Autonomous AI pentest platform · built by offensive security pros

Take on more clients.
Without adding hours.

PentX runs the whole engagement for you — recon, exploitation, evidence, and the report you'd rather not write — across external, internal, cloud and web. Autonomous, scoped, non-destructive. You review the findings, ship the report under your own brand, and keep the margin. The craft stays yours. The grunt work doesn't.

Unlimited retesting for 12 months · Money-back guarantee on your first report
50+ offensive tools orchestrated External · Internal · Cloud · Web Weeks of work in hours
Weeks → Hours
Full engagement turnaround
50+
Pre-loaded offensive tools, orchestrated
30
Hosts tested in parallel per scan
~25h → 4h
Report production, per real teams
Trained on 7+ years of real engagements · reports that clear Big Four audits
ISO 27001 SOC 2 PCI DSS GDPR optional CREST co-sign OSCP · OSED · GIAC built
The 80% you hate

You didn't get into offense to write reports at 2am.

Every engagement is the same tax: recon, port and service enumeration, chasing low-hanging fruit, screenshotting evidence, and the soul-draining hours of report writing. It's most of the clock and none of the fun — and it's exactly what caps how many clients you can take.

PentX absorbs all of it:

  • Recon & subdomain/asset discovery  → automated
  • Port, service & tech-stack enumeration  → automated
  • Vuln validation & false-positive triage  → proven, then filtered
  • Evidence capture, screenshots, repro steps  → attached automatically
  • Report writing & formatting  → drafted, white-labeled, in minutes

What stays yours: the creative exploitation, the judgement calls, the scoping conversations, the client trust — and 100% of the invoice. PentX makes one of you deliver like a team.

A typical external + web engagement, your way~3–5 days
recon · scan · exploit · evidence · write-up
// most of it repeatable grunt work
The same engagement, with PentXhours
run + review
// you review findings & sign off — that's it
Time you get back≈ 70%
Spend it on deeper exploitation, premium red-team work, or simply the next client.
Three steps

Point it at a scope. Get a report.

No platform to master, no playbooks to script. You stay in control of scope and sign-off; PentX does the work in between.

you, 2 min

Scope the target

Get your account set up and define an authorized scope — external IPs/domains, an internal range, a cloud account, or a web app. Black box or white box.

autonomous

PentX runs the kill chain

The multi-agent engine reconnoiters, plans, exploits and validates — running 50+ real tools in a live sandbox. You watch every command and decision stream in real time.

your brand

Review & ship

Findings arrive proven, with evidence and repro steps. Export a client-ready report with your logo and colors — PDF, DOCX or JSON. Free retest to verify the fix.

Under the hood

Not a scanner. An autonomous operator.

Scanners list maybes. PentX reasons like a tester: it explores, exploits, and proves — then only ships what it can demonstrate. Here's what's actually running.

Discoverer
Service enumeration, port scanning, tech & OS fingerprinting. Maps the attack surface.
Planner
Matches findings to expert attack scenarios, prioritises paths, flags untested gaps.
Pentest Agent
A ReAct loop with reflection: runs commands, reads output, adapts, retries alternate paths when blocked.
Vuln Agent
Validates exploitability, writes structured findings with severity, evidence & repro steps.
Aggregator
Deduplicates & correlates across hosts into one consolidated, compliance-ready report.
Recon & discovery
nmapnaabumasscansubfinderamasshttpxreconftw
Web app testing
ffufferoxbusterdalfoxkatananucleiniktosqlmap
Creds & internal protocols
hydramedusahashcatSMBLDAPSSHSNMP
…and 50+ tools in total — orchestrated, with results parsed and correlated automatically. New tools and scenarios are added continuously by the offensive team behind the model.

It proves, it doesn't guess

Findings ship only with a working exploit, request/response captures, screenshots and reproduction steps. Unvalidated noise is filtered before it ever reaches you.

You see it think

Every command, decision and reasoning step streams live. Audit the agent's logic in real time — full transparency, not a black box that hands you a PDF.

Safe by design

Non-destructive by default: a hard ban-list blocks dangerous commands, scope is enforced, tools are rate-limited, jobs are process-isolated and timed out, everything is logged.

