Founding launch · run your first pentest for €99 €350 with code ROOT99 · first 100 operators
Autonomous AI pentest platform · built by offensive security pros

Take on more clients.
Without adding hours.

PentX runs the whole engagement for you — recon, exploitation, evidence, and the report you'd rather not write — across external, internal, cloud and web. Autonomous, scoped, non-destructive. You review the findings, ship the report under your own brand, and keep the margin. The craft stays yours. The grunt work doesn't.

Founding offer: your first pentest €99 €350 with code ROOT99
Every credit includes a free retest · Money-back guarantee on your first report
50+ offensive tools orchestrated External · Internal · Cloud · Web Weeks of work in hours
Weeks → Hours
Full engagement turnaround
50+
Pre-loaded offensive tools, orchestrated
30
Hosts tested in parallel per scan
~25h → 4h
Report production, per real teams
Trained on 7+ years of real engagements · reports that clear Big Four audits
ISO 27001 SOC 2 PCI DSS GDPR optional CREST co-sign OSCP · OSED · GIAC built
The 80% you hate

You didn't get into offense to write reports at 2am.

Every engagement is the same tax: recon, port and service enumeration, chasing low-hanging fruit, screenshotting evidence, and the soul-draining hours of report writing. It's most of the clock and none of the fun — and it's exactly what caps how many clients you can take.

PentX absorbs all of it:

  • Recon & subdomain/asset discovery  → automated
  • Port, service & tech-stack enumeration  → automated
  • Vuln validation & false-positive triage  → proven, then filtered
  • Evidence capture, screenshots, repro steps  → attached automatically
  • Report writing & formatting  → drafted, white-labeled, in minutes

What stays yours: the creative exploitation, the judgement calls, the scoping conversations, the client trust — and 100% of the invoice. PentX makes one of you deliver like a team.

A typical external + web engagement, your way~3–5 days
recon · scan · exploit · evidence · write-up
// most of it repeatable grunt work
The same engagement, with PentXhours
run + review
// you review findings & sign off — that's it
Time you get back≈ 70%
Spend it on deeper exploitation, premium red-team work, or simply the next client.
Three steps

Point it at a scope. Get a report.

No platform to master, no playbooks to script. You stay in control of scope and sign-off; PentX does the work in between.

you, 2 min

Scope the target

Buy a credit, create your account, and define an authorized scope — external IPs/domains, an internal range, a cloud account, or a web app. Black box or white box.

autonomous

PentX runs the kill chain

The multi-agent engine reconnoiters, plans, exploits and validates — running 50+ real tools in a live sandbox. You watch every command and decision stream in real time.

your brand

Review & ship

Findings arrive proven, with evidence and repro steps. Export a client-ready report with your logo and colors — PDF, DOCX or JSON. Free retest to verify the fix.

Under the hood

Not a scanner. An autonomous operator.

Scanners list maybes. PentX reasons like a tester: it explores, exploits, and proves — then only ships what it can demonstrate. Here's what's actually running.

Discoverer
Service enumeration, port scanning, tech & OS fingerprinting. Maps the attack surface.
Planner
Matches findings to expert attack scenarios, prioritises paths, flags untested gaps.
Pentest Agent
A ReAct loop with reflection: runs commands, reads output, adapts, retries alternate paths when blocked.
Vuln Agent
Validates exploitability, writes structured findings with severity, evidence & repro steps.
Aggregator
Deduplicates & correlates across hosts into one consolidated, compliance-ready report.
Recon & discovery
nmapnaabumasscansubfinderamasshttpxreconftw
Web app testing
ffufferoxbusterdalfoxkatananucleiniktosqlmap
Creds & internal protocols
hydramedusahashcatSMBLDAPSSHSNMP
…and 50+ tools in total — orchestrated, with results parsed and correlated automatically. New tools and scenarios are added continuously by the offensive team behind the model.

It proves, it doesn't guess

Findings ship only with a working exploit, request/response captures, screenshots and reproduction steps. Unvalidated noise is filtered before it ever reaches you.

You see it think

Every command, decision and reasoning step streams live. Audit the agent's logic in real time — full transparency, not a black box that hands you a PDF.

Safe by design

Non-destructive by default: a hard ban-list blocks dangerous commands, scope is enforced, tools are rate-limited, jobs are process-isolated and timed out, everything is logged.

