Vulnerability Scanning as a Service

You Already Own the Scanner. Sell What It Produces.

Most firms have a Burp or Nessus licence sitting there being used for one engagement at a time. Pental turns it into a recurring service: scope you approve, a cadence the client pays for, results that arrive deduplicated and reviewed, and a vulnerability report on your own paper. Pental never contacts a target and holds no scan of its own. It brokers the work between your scanner and your customer.

Your licenceFourteen scanner integrations, all running on credentials and licences that stay yours.
Your scope rulesAssets are authorised by you, with dates at both ends, and a scan outside them does not run.
Your pricePer scan or on a cadence, charged through your own Stripe account or raised as an invoice.
Your networkA collector option means the scanner credential never leaves the firm that owns it.
The Product You Are Selling

A Managed Scanning Service, Not a Scanner Login.

A customer given a scanner account will drown in output and blame whoever sold it to them. What they will pay for is the same output arriving on a schedule, filtered, merged, and with a person from your firm standing behind it.

  • They ask, or it runs itselfA customer can request a scan from their own portal, or a cadence you set runs it for them daily, weekly, monthly or annually without anybody pressing anything.
  • Your testers can run it for themYour own people can start a scan on behalf of any customer from the scanning area, which is the job rather than a customer convenience, and it skips the caps that exist to stop a customer spending your money.
  • Everything is a setting you ownWho may start a scan, which scanners are offered, what is charged, where results land, which hours scanning is allowed in, and the authorisation wording. Each has a sensible default so it works before you have decided any of it.
  • It switches off cleanlyScanning is a module. Off, it leaves the interface entirely for your team and your clients, and the templates you have built stay where they are.
The Tools

Connect the Scanners You Already Pay For.

Fourteen integrations, configured in settings with only the fields that particular scanner actually needs. The credential is encrypted, stored with a column grant that keeps it out of every ordinary read, and shown back to you as nothing but its last four characters.

Polled by Pental
Burp Suite
Enterprise Edition and Professional, each with its own API shape rather than one pretending to be the other.
Tenable
Vulnerability Management, Security Center, and Nessus pointed at your own host.
Qualys
VMDR, including the knowledge base step its detections need before they carry a title at all.
Others
Rapid7 InsightVM, Acunetix, Probely and Wiz, plus a generic adapter for any API you can describe.
Pushed to Pental
Nuclei
Post the results at the end of your own pipeline and they land against the customer like any other run.
OpenVAS
Greenbone or OpenVAS output pushed in, for the firms running their own appliance.
Anything Else
A webhook endpoint with a field mapping, so a scanner nobody has integrated is a configuration rather than a wait.
One Kind of Vendor Is Deliberately Absent

Some scanning vendors also sell human penetration testing. Offering those in this list would ask you to route your own client's estate through a competitor and show that competitor's name inside your report, so they are excluded on purpose rather than by omission. A tool vendor is a different thing entirely: you buy the tool and do the testing, which is the whole business this platform serves.

Where the Credential Lives

Two Ways to Reach a Scanner, and They Cost Different Things.

A consultancy asked to open its scanner to a shared cloud egress will refuse, and be right to. So there are two connection styles, and the platform states the cost of each rather than defaulting you into the convenient one.

Direct
How
Pental calls your scanner's API when there is work to do.
Needs
The scanner reachable from the internet, behind an access proxy if you run one. Extra headers for Cloudflare Access, Google IAP or your own reverse proxy are supported on every provider.
Cost
Pental holds the scanner credential, encrypted in your own database.
Collector
How
A small Node process inside your network asks Pental for work and carries the results back. Nothing inbound, no port opened.
Needs
A machine that stays on with Node installed. The portal generates the file and the exact command for macOS, Linux and Windows.
Cost
Nothing, except that the machine has to keep running. The scanner credential never leaves your network.
  • Scanning a client's internal estateThe same collector, owned by the customer instead of by you, runs inside their network. Internal systems are scanned from inside without a tunnel to anywhere, and there is no second protocol to learn.
  • Self-hosted only, if that is your policyA switch that refuses any scanner whose results would pass through a third party, and every run records which of the two it used, so the answer to a customer's question is on the record rather than in somebody's memory.
  • The token is shown onceA collector authenticates with a token generated in your browser and stored only as a hash. The screen says so at the moment it appears, because that is the only moment it can be copied.
The Part That Keeps You Out of Court

Nothing Is Scanned That You Have Not Authorised.

Pointing a scanner at a host nobody approved is a criminal offence in most of the jurisdictions your clients operate in. That is a product problem, not a policy document, so the rules are enforced by the database rather than by the screen that happens to be open.

