Private beta · Applications open

Enterprise-grade penetration testing,
on autopilot.

PentrAX AI combines autonomous AI reconnaissance, a full multi-agent exploitation engine, and a credentialed in-app browser to deliver audit-ready, compliance-mapped reports — without requiring an internal security team.

Private beta · Founding cohort seats are limited · Authorisation gated by signed Terms of Engagement

PentrAX AI · Engagement #PT-2026-04812

app.northvale-bank.com — Full assessment

CriticalHighMediumLow

Findings

60

12 actionable

Avg CVSS (open)

7.4

3 above 9.0

Compliance gaps

11

across 6 frameworks

Top attack chain — MITRE ATT&CK

T1190 Initial AccessT1552 Unsecured CredentialsT1078 Valid AccountsT1530 Cloud Storage

Findings automatically mapped to

OWASP Top 10 (2021)OWASP API Security Top 10 (2023)PCI DSS v4.0SOC 2 Type IIISO 27001:2022HIPAA Security RuleNIST SP 800-53GDPRCIS Cloud Benchmarks (AWS/Azure/GCP)MITRE ATT&CK

Two-phase engagement model

Prove value before you pay.

A free AI recon, then optional deep assessment — gated by a DRM-protected preview.

Phase 1 · Free

Preliminary AI recon

Passive enumeration, tech fingerprint, public CVE matching, surface-level vulnerability discovery. Produces a redacted, watermarked draft report preview.

  • Subdomain & port enumeration
  • Tech & dependency fingerprint
  • OWASP Top 10 surface scan
  • Redacted DRM preview
Phase 2 · Paid

Full multi-vector assessment

Deep web, network, API, auth, and cryptographic testing. AI-correlated attack chains, full compliance gap analysis, downloadable PDF.

  • 6 specialised attack modules
  • AI correlation + MITRE ATT&CK
  • Multi-framework compliance gap analysis
  • Audit-ready PDF (DRM-enforced)

Testing modules

552 checks across 6 attack surfaces.

184 checks

Web Application

Adaptive payloads, AI-driven exploit selection, automatic evidence capture.

142 checks

Network Infrastructure

Adaptive payloads, AI-driven exploit selection, automatic evidence capture.

96 checks

API Security

Adaptive payloads, AI-driven exploit selection, automatic evidence capture.

64 checks

Authentication & Session

Adaptive payloads, AI-driven exploit selection, automatic evidence capture.

38 checks

Cryptography & TLS

Adaptive payloads, AI-driven exploit selection, automatic evidence capture.

28 checks

Social Engineering Recon

Adaptive payloads, AI-driven exploit selection, automatic evidence capture.

Platform capabilities

Everything a security team does — automated.

Beyond scanning: a full engagement lifecycle from recon to remediation tracking.

Multi-agent AI engine

Specialised agents handle recon, exploitation, correlation, and report writing — each tuned to its own attack surface, not a single general-purpose model.

Credentialed in-app browser

A live, interactive browser session runs inside the platform so authenticated flows — logins, multi-step forms, SPAs — get tested exactly as a human tester would.

Continuous monitoring

Re-scan targets on a schedule and get alerted the moment posture drifts between releases, not just at engagement time.

Retest & verification

Request a retest on any finding directly from the platform — evidence is re-collected and the finding's status updates automatically.

Jira & Linear ticket sync

File a finding straight to your existing tracker with one click. No copy-pasting CVSS scores into a ticket template.

Encrypted credential vault

Store target login credentials and session cookies, AES-256-GCM encrypted at rest, scoped per target and never returned in plaintext.

Multi-tenant workspaces

Separate clients or business units into isolated workspaces with their own targets, findings, and role-scoped access.

Full RBAC

Admin, analyst, auditor, and super-admin roles — auditors get read-only access, analysts triage findings, super-admins manage every tenant.

Real-time notifications

Scan completion, critical findings, and export-ready reports push to the dashboard and your integrations the moment they happen.

DRM-protected report delivery

Draft previews render in a viewer that blocks download, copy, print, and screen capture — watermarked per recipient.

Legal authorisation engine

Domain-ownership verification and a cryptographically signed Terms of Engagement gate every scan before it starts.

API & webhook access

Trigger scans from CI/CD, pull findings programmatically, and push results to Slack, email, or any webhook endpoint.

AI-native architecture

Every phase — recon, exploitation, analysis, reporting — is AI-driven, not rule-based. The engine learns from emerging CVEs daily.

DRM-protected delivery

Draft previews are rendered in a viewer that disables download, copy, print, and screen capture. Watermarked per user.

Continuous DevSecOps

Trigger scans from CI/CD. Receive Slack / Jira alerts. Track posture drift across releases.

90% cost reduction

A manual assessment that takes 4 weeks and costs $40k is delivered in hours, at a fraction of the price.

Legal authorisation engine

Scope verification, domain ownership proofs, cryptographically signed ToE — preventing unauthorised use across jurisdictions.

Audit-defensible reports

Every finding includes evidence, CVSS v3.1 + v4.0, CWE, MITRE technique, and remediation. Reports are accepted by SOC 2 / ISO auditors.

Find what an attacker would find — today.

PentrAX AI is in private beta. Founding cohort members get free full assessments and direct input into the roadmap.