Trained on real tradecraft

A fine-tuned model grounded (via RAG) in a curated command knowledge base, expert attack scenarios and a CVE-enriched vuln dataset — drawn from 500+ real pentest reports.

Reflexion, not repetition

Reinforcement-learned to explore unconventional paths and recover from dead ends — instead of looping or quitting early like rule-based automation.

Continuous on a schedule

Schedule recurring scans against a scope and turn one-off tests into a continuous-testing retainer — recurring revenue, no extra hours from you.

Say yes to more scopes

External, internal, cloud and web. One platform.

Black box or white box. Take the engagement even when it's outside your comfort zone — PentX has the coverage.

External
perimeter

Internet-facing attack surface, run entirely from the cloud — nothing to install.

  • Service & cert posture
  • Web misconfig & exposure
  • Externally exploitable CVEs
Internal
in-network

A single outbound-only container in the client network. No inbound firewall rules.

  • Active Directory enumeration
  • Lateral-movement paths
  • Internal service exploitation
Cloud
misconfig

Cloud-facing posture and exposure across your client's footprint.

  • Exposed services & stores
  • Identity & access exposure
  • Hardening recommendations
Web app
black / white box

Crawling, fuzzing and injection testing with proof, not just signatures.

  • Injection & XSS (sqlmap, dalfox)
  • Dir fuzzing (ffuf, feroxbuster)
  • Auth & access-control flaws
What your client receives

Your name on the cover. Proof on every page.

A freelancer's reputation is the report. So PentX makes it client-ready and unmistakably yours — every finding demonstrated, mapped to impact, with the fix spelled out.

  • White-label, fully. Your logo, your colors, your cover. PentX never appears.
  • Exploit-proven findings with payloads, screenshots and request/response captures.
  • Auditor- & insurer-ready — maps to ISO 27001, SOC 2, PCI DSS, GDPR. Optional named CREST co-sign.
  • Four report types — full technical, executive summary, public compliance, single-vuln — in three formats:
PDFDOCXJSON
Download a real sample report
Do the math

Same week. Same hours. More invoices.

Your output is capped by delivery time. Hand the repeatable 80% to PentX and the same hours cover far more engagements — at a delivery cost from €250 against the €1,500–€4,000 a pentest typically bills.

Drag the sliders. See what your calendar is actually worth.

Start now
Revenue today€10,000
Capacity with PentX (same hours)€30,000
PentX delivery cost€3,000
Added profit / month€17,000
One extra client more than covers a full 10-pack.

Illustrative: assumes PentX absorbs ~70% of delivery time (weeks→hours) so the same hours cover up to ~3× the engagements, at €250/pentest on the 10-pack. Your numbers will vary.

Let's address the obvious

You're a skeptic. Good — so are we.

The questions every serious operator asks before trusting automation with their name. Straight answers.

"Is this just a scanner with an LLM bolted on?"
No. It runs real commands in a live sandbox and proves exploitability — exploit chain, payloads, captures, repro. If it can't demonstrate it, it doesn't ship. You see the false positives die before they reach you.
"Is the AI going to replace me?"
It replaces your grunt work, not your judgement. The repeatable 80% runs on autopilot; the creative exploitation, scoping and client trust stay yours. One operator delivers like a team — and keeps the whole invoice.
"Will it break my client's production?"
Non-destructive by default. A hard command ban-list, enforced scope, rate limiting, per-job process isolation and full audit logs. Nothing runs against assets you didn't authorize.
"Will clients and auditors accept an AI report?"
They already do. PentX-powered reports have cleared Big Four audits for 12 months with zero revisions, map to the major frameworks, and ship under your brand. Add a named CREST co-sign when required.
"Won't reviewing the output eat the time it saves?"
You review, you don't rewrite. Every step is a readable trace; every finding has evidence and repro attached. Teams cut report production from ~25h to ~4h.
"Where does my client data live?"
Encrypted in transit and at rest, isolated per tenant, EU region, under ISO 27001 controls. Your engagement data is yours — and a money-back guarantee covers your first report.
Already in production

Operators are shipping with it now.

"We started onboarding PentX to replace our external infrastructure audits. Same team, a fraction of the hours, and the ROI was obvious almost immediately."

PT
Pentest team leadPentX pilot partner
95%
faster reporting

An offensive team cut report production from ~25 hours of manual writing to ~4 hours of senior review — freeing engineers for billable exploitation and advisory work.