Trained on real tradecraft

A fine-tuned model grounded (via RAG) in a curated command knowledge base, expert attack scenarios and a CVE-enriched vuln dataset — drawn from 500+ real pentest reports.

Reflexion, not repetition

Reinforcement-learned to explore unconventional paths and recover from dead ends — instead of looping or quitting early like rule-based automation.

Continuous on a schedule

Schedule recurring scans against a scope and turn one-off tests into a continuous-testing retainer — recurring revenue, no extra hours from you.

Say yes to more scopes

External, internal, cloud and web. One platform.

Black box or white box. Take the engagement even when it's outside your comfort zone — PentX has the coverage.

External
perimeter

Internet-facing attack surface, run entirely from the cloud — nothing to install.

  • Service & cert posture
  • Web misconfig & exposure
  • Externally exploitable CVEs
Internal
in-network

A single outbound-only container in the client network. No inbound firewall rules.

  • Active Directory enumeration
  • Lateral-movement paths
  • Internal service exploitation
Cloud
misconfig

Cloud-facing posture and exposure across your client's footprint.

  • Exposed services & stores
  • Identity & access exposure
  • Hardening recommendations
Web app
black / white box

Crawling, fuzzing and injection testing with proof, not just signatures.

  • Injection & XSS (sqlmap, dalfox)
  • Dir fuzzing (ffuf, feroxbuster)
  • Auth & access-control flaws
What your client receives

Your name on the cover. Proof on every page.

A freelancer's reputation is the report. So PentX makes it client-ready and unmistakably yours — every finding demonstrated, mapped to impact, with the fix spelled out.

  • White-label, fully. Your logo, your colors, your cover. PentX never appears.
  • Exploit-proven findings with payloads, screenshots and request/response captures.
  • Auditor- & insurer-ready — maps to ISO 27001, SOC 2, PCI DSS, GDPR. Optional named CREST co-sign.
  • Four report types — full technical, executive summary, public compliance, single-vuln — in three formats:
PDFDOCXJSON
Download a real sample report
Let's address the obvious

You're a skeptic. Good — so are we.

The questions every serious operator asks before trusting automation with their name. Straight answers.

"Is this just a scanner with an LLM bolted on?"
No. It runs real commands in a live sandbox and proves exploitability — exploit chain, payloads, captures, repro. If it can't demonstrate it, it doesn't ship. You see the false positives die before they reach you.
"Is the AI going to replace me?"
It replaces your grunt work, not your judgement. The repeatable 80% runs on autopilot; the creative exploitation, scoping and client trust stay yours. One operator delivers like a team — and keeps the whole invoice.
"Will it break my client's production?"
Non-destructive by default. A hard command ban-list, enforced scope, rate limiting, per-job process isolation and full audit logs. Nothing runs against assets you didn't authorize.
"Will clients and auditors accept an AI report?"
They already do. PentX-powered reports have cleared Big Four audits for 12 months with zero revisions, map to the major frameworks, and ship under your brand. Add a named CREST co-sign when required.
"Won't reviewing the output eat the time it saves?"
You review, you don't rewrite. Every step is a readable trace; every finding has evidence and repro attached. Teams cut report production from ~25h to ~4h.
"Where does my client data live?"
Encrypted in transit and at rest, isolated per tenant, EU region, under ISO 27001 controls. Your engagement data is yours — and a money-back guarantee covers your first report.
Already in production

Operators are shipping with it now.

"We started onboarding PentX to replace our external infrastructure audits. Same team, a fraction of the hours, and the ROI was obvious almost immediately."

PT
Pentest team leadPentX pilot partner
95%
faster reporting

An offensive team cut report production from ~25 hours of manual writing to ~4 hours of senior review — freeing engineers for billable exploitation and advisory work.

CTDefense
125
pentests in 5 months

A provider went from 8–12 outsourced engagements a year to 125 delivered in-house, cutting cost per pentest ~70% — without growing the team.

US security provider
0
auditor revisions, 12 months

PentX-powered reports submitted to Big Four auditors for a full year. Every report accepted. Zero revisions requested.

