The plans differ by capacity and nothing else. There is no feature behind a higher tier, no add-on, and no module you have to buy back. Upgrading changes a number, so the product you try in week one is the product you are still using at fifty people.
Move up or down any time, pro-rated, from your own dashboard. The database stays yours whichever plan you are on, and whether you are on one at all.
The entire platform, on your own database, priced so a small firm runs on it from day one.
Identical platform, more headroom. Move up in one click, pro-rated.
Identical platform, limits removed, and a team that builds your instance with you until it is exactly right.
Prices include tax. Billed monthly. Cancel any time. Your database is yours either way.
Two numbers, and the onboarding. Everything below this is identical on all three, which is why the feature table that follows has three identical columns.
| Capacity | Starter | Professional | Enterprise |
|---|---|---|---|
| Internal usersTesters, reviewers, sales and management. Client accounts are not internal users and never count against this. | 3 | 50 | Unlimited |
| ClientsOrganisations you hold records for. Their own people sign in against the client, not against your seat count. | 60 | 1,000 | Unlimited |
| AssessmentsEngagements, phases and retests. There is no per-project charge on any plan. | Unlimited | Unlimited | Unlimited |
| Findings and evidenceIncluding screenshots and attachments, because they are stored in your own database rather than ours. | Unlimited | Unlimited | Unlimited |
| File storageNo storage tier to outgrow. What it costs is what your own hosting charges you for the space. | Your database | Your database | Your database |
| OnboardingEvery plan gets the guided setup in the portal. Enterprise gets a team that builds your instance with you. | Guided setup | Guided setup | Done with you |
Evidence, screenshots, files and generated documents live in the Postgres project you created, so there is no storage tier for us to sell you. A firm with ten years of engagements and a firm in its first month are on the same terms here.
All 57 of them, grouped the way the platform is. Run your eye down the three columns: that is the argument this page exists to make.
| Feature | Starter | Professional | Enterprise |
|---|---|---|---|
| Engagements | |||
| Structured scopingClients answer a scoping form in their own portal, and the answers land attached to the engagement. | |||
| Phased engagementsExternal, internal, web, retest, or whatever shape the work takes, each with its own dates, testers and checklists. | |||
| Assignment and schedulingTesters assigned per phase, with assessments able to start and complete on their scheduled dates. | |||
| Client credentials, collected safelyAccess credentials arrive encrypted and one-time view, attached to the engagement rather than an email thread. | |||
| Testing source addressesYour public testing IPs carried onto proposals and reports automatically for whitelisting. | |||
| Checklists and runbooksMethodology written once in settings, attached per phase, with tick progress on the phase itself. | |||
| Engagement timelineProposal signed, scope answered, finding written, report released, invoice paid, all on one record. | |||
| Findings and AI | |||
| Generate all from evidenceOne action drafts title, description, remediation, CVSS, CWE, category, assets, custom fields and references in order. | |||
| Per-field generationEvery field has its own generate button, so one thing can be redone without touching the rest. | |||
| Your own provider keyOpenAI, Anthropic or Groq on your account, under your terms, encrypted inside your own database. | |||
| Local and self-hosted modelsOllama on your own hardware, or any compatible endpoint you host, so nothing leaves your network. | |||
| Editable prompts, no hidden onesEvery generated field and section uses a prompt you can read and rewrite, with a reset to the shipped default. | |||
| CVSS scoringThe vector is derived as you toggle metrics, so the score and the string cannot disagree. | |||
| Custom finding fieldsAdd the fields your methodology carries, each with its own control type and its own AI prompt. | |||
| Findings librarySave a write-up once and reuse it, with scoring and remediation intact, improving every time someone edits it. | |||
| Rich evidence editingEvidence blocks, images, tables and code, with clean paste from Word that keeps your formatting. | |||
| RetestsEvery finding tracked as fixed, still open or newly introduced, as a delta rather than a rewrite. | |||
| Documents | |||
| Built-in PDFEditable from your branding: fonts, logo, colours and layout, with nothing to upload and no Word skills needed. | |||
| Custom Word templatesYour own DOCX with your cover page, headers, fonts, tables and appendices. The platform fills your document. | |||
| The report builderUpload a document, click to place what goes where, say what repeats, and build the template visually. | |||
