Most platforms hold your clients' vulnerabilities in a database they control. Pental inverts that: you create the Postgres project, the schema installs into it, and that is where everything lives. We run the software. You hold the data. This page is the machinery.
The trust boundary is short enough to state in full. Pental's side holds what is needed to bill you and route your domain. Your side holds the business.
Owning the database does not mean administering it. Supabase runs the infrastructure, backups and upgrades; the setup is a guided step during onboarding.
“We take your privacy seriously” is a sentence. These are constraints the database enforces on every request, including requests from us.
Follow what a read of your findings actually requires, and where each requirement leaves Pental.
Control of access to your data rests on people signed in to your own portal with fresh second factors, under policies enforced by your own database. That is a stronger position than any promise we could make, because it does not depend on you believing us.
Connect to your own project with your own credentials and count for yourself. The figures we publish are properties of the schema the install creates.
The full layer-by-layer account, including authentication, enumeration resistance and secret handling, lives on the security page
Setup is a guided ten minutes, the trial is seven days with no card, and the project you create is yours from the first minute to whenever you decide, either way.