CTDefense
125
pentests in 5 months

A provider went from 8–12 outsourced engagements a year to 125 delivered in-house, cutting cost per pentest ~70% — without growing the team.

US security provider
0
auditor revisions, 12 months

PentX-powered reports submitted to Big Four auditors for a full year. Every report accepted. Zero revisions requested.

Forward Defense
Pricing

Buy credits. Run pentests. Keep the margin.

1 credit = 1 full engagement on a target scope (external, internal, cloud or web) + a free retest. No subscription, no lock-in.

Founding offer · code ROOT99
Single
Try it on one real engagement, no commitment.
€350€99 first pentest
1 pentest + 1 free retest
Apply ROOT99 at checkout · ongoing €350/credit
  • Full external / internal / cloud / web scope
  • Exploit-proven, white-label report
  • PDF · DOCX · JSON, all 4 report types
  • Free retest included
Get my first pentest →
Founding price — first 100 operators
★ Best value
Scale 10-pack
Run a continuous testing practice and stack recurring revenue.
€2,500 / 10 credits
€250 per pentest · + free retests
  • Everything in Single, ×10
  • Lowest cost per pentest
  • Scheduled / recurring scans
  • Priority support + onboarding
Buy 10 credits
Resell at €1,500–€4,000 each — the pack pays for itself on the first client.
Scale Partner
Larger MSPs, MSSPs and security providers delivering more pentests per year.
Custom
Volume pricing
  • Everything in Scale, at volume rates
  • Best per-pentest pricing
  • White-label partner program & custom branding
  • Partner API & embeddable widget
  • Dedicated onboarding & priority support
Get in touch →
Tell us your volume — we'll tailor pricing.

Money-back guarantee. If your first report doesn't meet your standard, we refund it — you judge the quality before your name ever depends on it. Transparent per-credit pricing, every credit includes a free retest, and scope is confirmed before launch.

FAQ

What operators ask before the first run.

Is PentX just a vulnerability scanner?

No. PentX runs real commands in a live sandboxed environment and proves exploitability before anything reaches the report. A finding only ships with a working exploit, request/response captures, screenshots and reproduction steps. Unvalidated noise is filtered out before you ever see it.

Is the AI going to replace me?

It replaces your grunt work, not your judgement. The repeatable 80% — recon, enumeration, evidence capture and report writing — runs autonomously. The creative exploitation, the scoping calls, the client relationship and the final sign-off stay yours. PentX lets one operator deliver like a team.

What scopes does it cover?

External, internal, cloud and web application testing — black box and white box. Internal engagements run from a single outbound-only container inside the client network (Active Directory enumeration, lateral-movement path discovery, internal service exploitation) with no inbound firewall rules required.

Will it break my client's production environment?

PentX is non-destructive by default. A hard command ban-list blocks destructive actions, scope is enforced, resource-intensive tools are rate-limited, every job is process-isolated with enforced timeouts, and the full command log is auditable. Nothing runs against assets you didn't authorize.

Will clients and auditors accept an AI-generated report?

They already do. PentX-powered reports have cleared Big Four audits for 12 months with zero revisions, map to ISO 27001, SOC 2, PCI DSS and GDPR, and ship under your brand — not ours. Add a named CREST-certified co-sign when an insurer or regulator requires it.

Can I white-label the report?

Completely. Your logo, your colors, your cover — across all four report types (full technical, executive summary, public compliance, single-vulnerability) and all three formats (PDF, DOCX, JSON). PentX never appears to your client.

How does pricing work?

You buy pentest credits. One credit = one full engagement on a target scope, plus a free retest to verify the fix. Packs start from €250 per pentest. No subscription, no lock-in, and a money-back guarantee on your first report.

How do I start?

Buy a credit and create your account at app.pentx.ai/join, define your authorized scope and launch. The engagement runs in hours, not weeks. Prefer to talk first? Book a 15-minute call and we'll walk you through a live run.

Your next engagement, in hours

Buy a credit. Scope a target. Ship the report.

Autonomous AI pentesting across external, internal, cloud and web — white-label under your brand, non-destructive, money-back guaranteed. Take on more clients without adding hours.

Founding offer: first pentest €99 with code ROOT99 · or see a sample report first.
Buy Now — from €250 / pentest