| Deterministic renderingThe same engagement produces the same file, byte for byte, so this quarter sits next to last quarter cleanly. | |||
| Edit in Word, read it backUpload the edited document and the assessment updates to match, item by item, only where you tick. | |||
| Executive and retest summariesDrafted from the findings actually present in the assessment, then edited by a human. | |||
| Five document typesReport, vulnerability report, proposal, invoice and attestation, each with its own template and defaults. | |||
| Your file namingGenerated files follow your own naming convention, so what reaches a client matches your archive. | |||
| Client portal | |||
| Standing client accountsClients keep every report, finding, retest outcome and attestation letter, between engagements as well as during them. | |||
| Release controlFindings reach a client when you release them, not when you save them. | |||
| Comments in contextQuestions are raised against the finding they concern rather than arriving as a separate thread. | |||
| Retest requestsA client can ask for the retest from the report they are reading, and it becomes a scoped phase on your side. | |||
| Attestation lettersThe letter a client’s auditor asks for, generated rather than written from scratch. | |||
| Structured feedbackEnd-of-engagement feedback, with a nudge towards a public review when it is glowing. | |||
| Vulnerability scanning | |||
| Connect your own scannersBurp Suite, Nessus, Tenable, Qualys, Rapid7, Acunetix and more, on your own licences and your own account. | |||
| Import from sixteen formatsNessus, Greenbone, Burp, Nmap, ZAP, Nuclei, SARIF, Trivy, Acunetix, Qualys, Nikto, testssl.sh, Semgrep, Wapiti, CSV and JSON. | |||
| Scans your clients can requestAgainst assets you have approved, inside caps, cooldowns and a window you set. | |||
| Scheduled scanningDaily, weekly, monthly or annual cadences, billed as a subscription through your own Stripe account. | |||
| Automatic deduplicationResults merge by title with every affected host and its own evidence kept in one table. | |||
| Vulnerability reportIts own document type, so scan output never lands inside a penetration test report. | |||
| Your brand | |||
| Your own domainportal.yourfirm.com, with TLS issued and renewed automatically. | |||
| Your sign-in pageYour logo, your colours, your wording. A client never sees a Pental login. | |||
| Both themes, your paletteLight and dark, your colours and fonts, applied everywhere including the documents. | |||
| Email from your addressYour own SMTP relay, or Google or Microsoft OAuth, with a test send before you commit to it. | |||
| No trace of usNo badge, no footer credit, no powered-by, anywhere a client or your own team can look. | |||
| Security and access | |||
| Your own databaseOne Postgres project per firm, in your account, in a region you pick. | |||
| Row-level security119 policies, with row-level security on 56 tables, evaluated by Postgres on every query. | |||
| Freshness-gated MFAEvery data-access policy also demands a recent second factor, required by 86 policies in all. | |||
| Passkeys and authenticator appsMandatory second factor, an any or all policy across two methods, with sessions listable and revocable. | |||
| Google and Microsoft SSOOr emailed one-time codes if you would rather run passwordless. | |||
| Roles by seniorityAdmin, senior, standard, sales and marketing internally, and client accounts locked to their own organisation. | |||
| Secrets encrypted at restNine secret columns encrypted on write inside your own database, with a key generated in that same database. | |||
| Running the firm | |||
| Proposals with e-signatureOne-off, multi-year and retainer shapes, legally valid across the major frameworks, with the engagement created on signature. | |||
| InvoicingRaised against the engagement, on your template, tracked to payment and chased automatically. | |||
| Xero syncInvoices and their state flow both ways, so the books agree without rekeying. | |||
| Card paymentConnect your own Stripe account and clients can pay from the portal. Your account, your payout. | |||
| Issue trackersPush findings into a client’s own Jira, ServiceNow or GitHub and read the state back. | |||
| Dashboards and notificationsPer-role dashboards and per-event switches, including Slack and Teams. | |||
| Modules you can switch offProposals, invoicing, feedback, dashboards and scanning each leave the interface entirely when off. | |||
| Full backup and restoreExport the whole portal as one archive, files included, and restore it into a fresh project. | |||
Seven days, the whole product, no card. The database you create in the first ten minutes stays yours either way.
Enterprise removes the limits and adds people rather than features. The price is agreed per firm, because what it includes is work rather than a licence tier, and that work is different every time.
Seven days free, no card, and every feature in the table above from the first minute. If the shape of your firm needs a conversation instead, book a demo and we will walk through it.