  • Assets are approved by youEach authorised target carries who approved it, a reference for the paperwork behind it, and a date at each end. A start date in the future is exactly as unapproved as an expiry in the past, and one lapsed asset does not block a live one.
  • Three policies for who may proposeOnly your firm adds targets, or a customer may propose one and wait for approval, or targets are open. The open setting names the legal risk next to itself, because a proposal that approves itself is precisely what the list exists to prevent.
  • The authorisation is recorded on the runWhat was agreed, by whom, and when, stored on the scan itself rather than looked up later. You may reword your terms next month; the record has to say what was actually accepted at the time.
  • Caps, cooldowns and hoursA monthly allowance and a minimum gap per customer, plus a window scanning is permitted in. A request outside the window is not refused, it is told when the window opens, which is the thing the person actually needs to know.
  • One rule, asked everywhereThe button, the request and the scheduler all ask the same eligibility check, and it answers with a reason rather than a no.

If your scanner is already licensed, the service is a settings screen and an authorised asset away.

The Commercials

A Cadence Is a Subscription on Your Own Stripe Account.

This is your revenue, not a share of ours. The frequency is the billing interval, the price is yours, and the money goes to your account without passing through us.

Frequencies
Daily
Off unless you switch it on, because it is the one that runs up a scanner bill without anybody deciding to.
Weekly
The usual shape for something sold as continuous coverage between engagements.
Monthly
The other common one, and the pair enabled by default.
Annual
For a customer whose compliance calendar wants one a year with a document at the end.
Charging
Included
Absorb it, as part of a retainer you already charge for.
Invoiced
A draft invoice raised against that customer when the scan finishes, numbered and dated like any other, needing nothing connected.
Card
Charged to their card through your own Stripe account, per scan or as metered usage.
Lapsing
A subscription that stops paying switches its cadence off, so you are never scanning for somebody who has quietly cancelled.
Cancelling Is Not Stopping

Cancelling a customer's scanning subscription ends it at the period they have already paid for, and the scans until then still run. Stopping the schedule is a different action and is offered as one, because a firm that assumes otherwise finds out a month later.

The Output

Results Worth Putting Your Name On.

Raw scanner output is twenty-nine findings that are really two issues across fourteen hosts. Handing that to a client is how a scanning service loses its customer in the second month.

  1. 01Results are merged by title, so one weakness across forty hosts is one finding. Version numbers are deliberately never folded together, because two TLS versions are two different vulnerabilities and there is no undo for putting one under the other's heading.
  2. 02Where the merge finds your library already has that write-up, your house wording wins. Otherwise the fullest description survives, and the worst severity and highest score are kept, because a merge must never quietly lower what a client is told.
  3. 03Every affected host keeps its own evidence, in a table on the finding, so eleven merged hosts do not become eleven hosts and one screenshot.
  4. 04The run can wait in a holding area for one of your people to read before the customer sees any of it, or go straight through, depending on what you are selling.
  5. 05Whoever should be told is told, and when results are being held the audience is your firm rather than the customer. The email carries counts only; the findings stay behind a login.
  6. 06The deliverable is a vulnerability report, with its own PDF and its own Word template, built in the report builder like every other document you send.
The Distinction That Matters

A Scan Result Is Not a Tested Finding.

Your firm sells the difference between those two things. A platform that blurs them is quietly devaluing the work your testers do, so this one keeps them apart by construction.

  • Separate by defaultScan output lives in its own section of the engagement, staff-only, and is kept out of the penetration test report entirely rather than filtered out of it later.
  • Promotion is deliberateMoving a scan result into your findings is an explicit action, and once moved it stops being a scan result, so the next import cannot overwrite the write-up a human just did.
  • Honest about severityWhere a scanner asserts no severity, such as a port scan, nothing is invented. A column appears only when a result actually fills it.
  • Two documents, two namesThe vulnerability report and the penetration test report are different templates with different defaults, so a client can always tell which they are holding.
The Simple Path

Or Run It Yourself and Upload the File.

Plenty of firms will never connect a scanner and only ever want the output of the one they ran by hand on a phase. That path is first class, and it is the same merge, the same mapping and the same documents.

  • Sixteen formatsNessus, Greenbone and OpenVAS, Burp, Nmap, ZAP in both its shapes, Nuclei, SARIF, Trivy, Acunetix, Qualys, Nikto, testssl.sh, Semgrep, Wapiti, CSV and generic JSON.
  • Nothing is written until you have seen itThe count, the format it was recognised as, and the breakdown by severity appear before a single row is saved.
  • Every field, and where it wentEach field the file carried is listed with a real sample beside it and what it fed. An unused one can be pointed at a field of yours, including your custom fields under the names you gave them.
  • Remembered sensiblyField mappings are remembered per scanner, because a scanner emits the same fields whoever it was run against. The severity floor is remembered per client, because that genuinely is a per-customer decision.
  • Where it landsImport from the scanning area, choosing the customer and then the engagement, and the results attach to the phase they belong to.

Point It at Your Own Scanner and See.

Connect one scanner in settings, approve one asset, and run a scan for a test client. Seven days free, no card, and your licence and credentials stay exactly where they are.