Forward Defense
Packages

Penetration Testing Packages

Two engagement models built around how your attack surface actually looks. Each one includes a full year of unlimited retesting and expert validation on demand, scoped and priced around your environment.

External & Web Application
10 targets
1 target = 1 web application or 1 IP
Prove exactly what an attacker could reach from the outside. Every internet-facing application and host is tested, exploited and re-validated for a full year.
  • 10 targets, each one web application or one IP
  • Unlimited retesting for 12 months
  • External infrastructure penetration testing
  • Web application testing, black-box and white-box
  • Internal network penetration test included
  • Cloud configuration review at no extra cost
  • White-label report, ready for clients and auditors
Contact Us
Internal Network Pentest
Up to 100 live IPs
Post-breach and insider threat simulation
Assume the perimeter has already failed. The PentX AI engine tests lateral movement, privilege escalation and domain compromise across your live estate.
  • Internal network testing across up to 100 live IPs
  • Unlimited retesting for 12 months
  • Cloud configuration review at no extra cost
  • White-label report, ready for clients and auditors
Contact Us
★ Optional add-on
Expert Technical Support
Monthly

Put senior security engineers behind either package, with hands-on delivery, quality assurance and direct technical guidance throughout your engagement.

Contact Us
Every engagement includes:
  • Kickoff and scoping meeting
  • Report review and walkthrough
  • Pentest quality assurance review
  • Manual verification of findings
  • Formal report delivery
  • Ongoing technical support
Recommended wherever findings must be independently verified and defensible to auditors, boards and clients.
Custom

Volume delivery across a client base, a white-label partner programme or a continuous testing practice. The PentX AI engine scales to the scope and cadence you need, with partner terms, custom branding and API access built around your business.

Contact Us
Every package includes unlimited retesting for 12 months, a cloud configuration review at no extra cost, and a white-label report ready for clients and auditors.
FAQ

What operators ask before the first run.

Is PentX just a vulnerability scanner?

No. PentX runs real commands in a live sandboxed environment and proves exploitability before anything reaches the report. A finding only ships with a working exploit, request/response captures, screenshots and reproduction steps. Unvalidated noise is filtered out before you ever see it.

Is the AI going to replace me?

It replaces your grunt work, not your judgement. The repeatable 80% — recon, enumeration, evidence capture and report writing — runs autonomously. The creative exploitation, the scoping calls, the client relationship and the final sign-off stay yours. PentX lets one operator deliver like a team.

What scopes does it cover?

External, internal, cloud and web application testing — black box and white box. Internal engagements run from a single outbound-only container inside the client network (Active Directory enumeration, lateral-movement path discovery, internal service exploitation) with no inbound firewall rules required.

Will it break my client's production environment?

PentX is non-destructive by default. A hard command ban-list blocks destructive actions, scope is enforced, resource-intensive tools are rate-limited, every job is process-isolated with enforced timeouts, and the full command log is auditable. Nothing runs against assets you didn't authorize.

Will clients and auditors accept an AI-generated report?

They already do. PentX-powered reports have cleared Big Four audits for 12 months with zero revisions, map to ISO 27001, SOC 2, PCI DSS and GDPR, and ship under your brand — not ours. Add a named CREST-certified co-sign when an insurer or regulator requires it.

Can I white-label the report?

Completely. Your logo, your colors, your cover — across all four report types (full technical, executive summary, public compliance, single-vulnerability) and all three formats (PDF, DOCX, JSON). PentX never appears to your client.

How does pricing work?

Two packages. External and Web Application covers 10 targets, where one target is one web application or one IP. Internal Network Pentest covers up to 100 live IPs. Both include unlimited retesting for 12 months, a cloud configuration review, and a money-back guarantee on your first report. Contact us to have a package scoped around your work.

How do I start?

Get in touch to have your account set up, define your authorized scope and launch. The engagement runs in hours, not weeks. Prefer to talk first? Book a 15-minute call and we'll walk you through a live run.

Your next engagement, in hours

Scope a target. Ship the report.

Autonomous AI pentesting across external, internal, cloud and web — white-label under your brand, non-destructive, money-back guaranteed. Take on more clients without adding hours.

Contact Us