it should.
Each generated field has its own prompt, visible and editable in settings. House style, structure rules, banned phrases, the level of detail your clients expect: put it in the prompt once and every draft follows it. A reset returns any prompt to the shipped default, so experimenting is safe.
A fixed, hidden prompt produces the same beige paragraph for every firm in the industry. Your wording is part of your product. The prompts being yours is what makes the drafts sound like you rather than like everyone.
Upload the Word report you already send. The platform reads its structure and maps your placeholders, tables and sections to live engagement data. From then on, rendering is deterministic: the same engagement produces the same document, byte for byte, with no AI in the loop at render time.
Configure no provider and the AI is simply absent: no buttons, no nags, no degraded mode. Proposals, engagements, findings, QA, reports, the portal and invoicing all work completely without it, because the platform was built to run a firm first and to draft prose second. Turn it on later, or never, and change routes whenever you like.
Either way it is configured in minutes from your portal, and either way the key material and the findings stay on your side of the boundary. Seven days free on Starter, no card.